EU AI Act Compliance for Tech Companies
Regulation (EU) 2024/1689 is the first comprehensive AI law. Here is what any company building or deploying AI in the EU must know: the four risk tiers, the obligations, the deadlines, and the fines.
Overview
What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It entered into force on 1 August 2024 and applies a risk-based approach: the more an AI system can affect people's safety or fundamental rights, the more obligations apply to it.
The most important thing for founders and engineering teams outside the EU: the Act has extraterritorial reach. If your AI system is placed on the EU market or its output is used by people in the EU, the Act applies to you, whether you are based in San Francisco, London, or Bangalore.
In force since
1 Aug 2024
Full regime from
2 Aug 2026
Applies to
Providers + deployers
Covers
EU market + EU users
Timeline
The phased rollout
The AI Act does not apply all at once. Obligations phase in over two years:
Entry into force
Regulation (EU) 2024/1689 becomes law across the EU.
Prohibited practices banned
Article 5 practices, social scoring, manipulative systems, real-time biometric ID in public, become illegal.
GPAI obligations apply
General-purpose AI model providers face transparency and copyright-related duties.
Full high-risk regime
Conformity assessment, technical documentation, and EU database registration required for Annex III systems.
Scope
Who must comply?
The Act assigns different obligations to different roles in the AI supply chain:
Providers
Companies that develop an AI system or general-purpose AI model and place it on the EU market, under their own name or trademark. Carry the heaviest compliance burden for high-risk systems.
Deployers
Any organisation using an AI system under its authority in a professional context, including companies that integrate a third-party AI system into their product or internal process.
Importers and distributors
Must verify the provider has completed the required conformity procedures before making the system available in the EU.
Authorised representatives
Non-EU providers of high-risk systems must appoint an EU-based authorised representative, similar to the GPSR responsible person requirement.
Requirements
The core compliance checklist
Not every item applies to every system: the exact list depends on your risk tier. This is the full set a high-risk provider needs to work through.
1. Risk classification
High priorityDetermine whether your system is prohibited, high-risk, limited-risk, or minimal-risk based on its purpose, sector, and the people it affects.
2. Technical documentation
High priorityFor high-risk systems: a complete technical file describing the system, its intended purpose, architecture, and development process (Art. 11).
3. Risk management system
High priorityA continuous process to identify, estimate, and mitigate foreseeable risks to health, safety, and fundamental rights across the system lifecycle (Art. 9).
4. Human oversight
High-risk systems must let a person interpret outputs, intervene, and override or stop the system (Art. 14).
5. Data governance
Document how training, validation, and testing datasets were selected and checked for bias (Art. 10).
6. Transparency to users
Consumer-facing chatbots, recommenders, and generated content must disclose that users are interacting with AI (Art. 50).
7. Conformity assessment + EU registration
High-risk systems need a conformity assessment, an EU Declaration of Conformity, and registration in the public EU database before going live (Art. 43, 47, 49).
Enforcement
Fines by violation type
Fines scale with the severity of the breach and are capped at the higher of the fixed amount or the turnover percentage.
€35M / 7%
Prohibited practices
of global annual turnover
€15M / 3%
High-risk obligations
of global annual turnover
€7.5M / 1%
Incorrect information
of global annual turnover
Compliance check
How to find your risk tier
Reading the regulation directly takes hours. Answering a short questionnaire about your system takes minutes.
01
Describe your system
What it does, which sector it operates in, and whether it processes biometric data.
02
Answer 7 questions
Whether it influences decisions about people, whether it faces consumers, and how transparent you already are.
03
Get your classification
A risk tier, a compliance score, and the exact list of documents your tier requires, with the legal article for each.
FAQ
Frequently asked questions
Does the EU AI Act apply to my company?
Yes, if your AI system is placed on the EU market or its output is used by people in the EU. This applies regardless of where your company is incorporated, the same extraterritorial reach as GDPR.
When do the obligations start?
The Act entered into force in August 2024. Prohibited practices have been banned since 2 February 2025. General-purpose AI model obligations apply since 2 August 2025. The full high-risk regime applies from 2 August 2026.
What are the fines for non-compliance?
Up to €35M or 7% of global annual turnover for prohibited practices, up to €15M or 3% for breaching high-risk obligations, and up to €7.5M or 1% for supplying incorrect information to authorities.
How do I know my system's risk tier?
It depends on what the system does and who it affects. EuroComply's free assessment answers this for you in about 3 minutes, mapping your answers onto Article 5, Annex III, and Article 50.
What documents does a high-risk system need?
Technical documentation, a risk management system, data governance records, human oversight measures, instructions for deployers, a conformity assessment, an EU Declaration of Conformity, and EU database registration.