EUEuropean UnionPhasing inAI Act

How to make an AI system compliant with the EU AI Act

EU AI Act, Regulation (EU) 2024/1689

Status
Phasing in
Binding
Yes
Object analysed
AI system
Requirements
33
Next milestone
Aug 2, 2027

In short

First horizontal, binding AI framework. Risk-based: prohibited practices, high-risk systems, transparency duties, general-purpose models.

Steps to compliance

  1. Qualify each AI systemAxes to decide: AI Act risk level, Organisation role and General-purpose model.
  2. Determine your roleDuties vary by role: Provider, Deployer and GPAI provider.
  3. Apply the 33 requirementsThey focus on: Technical documentation, Transparency & notice, Quality & conformity and Incidents & corrective action.
  4. Prove it with checks69 checks to document, 54 of which also serve PL 2338, ISO 42001 and AI Basic Act.
  5. Track the deadlinesNext milestone: Aug 2, 2027, Annex I high risk (regulated products); GPAI placed on the market before Aug 2025 (set in the text).

Scope and penalties

Kind
Regulation
Scope
Providers, deployers, importers and distributors of AI systems; providers of GPAI models.
Territorial reach
Extraterritorial: applies when the system is placed on the EU market or its output is used in the EU.
Penalties
Up to €35M or 7% of worldwide turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (incorrect information).
Jurisdiction
European Union

Timeline

Apr 21, 2021Commission proposal
Jul 12, 2024Published in the Official Journal
Aug 1, 2024Entry into force
Feb 2, 2025Prohibited practices (Art. 5) and AI literacy (Art. 4)
Jul 10, 2025GPAI Code of Practice published
Aug 2, 2025GPAI obligations, governance, penalties, notified bodies
Nov 19, 2025Digital Omnibus proposal: high-risk delay tied to standards
Aug 2, 2026General application: Art. 50, sandboxes, Annex III high risk (unless Omnibus delay)To verify
Release
Aug 2, 2027Annex I high risk (regulated products); GPAI placed on the market before Aug 2025Set in the text
Dec 2, 2027Omnibus backstop for Annex III high riskPotential
Aug 2, 2028Omnibus backstop for Annex I high riskPotential
Aug 2, 2030High-risk systems of public authorities already in service (Art. 111)Set in the text
PastSet in the textPotentialTo verify

Qualifying a system

Classification axes and possible verdicts

AI Act risk level

Prohibited (Art. 5)High risk (Art. 6, Annexes I and III)Transparency risk (Art. 50)Minimal risk

Organisation role

ProviderDeployerProvider and deployerImporterDistributor

General-purpose model

GPAI with systemic risk (> 10^25 FLOP)GPAINot a GPAI model

Requirements

33 requirements

CodeArticleRequirementApplies toChecks
EX-001Art. 4AI literacy
Detail

Article 4 requires every provider and deployer to ensure a sufficient level of AI literacy for the persons involved in the operation and use of AI systems. TrustFlow must verify that training and awareness programmes are in place, both at the organisational level and at the level of each system.

ProviderDeployer
EX-002Art. 5Prohibited practices
Detail

Article 5 defines the AI practices that are strictly prohibited. TrustFlow must make it possible to verify that no AI system in the organisation falls within the scope of these prohibited practices, and that a process for detecting drift is in place.

ProviderDeployer
EX-003Art. 9Risk management
Detail

Article 9 requires an iterative and documented risk management system covering the entire lifecycle. TrustFlow must verify that risks are identified, that residual risks are communicated to deployers, and that mitigation measures are in place.

ProviderDeployerHigh risk
EX-004Art. 10Data and data governance
Detail

Article 10 requires rigorous data governance for high-risk AI systems. TrustFlow must verify that the data governance policy is documented (provider) and that input data are relevant and representative (deployer).

ProviderDeployerHigh risk
EX-005Art. 11 + Annexe IVTechnical documentation
Detail

Article 11 requires complete technical documentation to be drawn up and kept up to date before placing on the market. TrustFlow must verify that this documentation exists (provider) and that the deployer has obtained and followed the instructions for use.

ProviderDeployerHigh risk
EX-006Art. 12Record-keeping / logging
Detail

Article 12 requires high-risk AI systems to allow for the automatic recording of events throughout their lifecycle. TrustFlow must verify the existence of a log retention policy, the proper functioning of logging, and the accessibility of logs.

