How to make an AI system compliant with the EU AI Act
EU AI Act, Regulation (EU) 2024/1689
- Status
- Phasing in
- Binding
- Yes
- Object analysed
- AI system
- Requirements
- 33
- Next milestone
- Aug 2, 2027
In short
First horizontal, binding AI framework. Risk-based: prohibited practices, high-risk systems, transparency duties, general-purpose models.
Steps to compliance
- Qualify each AI systemAxes to decide: AI Act risk level, Organisation role and General-purpose model.
- Determine your roleDuties vary by role: Provider, Deployer and GPAI provider.
- Apply the 33 requirementsThey focus on: Technical documentation, Transparency & notice, Quality & conformity and Incidents & corrective action.
- Prove it with checks69 checks to document, 54 of which also serve PL 2338, ISO 42001 and AI Basic Act.
- Track the deadlinesNext milestone: Aug 2, 2027, Annex I high risk (regulated products); GPAI placed on the market before Aug 2025 (set in the text).
Scope and penalties
- Kind
- Regulation
- Scope
- Providers, deployers, importers and distributors of AI systems; providers of GPAI models.
- Territorial reach
- Extraterritorial: applies when the system is placed on the EU market or its output is used in the EU.
- Penalties
- Up to €35M or 7% of worldwide turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (incorrect information).
- Jurisdiction
- European Union
Timeline
Qualifying a system
Classification axes and possible verdicts
AI Act risk level
Organisation role
General-purpose model
Requirements
33 requirements
| Code | Article | Requirement | Applies to | Checks |
|---|---|---|---|---|
| EX-001 | Art. 4 | AI literacyDetailArticle 4 requires every provider and deployer to ensure a sufficient level of AI literacy for the persons involved in the operation and use of AI systems. TrustFlow must verify that training and awareness programmes are in place, both at the organisational level and at the level of each system. | ||
| EX-002 | Art. 5 | Prohibited practicesDetailArticle 5 defines the AI practices that are strictly prohibited. TrustFlow must make it possible to verify that no AI system in the organisation falls within the scope of these prohibited practices, and that a process for detecting drift is in place. | ||
| EX-003 | Art. 9 | Risk managementDetailArticle 9 requires an iterative and documented risk management system covering the entire lifecycle. TrustFlow must verify that risks are identified, that residual risks are communicated to deployers, and that mitigation measures are in place. | ||
| EX-004 | Art. 10 | Data and data governanceDetailArticle 10 requires rigorous data governance for high-risk AI systems. TrustFlow must verify that the data governance policy is documented (provider) and that input data are relevant and representative (deployer). | ||
| EX-005 | Art. 11 + Annexe IV | Technical documentationDetailArticle 11 requires complete technical documentation to be drawn up and kept up to date before placing on the market. TrustFlow must verify that this documentation exists (provider) and that the deployer has obtained and followed the instructions for use. | ||
| EX-006 | Art. 12 | Record-keeping / loggingDetailArticle 12 requires high-risk AI systems to allow for the automatic recording of events throughout their lifecycle. TrustFlow must verify the existence of a log retention policy, the proper functioning of logging, and the accessibility of logs. | ||
| EX-007 | Art. 13 | Transparency to deployersDetailArticle 13 requires high-risk AI systems to be sufficiently transparent so that deployers can interpret the outputs. TrustFlow must verify that the instructions for use are complete and that residual risks are communicated. | ||
| EX-008 | Art. 14 | Human oversightDetailArticle 14 requires effective human oversight during the use of high-risk AI systems. TrustFlow must verify that an escalation procedure exists, that the system is designed for human oversight, and that the overseers are competent. | ||
| EX-009 | Art. 15 | Accuracy, robustness, cybersecurityDetailArticle 15 requires an appropriate level of accuracy, robustness and cybersecurity throughout the lifecycle. TrustFlow must verify the cybersecurity measures, the accuracy and robustness testing, and the resilience against adversarial attacks. | ||
| EX-010 | Art. 17 | QMSDetailArticle 17 requires providers of high-risk AI systems to put in place a quality management system (QMS) covering all aspects of the lifecycle. TrustFlow must verify that this QMS is documented and implemented. | ||
