All frameworks
EU regulationEU, extraterritorial

EU AI Act

Artificial Intelligence Act (EU) 2024/1689

The AI Act classifies AI systems by risk: prohibited practices, high-risk systems with conformity obligations, limited-risk systems with transparency duties, and general-purpose AI models with their own regime. It phases in from February 2025 to August 2027.

Who it reaches

  • Providers placing AI systems on the EU market, wherever they are established.
  • Deployers using AI systems in the EU, especially in Annex III areas: employment, credit, insurance, education, essential services, biometrics, law enforcement.
  • Providers of general-purpose AI models, and everyone that builds on them.

What the audit checks

  1. 01High-risk systems need a conformity assessment: self-assessment against harmonised standards for most Annex III systems, a notified body for Annex I products and some biometrics.
  2. 02Readiness audits check classification, the risk and quality management systems, data governance, technical documentation, human oversight and post-market monitoring.
  3. 03ISO/IEC 42001 is the management-system scaffold most auditors assess against while standards are finalised.

A typical engagement

Durations are ranges seen in practice for a mid-sized organisation starting from a working security function; a first-time programme runs longer, a mature one shorter.

PhaseWeeks
AI inventory and risk classification2 to 6
Gap assessment against the applicable chapter2 to 4
Risk and quality management, data governance, documentation12 to 36
Conformity assessment, registration, declaration4 to 12

Evidence to have ready

  • AI system inventory with classification reasoning
  • AI literacy programme and attendance
  • Risk management system records (Article 9)
  • Data governance evidence for training, validation and test sets
  • Technical documentation per Annex IV
  • Instructions for use and human oversight measures
  • Quality management system documentation
  • Post-market monitoring plan and serious incident process
  • Transparency notices for chatbots and generated content
  • Fundamental rights impact assessment where required

Dates

  • Prohibited practices and AI literacy apply
  • General-purpose AI obligations and penalties apply
  • General application, Annex III high-risk systems
  • Annex I product-embedded high-risk systems
All regulatory deadlines

Questions people ask

When does the AI Act apply?
Prohibitions and AI literacy since 2 February 2025; general-purpose AI obligations since 2 August 2025; most of the regulation including Annex III high-risk systems from 2 August 2026; Annex I product-embedded high-risk systems from 2 August 2027. A late-2025 proposal to postpone the high-risk dates was not adopted law at the time of writing.
Does ISO 42001 make me AI Act compliant?
No. It covers most of the management-system ground the Act requires for high-risk providers, but it is not a presumption of conformity and does not replace the conformity assessment.
What are the penalties?
Up to 35 million euro or 7 percent of worldwide turnover for prohibited practices, 15 million euro or 3 percent for most other infringements, and 7.5 million euro or 1 percent for supplying incorrect information.

Go deeper