ProviderDeployerHigh risk
EX-007Art. 13Transparency to deployers
Detail

Article 13 requires high-risk AI systems to be sufficiently transparent so that deployers can interpret the outputs. TrustFlow must verify that the instructions for use are complete and that residual risks are communicated.

ProviderDeployerHigh risk
EX-008Art. 14Human oversight
Detail

Article 14 requires effective human oversight during the use of high-risk AI systems. TrustFlow must verify that an escalation procedure exists, that the system is designed for human oversight, and that the overseers are competent.

ProviderDeployerHigh risk
EX-009Art. 15Accuracy, robustness, cybersecurity
Detail

Article 15 requires an appropriate level of accuracy, robustness and cybersecurity throughout the lifecycle. TrustFlow must verify the cybersecurity measures, the accuracy and robustness testing, and the resilience against adversarial attacks.

ProviderDeployerHigh risk
EX-010Art. 17QMS
Detail

Article 17 requires providers of high-risk AI systems to put in place a quality management system (QMS) covering all aspects of the lifecycle. TrustFlow must verify that this QMS is documented and implemented.

ProviderHigh risk
EX-011Art. 1810-year retention
Detail

Article 18 requires documentation to be kept for a minimum of 10 years. TrustFlow must verify that the document retention policy is in place.

ProviderHigh risk
EX-012Art. 19Automatically generated logs
Detail

Article 19 requires the retention of automatically generated logs (minimum 6 months). TrustFlow reuses the verifications of Article 12 (EX-006).

ProviderDeployerHigh risk
EX-013Art. 20Corrective actions
Detail

Article 20 requires providers to take immediate corrective actions and to inform the parties concerned in the event of non-conformity. TrustFlow must verify the existence of non-conformity management procedures and the traceability of corrective actions.

ProviderHigh risk
EX-014Art. 21 + Art. 26§12Cooperation with authorities
Detail

Articles 21 and 26(12) require cooperation with competent authorities. TrustFlow must verify that a cooperation procedure is in place and that the documentation is accessible.

ProviderDeployerHigh risk
EX-015Art. 47EU declaration of conformity
Detail

Article 47 requires the provider to draw up an EU declaration of conformity and to keep it for 10 years. TrustFlow must verify its existence and retention.

ProviderHigh risk
EX-016Art. 48CE marking
Detail

Article 48 requires CE marking on high-risk AI systems. TrustFlow must verify that this marking is affixed.

ProviderHigh risk
EX-017Art. 49EU database registration
Detail

Article 49 requires registration in the EU database before placing on the market or deployment. TrustFlow must verify this registration.

ProviderDeployerHigh risk
EX-018Art. 50Transparency for all systems
Detail

Article 50 imposes transparency obligations for ALL AI systems (not only high-risk): inform users that they are interacting with an AI, and mark AI-generated content.

ProviderDeployerTransparency risk
EX-019Art. 26§9DPIA
Detail

Article 26(9) requires the deployer to use the information provided by the provider to carry out a data protection impact assessment (DPIA).

DeployerHigh risk
EX-020Art. 27FRIA
Detail

Article 27 requires a fundamental rights impact assessment (FRIA) before any deployment of certain high-risk AI systems. TrustFlow must verify that this assessment is carried out and notified.

DeployerHigh risk
EX-021Art. 72Post-market monitoring
Detail

Article 72 requires providers of high-risk AI systems to establish and document a proportionate post-market monitoring system, based on a plan integrated into the technical documentation (Annex IV). This system actively collects, documents and analyses operational data (provided by deployers or through other sources) to evaluate whether the system remains continuously compliant with high-risk requirements and to enable detection of drift throughout the lifecycle. Deployers contribute by monitoring the operation of the system in accordance with the instructions for use (Art. 26(5)) and by reporting relevant information back to the provider. The Commission must publish a plan template by 2 February 2026.

ProviderDeployerHigh risk
EX-022Art. 73Serious incident reporting
Detail

Article 73 requires providers of high-risk AI systems to report any serious incident to the market surveillance authorities, with strict deadlines: 15 days maximum as a general rule, 2 days in the event of a widespread infringement or a serious incident within the meaning of Art. 3(49)(b), and 10 days in the event of death. Deployers must report incidents to the provider as soon as they become aware of them. Following the report, the provider shall, without delay, perform the necessary investigations (risk assessment, corrective action) in cooperation with the competent authorities and the notified body. A failure to report under Article 26 (deployer) exposes the party to an administrative fine of up to EUR 15 million or 3% of worldwide turnover (Art. 99(4)).