| EX-011 | Art. 18 | 10-year retentionDetailArticle 18 requires documentation to be kept for a minimum of 10 years. TrustFlow must verify that the document retention policy is in place. | ||
| EX-012 | Art. 19 | Automatically generated logsDetailArticle 19 requires the retention of automatically generated logs (minimum 6 months). TrustFlow reuses the verifications of Article 12 (EX-006). | ||
| EX-013 | Art. 20 | Corrective actionsDetailArticle 20 requires providers to take immediate corrective actions and to inform the parties concerned in the event of non-conformity. TrustFlow must verify the existence of non-conformity management procedures and the traceability of corrective actions. | ||
| EX-014 | Art. 21 + Art. 26§12 | Cooperation with authoritiesDetailArticles 21 and 26(12) require cooperation with competent authorities. TrustFlow must verify that a cooperation procedure is in place and that the documentation is accessible. | ||
| EX-015 | Art. 47 | EU declaration of conformityDetailArticle 47 requires the provider to draw up an EU declaration of conformity and to keep it for 10 years. TrustFlow must verify its existence and retention. | ||
| EX-016 | Art. 48 | CE markingDetailArticle 48 requires CE marking on high-risk AI systems. TrustFlow must verify that this marking is affixed. | ||
| EX-017 | Art. 49 | EU database registrationDetailArticle 49 requires registration in the EU database before placing on the market or deployment. TrustFlow must verify this registration. | ||
| EX-018 | Art. 50 | Transparency for all systemsDetailArticle 50 imposes transparency obligations for ALL AI systems (not only high-risk): inform users that they are interacting with an AI, and mark AI-generated content. | ||
| EX-019 | Art. 26§9 | DPIADetailArticle 26(9) requires the deployer to use the information provided by the provider to carry out a data protection impact assessment (DPIA). | ||
| EX-020 | Art. 27 | FRIADetailArticle 27 requires a fundamental rights impact assessment (FRIA) before any deployment of certain high-risk AI systems. TrustFlow must verify that this assessment is carried out and notified. | ||
| EX-021 | Art. 72 | Post-market monitoringDetailArticle 72 requires providers of high-risk AI systems to establish and document a proportionate post-market monitoring system, based on a plan integrated into the technical documentation (Annex IV). This system actively collects, documents and analyses operational data (provided by deployers or through other sources) to evaluate whether the system remains continuously compliant with high-risk requirements and to enable detection of drift throughout the lifecycle. Deployers contribute by monitoring the operation of the system in accordance with the instructions for use (Art. 26(5)) and by reporting relevant information back to the provider. The Commission must publish a plan template by 2 February 2026. | ||
| EX-022 | Art. 73 | Serious incident reportingDetailArticle 73 requires providers of high-risk AI systems to report any serious incident to the market surveillance authorities, with strict deadlines: 15 days maximum as a general rule, 2 days in the event of a widespread infringement or a serious incident within the meaning of Art. 3(49)(b), and 10 days in the event of death. Deployers must report incidents to the provider as soon as they become aware of them. Following the report, the provider shall, without delay, perform the necessary investigations (risk assessment, corrective action) in cooperation with the competent authorities and the notified body. A failure to report under Article 26 (deployer) exposes the party to an administrative fine of up to EUR 15 million or 3% of worldwide turnover (Art. 99(4)). | ||
| EX-023 | Art. 16(l) | AccessibilityDetailArticle 16(l) requires providers to ensure that the high-risk AI system complies with accessibility requirements. TrustFlow must verify this compliance. | ||
| EX-024 | Art. 43 | Conformity assessmentDetailArticle 43 defines the conformity assessment procedures. TrustFlow must verify that the appropriate procedure has been followed. | ||
| EX-025 | Art. 22 | Authorised representative outside the EUDetailArticle 22 requires non-EU providers to appoint an authorised representative in the Union. TrustFlow must verify this appointment and the representative's powers. | ||
