Now available: 🔀 Free OneTrust migration trial
EU AI ACT COMPLIANCE GUIDE

EU AI Act compliance: risk classes, obligations and implementation timeline

Understand how the EU AI Act applies to providers, deployers and other actors, how AI systems are classified, and which obligations are already in force or coming next.
EU AI ACT COMPLIANCE WITH TRUSTWORKS

Build a defensible AI governance programme before obligations apply

Discover and inventory AI systems

Identify approved, vendor-provided and shadow AI systems across the organisation and assign clear ownership.

Classify roles and risk levels

Determine whether the organisation is a provider, deployer, importer or distributor and classify each system by regulatory risk.

Run lifecycle risk assessments

Assess fundamental rights, data, human oversight, robustness, security and operational risk throughout the AI lifecycle.

Maintain evidence and accountability

Maintain technical documentation, instructions, logs, incidents, training records, approvals and remediation evidence.
On this page

What is the EU AI Act?

The EU Artificial Intelligence Act is the European Union's horizontal legal framework for artificial intelligence. It uses a risk-based approach and creates different obligations for organisations that develop, place on the market, import, distribute or use AI systems and general-purpose AI models.

The Act entered into force on 1 August 2024. Its provisions apply in phases, so organisations should track both the legal category of each AI system and the date on which the relevant obligations become enforceable.

Who does the EU AI Act apply to?

The Act can apply to providers, deployers, importers, distributors, product manufacturers and providers of general-purpose AI models. It can also reach organisations outside the EU when they place an AI system or model on the EU market, or when the output produced by an AI system is used in the EU.

An organisation's role may change from one system to another. A business can be a deployer when using a third-party tool, a provider when developing or substantially modifying a system, and a product manufacturer when integrating AI into a regulated product. Role classification should therefore be completed for each use case and documented.

The AI Act risk framework

Prohibited AI practices

Certain uses are considered incompatible with EU values and are prohibited, subject to narrow exceptions. These include specified forms of harmful manipulation, exploitation of vulnerabilities, social scoring, certain predictive policing, untargeted facial-image scraping, emotion recognition in workplaces and schools in defined circumstances, certain biometric categorisation and some real-time remote biometric identification by law enforcement.

High-risk AI systems

High-risk systems include certain AI used as a safety component of regulated products and specified use cases in sensitive areas such as biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration and the administration of justice. Whether a use case is high risk depends on the legal criteria and any applicable exclusions.

Transparency-risk systems

Specific transparency rules apply to systems that interact directly with people and to certain AI-generated or manipulated content. Depending on the context, people may need to be informed that they are interacting with AI, and synthetic content may need machine-readable marking or visible labelling.

Minimal or no risk

Most AI systems are not classified as high risk and do not receive mandatory system-specific requirements under the Act. Voluntary codes and responsible governance remain useful, particularly where other laws such as the GDPR, consumer law, employment law or sector regulation apply.

General-purpose AI models

Providers of general-purpose AI models have separate obligations concerning technical documentation, information for downstream providers, copyright compliance and a public summary of training content. Models with systemic risk face additional evaluation, risk-management, incident-reporting and cybersecurity requirements.

EU AI Act implementation timeline

  • 2 February 2025: prohibited AI practices, definitions and AI literacy obligations began to apply.
  • 2 August 2025: governance rules and obligations for providers of general-purpose AI models began to apply.
  • 2 August 2026: the Act generally becomes applicable, including Article 50 transparency obligations and many other provisions.
  • 2 December 2027: high-risk rules for specified sensitive-area systems in Annex III apply following the 2026 AI Omnibus changes.
  • 2 August 2028: high-risk rules for AI embedded in regulated products listed in Annex I apply.

Timelines should be checked against the specific role, system and transitional provision. Existing systems, models already on the market and public-sector uses may have additional transition rules.

AI literacy and prohibited-practice controls

Providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and other people operating AI systems on their behalf. Training should reflect technical knowledge, experience, education, the context of use and the people affected by the system.