ProviderDeployerHigh risk
EX-023Art. 16(l)Accessibility
Detail

Article 16(l) requires providers to ensure that the high-risk AI system complies with accessibility requirements. TrustFlow must verify this compliance.

ProviderHigh risk
EX-024Art. 43Conformity assessment
Detail

Article 43 defines the conformity assessment procedures. TrustFlow must verify that the appropriate procedure has been followed.

ProviderHigh risk
EX-025Art. 22Authorised representative outside the EU
Detail

Article 22 requires non-EU providers to appoint an authorised representative in the Union. TrustFlow must verify this appointment and the representative's powers.

ProviderHigh risk
EX-026Art. 25Value chain
Detail

Article 25 defines the responsibilities along the value chain. TrustFlow must verify that contractual responsibilities are clear and that the role of each actor is analysed.

ProviderDeployerHigh risk
EX-027Art. 26§1Compliant use
Detail

Article 26(1) requires the deployer to use the system in accordance with the provider's instructions.

DeployerHigh risk
EX-028Art. 26§4Input data
Detail

Article 26(4) requires the deployer to ensure the relevance and representativeness of the input data.

DeployerHigh risk
EX-029Art. 26§11Information to affected persons
Detail

Article 26(11) requires natural persons to be informed that they are subject to the use of a high-risk AI system when it makes or assists in making decisions concerning them.

DeployerHigh risk
EX-030Art. 26§7Information to workers' representatives
Detail

Article 26(7) requires workers' representatives and workers to be informed before the use of a high-risk AI system at the workplace.

DeployerHigh risk
EX-031Art. 53GPAI obligations
Detail

Article 53 imposes documentation, transparency and copyright compliance obligations on providers of general-purpose AI (GPAI) models.

GPAI provider
EX-032Art. 55GPAI obligations with systemic risk
Detail

Article 55 imposes enhanced obligations on providers of GPAI models with systemic risk: adversarial evaluations, risk mitigation, incident reporting, and cybersecurity.

GPAI provider
EX-033Art. 86Right to explanation of individual decision-making
Detail

Article 86 grants persons affected by a decision based on a high-risk AI system (Annex III, excluding point 2) the right to obtain a clear explanation of the role of the AI system in the decision and of its main elements. The deployer must put in place the organisational and technical means to respond to this right. This right is complementary to the information obligation in Article 26(11) (EX-029), which covers prior information, whereas Article 86 covers the a posteriori explanation of a specific decision.

DeployerHigh risk

Checks to document

Evidence collected for a check counts for every regulation that uses it.

