EU regulationEU, extraterritorial
EU AI Act
Artificial Intelligence Act (EU) 2024/1689
The AI Act classifies AI systems by risk: prohibited practices, high-risk systems with conformity obligations, limited-risk systems with transparency duties, and general-purpose AI models with their own regime. It phases in from February 2025 to August 2027.
Who it reaches
- Providers placing AI systems on the EU market, wherever they are established.
- Deployers using AI systems in the EU, especially in Annex III areas: employment, credit, insurance, education, essential services, biometrics, law enforcement.
- Providers of general-purpose AI models, and everyone that builds on them.
What the audit checks
- 01High-risk systems need a conformity assessment: self-assessment against harmonised standards for most Annex III systems, a notified body for Annex I products and some biometrics.
- 02Readiness audits check classification, the risk and quality management systems, data governance, technical documentation, human oversight and post-market monitoring.
- 03ISO/IEC 42001 is the management-system scaffold most auditors assess against while standards are finalised.
A typical engagement
Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.
| Phase | Weeks |
|---|---|
| AI inventory and risk classification | 2 to 6 |
| Gap assessment against the applicable chapter | 2 to 4 |
| Risk and quality management, data governance, documentation | 12 to 36 |
| Conformity assessment, registration, declaration | 4 to 12 |
Evidence to have ready
- AI system inventory with classification reasoning
- AI literacy programme and attendance
- Risk management system records (Article 9)
- Data governance evidence for training, validation and test sets
- Technical documentation per Annex IV
- Instructions for use and human oversight measures
- Quality management system documentation
- Post-market monitoring plan and serious incident process
- Transparency notices for chatbots and generated content
- Fundamental rights impact assessment where required
Dates
- Prohibited practices and AI literacy apply
- General-purpose AI obligations and penalties apply
- General application, Annex III high-risk systems
- Annex I product-embedded high-risk systems
Questions people ask
- When does the AI Act apply?
- Prohibitions and AI literacy since 2 February 2025; general-purpose AI obligations since 2 August 2025; most of the regulation including Annex III high-risk systems from 2 August 2026; Annex I product-embedded high-risk systems from 2 August 2027. A late-2025 proposal to postpone the high-risk dates was not adopted law at the time of writing.
- Does ISO 42001 make me AI Act compliant?
- No. It covers most of the management-system ground the Act requires for high-risk providers, but it is not a presumption of conformity and does not replace the conformity assessment.
- What are the penalties?
- Up to 35 million euro or 7 percent of worldwide turnover for prohibited practices, 15 million euro or 3 percent for most other infringements, and 7.5 million euro or 1 percent for supplying incorrect information.