Organisations should also implement controls to prevent prohibited uses. A policy alone is not enough: system inventory, approval gates, role-based access, procurement review, use-case screening and monitoring are needed to show that the prohibition is operationalised.

Core obligations for high-risk AI systems

Providers of high-risk systems generally need a documented risk-management system, appropriate data and data-governance practices, technical documentation, logging, instructions for use, human-oversight measures, accuracy, robustness and cybersecurity controls, a quality-management system, conformity assessment, registration and post-market monitoring.

Deployers have their own duties, including following instructions, assigning competent human oversight, monitoring operation, keeping relevant logs, reporting serious incidents and carrying out a fundamental-rights impact assessment in specified cases. Employers and public authorities may also have notification or registration duties.

Fundamental-rights impact assessments

Certain deployers of high-risk systems must assess the potential impact on fundamental rights before use. A fundamental-rights impact assessment should describe the process in which the AI is used, the affected people, risks, human oversight, mitigation and governance. Where personal data is involved, it may need to be coordinated with a GDPR Data Protection Impact Assessment rather than treated as a disconnected exercise.

Transparency obligations

From 2 August 2026, providers and deployers of certain AI systems must meet Article 50 transparency rules. Examples include informing people when they are directly interacting with AI, making AI-generated or manipulated content detectable, and visibly disclosing deepfakes or specified public-interest text where the legal conditions are met.

Transparency should be designed into the product and workflow. Notices should be timely, accessible and understandable, and records should show who assessed the obligation, what disclosure was selected and how it is maintained.

Governance and enforcement

National competent authorities supervise AI systems, while the European AI Office oversees general-purpose AI obligations and certain AI systems based on those models. The Act provides tiered administrative fines linked to the type of infringement and, for undertakings, worldwide annual turnover. Contractual, product, employment, privacy and reputational consequences may apply in addition to regulatory fines.

A practical EU AI Act checklist

  • Create an inventory of internally developed, procured and shadow AI systems.
  • Assign an owner and document each organisation's role in the AI value chain.
  • Screen systems for prohibited practices, high-risk categories, transparency duties and GPAI obligations.
  • Implement AI literacy training proportionate to roles and contexts.
  • Document intended purpose, data, affected people, vendors and deployment context.
  • Run risk, fundamental-rights, privacy and security assessments where required.
  • Define human oversight, escalation, incident and change-management controls.
  • Maintain technical documentation, logs, instructions, approvals and evidence.
  • Review supplier contracts and obtain the information needed for downstream compliance.
  • Monitor regulatory guidance, standards and material changes throughout the lifecycle.

How TrustWorks supports EU AI Act operations

TrustWorks helps organisations turn AI Act obligations into a connected governance programme across legal, privacy, risk, security, procurement, engineering and business teams.

  • AI inventory and discovery: identify approved, third-party and shadow AI systems.
  • Role and risk classification: document value-chain roles, intended purpose and regulatory category.
  • Assessments: run AI risk, fundamental-rights, privacy, vendor and security reviews in structured workflows.
  • Evidence management: maintain documentation, logs, training, approvals, incidents and remediation histories.
  • Lifecycle monitoring: assign owners, trigger reviews and manage changes after deployment.
  • Cross-functional collaboration: coordinate accountability across internal teams and external providers.
TrustWorks supports AI governance and EU AI Act compliance operations. It does not provide legal advice, and organisations should assess their specific obligations with qualified counsel and current European Commission guidance.

Prepare your AI governance programme for the next implementation phase

See how TrustWorks connects AI inventory, classification, assessments, evidence and monitoring in one collaborative governance platform.

Frequently asked questions about the EU AI Act

What is the EU AI Act?
Who does the EU AI Act apply to?
What risk levels does the AI Act use?
Which EU AI Act rules are already in force?
When do the high-risk AI rules apply?
What must providers and deployers do?
Does the EU AI Act replace the GDPR?
How does TrustWorks support EU AI Act compliance?
Book your personalised demo!
And see how leading organisations are already powering their Privacy and AI Governance with context-aware operations.