CodeCheckScopeThemesAlso used by
VER-001-F-01Documented and implemented AI training programmeOrganisation
VER-001-F-02Staff assigned to the system trained and competentSystem
—
VER-001-F-03Training register kept up to dateOrganisation
—
VER-001-D-02System users trained in its useSystem
—
VER-002-01Documented process for detecting drift towards prohibited practicesOrganisation
VER-002-02System free of prohibited practices (provider assessment)System
VER-002-03System use free of prohibited practices (deployer assessment)System
VER-003-01Documented and up-to-date risk registerSystem
VER-003-02Residual risks communicated to deployersSystem
VER-003-03Residual risks read and understood by the deployerSystem
—
VER-003-04Complementary mitigation measures in placeSystem
—
VER-004-01Documented data governance (collection process, bias, quality)System
VER-004-02Input data relevant and representative in view of the intended purposeSystem
VER-005-01Complete technical documentation compliant with Annex IVSystem
VER-005-02Instructions for use obtained and read by the deployerSystem
VER-005-03Use consistent with the intended purpose documentedSystem
VER-006-01Documented log retention policyOrganisation
VER-006-02Automatic logging operational and compliantSystem
VER-006-03Logs accessible and usable by the deployerSystem
VER-007-01Instructions for use complete and compliant with Art. 13System
VER-008-01Documented escalation and emergency stop procedureOrganisation
VER-008-02System designed to allow human oversight (stop button, override)System
VER-008-03Competent overseers assigned to the systemSystem
VER-AUTO-05Accuracy monitoring in operationSystem
VER-009-01Cybersecurity of the hosting environmentOrganisation
VER-009-02Accuracy and robustness verified and documentedSystem
VER-009-03Cybersecurity of the AI system verifiedSystem
VER-010-01QMS documented and implemented in accordance with Art. 17Organisation
—
VER-011-0110-year document retention policy documented and implementedOrganisation
VER-013-F-01Documented non-conformity management procedureOrganisation
VER-013-F-02Immediate notification of stakeholders in the event of non-conformityOrganisation
—
VER-013-F-03Corrective actions traced and documentedSystem
—
VER-013-F-04Communication to market surveillance authorities in the event of riskSystem
VER-AUTO-02Cooperation procedure with authoritiesOrganisation
VER-AUTO-03EU declaration of conformity draftedSystem
VER-016-F-01CE marking affixed in accordance with Art. 48System
VER-017-F-01System registered in the EU database (Art. 71) by the providerSystem
—
VER-017-D-02Use registered in the EU database by the deployer (if public authority)System
—
VER-018-D-01Persons informed of the interaction with an AI systemSystem
VER-018-D-03AI-generated content marked as suchSystem
VER-AUTO-06DPIA completedSystem
—
VER-020-D-01FRIA carried out in accordance with Art. 27System
VER-020-D-07Results of the FRIA notified to the market surveillance authoritySystem
—
VER-021-F-01Operational monitoring planSystem
VER-021-D-03Operation monitoringSystem
VER-AUTO-01Suspension procedure in the event of riskOrganisation
VER-022-F-01Risk and incident response procedureOrganisation
VER-022-D-01Serious incident reporting procedureOrganisation
VER-023-F-03System accessibility verified (compliance with Directives 2016/2102 and 2019/882)System
—
VER-024-F-01Conformity assessment procedure performed (Annex VI or VII)System
VER-025-F-01Authorised representative appointed by written mandateOrganisation
VER-026-F-01Contractual responsibilities documented between provider and third partiesProvider
VER-026-D-01Role qualification analysis (provider/deployer/distributor) carried outSystem
VER-027-D-01Use compliant with the purpose intended by the provider verifiedSystem
VER-029-D-01Affected persons informed of the use of the AI systemSystem
VER-030-D-01Workers' representatives and workers informed of the useSystem
VER-031-G-01GPAI model technical documentation compliant with Annex XIModel
VER-031-G-02Documentation for downstream providers compliant with Annex XIIModel
VER-031-G-03Documented copyright compliance policyOrganisation
VER-031-G-04Published summary of training contentModel
VER-032-G-01Model evaluation with standardised protocols and adversarial testingModel
—
VER-032-G-02Systemic risks assessed and mitigation measures documentedModel
VER-032-G-03Serious incidents documented and reported to the AI OfficeModel
VER-032-G-04Cybersecurity of the model and physical infrastructure ensuredModel
VER-032-G-05Corrective measures for serious incidents documentedModel
—
VER-009-F-04Resilience to adversarial attacks testedModel
VER-033-D-01Decision explanation procedure documentedOrganisation
VER-033-D-02System explanation capability verifiedSystem
VER-033-D-03Explanations provided on request within a reasonable timeframeSystem

Themes covered

Frequently asked questions

Who is in scope of AI Act?

Providers, deployers, importers and distributors of AI systems; providers of GPAI models. Extraterritorial: applies when the system is placed on the EU market or its output is used in the EU.

What penalties does AI Act carry?

Up to €35M or 7% of worldwide turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (incorrect information).

When do the AI Act obligations apply?

Nov 19, 2025: Digital Omnibus proposal: high-risk delay tied to standards; Aug 2, 2026: General application: Art. 50, sandboxes, Annex III high risk (unless Omnibus delay); Aug 2, 2027: Annex I high risk (regulated products); GPAI placed on the market before Aug 2025; Dec 2, 2027: Omnibus backstop for Annex III high risk.

Is AI Act binding?

Yes. Kind: regulation. Status: phasing in.

How does AI Act relate to other regulations?

The same checks serve several texts. Shared checks: PL 2338 (37), ISO 42001 (14) and AI Basic Act (10).

Related regulations

Official sources

Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo