Skip to content

EU AI Act

Run the EU AI Act as part of AI governance.

Connect risk classification, technical documentation, transparency obligations and monitoring with the AI portfolio and ISO 42001, including rationale, owner and approval.

Unacceptable, high, limited, minimal risk classification
4 tiers
EU AI Act and ISO 42001 mapped to the same AIMS controls
2 frameworks
New deadline for Annex III high-risk obligations
Dec 2027

One control, several standards

Do the work once, satisfy it everywhere

Standards overlap far more than they differ. A control entered once is mapped to every framework whose requirement it answers, so the second audit inherits the evidence from the first.

One control, entered once, satisfies a requirement in each of the standards listed below.

One control

Supplier & third-party due diligence

  • EU AI ActRequirement satisfied
  • ISO 27001Requirement satisfied
  • ISO 22301Requirement satisfied
  • NIS2Requirement satisfied
  • GDPRRequirement satisfied

From control to policy

Where a control ends up

A control is not a line in a register. It belongs to a management system, and it is carried by the policies and procedures your people actually read, so it flows through both.

One control feeds the four management systems, which in turn carry it into the policies and procedures listed below.

One control

Supplier & third-party due diligence

Management systems

  • BCMSBusiness continuity
  • ISMSInformation security
  • DSMSData protection
  • AIMSAI governance

Policies and procedures

  • Information security policy
  • Supplier policy
  • Continuity plan

What changes for your team

01

AI system risk classification

The EU AI Act defines four risk tiers: unacceptable, high, limited, and minimal risk. KaitoSec's classification wizard guides you through the Annex III criteria and prohibited practices, producing a documented risk classification for every AI system in your portfolio. It is the first thing a supervisory authority asks for.

02

High-risk conformity assessment

High-risk AI systems require comprehensive technical documentation, conformity assessments, and registration in the EU AI database. KaitoSec provides templates for technical files, risk management records, and data governance documentation aligned with the requirements of Articles 9–17.

03

AI governance and accountability

The Act requires organisations to establish human oversight mechanisms, designate responsible roles, and implement quality management for AI. KaitoSec's governance module tracks AI system owners, oversight procedures, incident logs, and post-market monitoring obligations in one place.

The workflow

01

Keep every AI system in one register

Maintain a complete inventory of all AI systems your organisation develops, deploys, or uses. Each system record captures the risk classification, intended purpose, affected user groups, and compliance status, giving you the overview supervisory authorities and executive management increasingly expect.

02

Build the Article 11 technical documentation

High-risk AI systems require extensive technical documentation under Article 11. KaitoSec provides a structured document builder covering system design, training data governance, accuracy metrics, robustness testing, and human oversight mechanisms, exportable in regulator-ready format.

03

Track transparency obligations per system

Limited-risk AI systems, such as chatbots and tools for AI-generated content, must meet specific transparency obligations under Article 50, including user disclosure. KaitoSec tracks which transparency requirements apply to each system and maintains evidence that disclosure mechanisms are in place.

FAQ

What are the four risk tiers under the EU AI Act?

The EU AI Act classifies AI systems into four tiers. Unacceptable risk systems, such as social scoring or real-time remote biometric identification, are prohibited outright. High-risk systems in areas like employment, education, or critical infrastructure require conformity assessments and registration. Limited risk systems must meet transparency obligations. Minimal risk systems face no specific obligations.

Does the EU AI Act apply to companies outside the EU?

Yes. Like GDPR, the EU AI Act has extraterritorial reach. It applies to any organisation placing AI systems on the EU market or whose AI outputs are used in the EU, regardless of where the provider or deployer is headquartered. Non-EU providers of high-risk AI systems must appoint an authorised representative in the EU.

What is a GPAI model and what obligations does it have?

General Purpose AI (GPAI) models are AI models trained on large datasets capable of performing many different tasks, such as large language models. The EU AI Act imposes transparency obligations on all GPAI model providers, including model documentation and compliance with copyright law. Models with systemic risk (above defined compute thresholds) face additional requirements including adversarial testing.

When do EU AI Act obligations become enforceable?

The EU AI Act entered into force in August 2024. The prohibitions on certain AI practices have applied since February 2025, GPAI model obligations since August 2025, and the Article 50 transparency obligations since August 2026. The high-risk obligations were postponed by the Digital Omnibus in June 2026: they apply from 2 December 2027 for Annex III systems and from August 2028 for product-embedded systems under Annex I. KaitoSec tracks all deadlines and helps you prioritise work based on your compliance timeline.

How does the EU AI Act interact with GDPR?

The EU AI Act and GDPR interact closely when AI systems process personal data. GDPR governs how that data is collected, processed, and stored, while the AI Act governs how AI systems using that data must be designed, tested, and governed. KaitoSec cross-maps obligations so shared requirements, such as data quality, transparency, and human oversight, are evidenced once across both frameworks. That single-evidence approach is exactly what resilience made easy argues for across every framework.

Related frameworks