| EX-026 | Art. 25 | Value chainDetailArticle 25 defines the responsibilities along the value chain. TrustFlow must verify that contractual responsibilities are clear and that the role of each actor is analysed. | ||
| EX-027 | Art. 26§1 | Compliant useDetailArticle 26(1) requires the deployer to use the system in accordance with the provider's instructions. | ||
| EX-028 | Art. 26§4 | Input dataDetailArticle 26(4) requires the deployer to ensure the relevance and representativeness of the input data. | ||
| EX-029 | Art. 26§11 | Information to affected personsDetailArticle 26(11) requires natural persons to be informed that they are subject to the use of a high-risk AI system when it makes or assists in making decisions concerning them. | ||
| EX-030 | Art. 26§7 | Information to workers' representativesDetailArticle 26(7) requires workers' representatives and workers to be informed before the use of a high-risk AI system at the workplace. | ||
| EX-031 | Art. 53 | GPAI obligationsDetailArticle 53 imposes documentation, transparency and copyright compliance obligations on providers of general-purpose AI (GPAI) models. | ||
| EX-032 | Art. 55 | GPAI obligations with systemic riskDetailArticle 55 imposes enhanced obligations on providers of GPAI models with systemic risk: adversarial evaluations, risk mitigation, incident reporting, and cybersecurity. | ||
| EX-033 | Art. 86 | Right to explanation of individual decision-makingDetailArticle 86 grants persons affected by a decision based on a high-risk AI system (Annex III, excluding point 2) the right to obtain a clear explanation of the role of the AI system in the decision and of its main elements. The deployer must put in place the organisational and technical means to respond to this right. This right is complementary to the information obligation in Article 26(11) (EX-029), which covers prior information, whereas Article 86 covers the a posteriori explanation of a specific decision. |
Checks to document
Evidence collected for a check counts for every regulation that uses it.
| Code | Check | Scope | Themes | Also used by |
|---|---|---|---|---|
| VER-001-F-01 | Documented and implemented AI training programme | Organisation | ||
| VER-001-F-02 | Staff assigned to the system trained and competent | System | ||
| VER-001-F-03 | Training register kept up to date | Organisation | ||
| VER-001-D-02 | System users trained in its use | System | ||
| VER-002-01 | Documented process for detecting drift towards prohibited practices | Organisation | ||
| VER-002-02 | System free of prohibited practices (provider assessment) | System | ||
| VER-002-03 | System use free of prohibited practices (deployer assessment) | System | ||
| VER-003-01 | Documented and up-to-date risk register | System | ||
| VER-003-02 | Residual risks communicated to deployers | System | ||
| VER-003-03 | Residual risks read and understood by the deployer | System | ||
| VER-003-04 | Complementary mitigation measures in place | System | ||
| VER-004-01 | Documented data governance (collection process, bias, quality) | System | ||
| VER-004-02 | Input data relevant and representative in view of the intended purpose | System | ||
| VER-005-01 | Complete technical documentation compliant with Annex IV | System | ||
| VER-005-02 | Instructions for use obtained and read by the deployer | System | ||
| VER-005-03 | Use consistent with the intended purpose documented | System | ||
| VER-006-01 | Documented log retention policy | Organisation | ||
| VER-006-02 | Automatic logging operational and compliant | System | ||
| VER-006-03 | Logs accessible and usable by the deployer | System | ||
| VER-007-01 | Instructions for use complete and compliant with Art. 13 | System | ||
| VER-008-01 | Documented escalation and emergency stop procedure | Organisation | ||
| VER-008-02 | System designed to allow human oversight (stop button, override) | System | ||
| VER-008-03 | Competent overseers assigned to the system | System | ||
| VER-AUTO-05 | Accuracy monitoring in operation | System | ||
| VER-009-01 | Cybersecurity of the hosting environment | Organisation | ||
| VER-009-02 | Accuracy and robustness verified and documented | System | ||
| VER-009-03 | Cybersecurity of the AI system verified | System | ||
| VER-010-01 | QMS documented and implemented in accordance with Art. 17 | Organisation | ||
| VER-011-01 | 10-year document retention policy documented and implemented | Organisation | ||
| VER-013-F-01 | Documented non-conformity management procedure | Organisation | ||
| VER-013-F-02 | Immediate notification of stakeholders in the event of non-conformity | Organisation | ||
| VER-013-F-03 | Corrective actions traced and documented | System | ||
| VER-013-F-04 | Communication to market surveillance authorities in the event of risk | System | ||
| VER-AUTO-02 | Cooperation procedure with authorities | Organisation | ||
| VER-AUTO-03 | EU declaration of conformity drafted | System | ||
| VER-016-F-01 | CE marking affixed in accordance with Art. 48 | System | ||
| VER-017-F-01 | System registered in the EU database (Art. 71) by the provider | System | ||
| VER-017-D-02 | Use registered in the EU database by the deployer (if public authority) | System | ||
| VER-018-D-01 | Persons informed of the interaction with an AI system | System | ||
| VER-018-D-03 | AI-generated content marked as such | System | ||
| VER-AUTO-06 | DPIA completed | System | ||
| VER-020-D-01 | FRIA carried out in accordance with Art. 27 | System | ||
| VER-020-D-07 | Results of the FRIA notified to the market surveillance authority | System | ||
| VER-021-F-01 | Operational monitoring plan | System | ||
| VER-021-D-03 | Operation monitoring | System | ||
| VER-AUTO-01 | Suspension procedure in the event of risk | Organisation | ||
| VER-022-F-01 | Risk and incident response procedure | Organisation | ||
| VER-022-D-01 | Serious incident reporting procedure | Organisation | ||
| VER-023-F-03 | System accessibility verified (compliance with Directives 2016/2102 and 2019/882) | System | ||
| VER-024-F-01 | Conformity assessment procedure performed (Annex VI or VII) | System | ||
| VER-025-F-01 | Authorised representative appointed by written mandate | Organisation | ||
| VER-026-F-01 | Contractual responsibilities documented between provider and third parties | Provider | ||
| VER-026-D-01 | Role qualification analysis (provider/deployer/distributor) carried out | System | ||
| VER-027-D-01 | Use compliant with the purpose intended by the provider verified | System | ||
| VER-029-D-01 | Affected persons informed of the use of the AI system | System | ||
| VER-030-D-01 | Workers' representatives and workers informed of the use | System | ||
| VER-031-G-01 | GPAI model technical documentation compliant with Annex XI | Model | ||
| VER-031-G-02 | Documentation for downstream providers compliant with Annex XII | Model | ||
| VER-031-G-03 | Documented copyright compliance policy | Organisation | ||
| VER-031-G-04 | Published summary of training content | Model | ||
| VER-032-G-01 | Model evaluation with standardised protocols and adversarial testing | Model | ||
| VER-032-G-02 | Systemic risks assessed and mitigation measures documented | Model | ||
| VER-032-G-03 | Serious incidents documented and reported to the AI Office | Model | ||
| VER-032-G-04 | Cybersecurity of the model and physical infrastructure ensured | Model | ||
| VER-032-G-05 | Corrective measures for serious incidents documented | Model | ||
| VER-009-F-04 | Resilience to adversarial attacks tested | Model | ||
| VER-033-D-01 | Decision explanation procedure documented | Organisation | ||
| VER-033-D-02 | System explanation capability verified | System | ||
| VER-033-D-03 | Explanations provided on request within a reasonable timeframe | System |
Themes covered
Frequently asked questions
Who is in scope of AI Act?
Providers, deployers, importers and distributors of AI systems; providers of GPAI models. Extraterritorial: applies when the system is placed on the EU market or its output is used in the EU.
What penalties does AI Act carry?
Up to €35M or 7% of worldwide turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (incorrect information).
When do the AI Act obligations apply?
Nov 19, 2025: Digital Omnibus proposal: high-risk delay tied to standards; Aug 2, 2026: General application: Art. 50, sandboxes, Annex III high risk (unless Omnibus delay); Aug 2, 2027: Annex I high risk (regulated products); GPAI placed on the market before Aug 2025; Dec 2, 2027: Omnibus backstop for Annex III high risk.
Is AI Act binding?
Yes. Kind: regulation. Status: phasing in.
How does AI Act relate to other regulations?
The same checks serve several texts. Shared checks: PL 2338 (37), ISO 42001 (14) and AI Basic Act (10).
Related regulations
Official sources
Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.