Back to Frameworks

EU AI Act

European Union
v2024-03-13
10 domains
36 controls

The world's first comprehensive AI regulation, establishing risk-based rules for the placing on the market, putting into service and use of AI systems in the Union. Adopted 13 Jun 2024 (OJ L 1689/2024); entered into force 1 Aug 2024 with staged application: prohibited practices and AI literacy from 2 Feb 2025; GPAI obligations from 2 Aug 2025; most high-risk AI obligations from 2 Aug 2026; full application from 2 Aug 2027. 113 articles across 13 chapters: general provisions, prohibited AI practices, high-risk AI systems (classification, requirements, operator obligations, notified bodies, conformity assessment, standards), transparency for certain AI, general-purpose AI models (incl systemic-risk GPAI), measures for innovation (regulatory sandboxes), governance (AI Office, AI Board, scientific panel), the EU database for high-risk AI, post-market monitoring and market surveillance, codes of conduct and guidelines, delegation/committee, penalties, and final provisions including the right to explanation of individual decision-making.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (10)

EU AI Act - Codes, Penalties and Final Provisions

3 controls
Controls in the EU AI Act - Codes, Penalties and Final Provisions domain of EU AI Act3 controls
CodeTitle
EUAI-Art.111-113Transitional measures, evaluation and entry into force
EUAI-Art.95-96Codes of conduct and Commission guidelines
EUAI-Art.99-101Penalties

EU AI Act - General Provisions and Prohibited Practices

2 controls
Controls in the EU AI Act - General Provisions and Prohibited Practices domain of EU AI Act2 controls
CodeTitle
EUAI-Art.1-4Subject matter, scope, definitions and AI literacy
EUAI-Art.5Prohibited AI practices

EU AI Act - General-Purpose AI Models

4 controls
Controls in the EU AI Act - General-Purpose AI Models domain of EU AI Act4 controls
CodeTitle
EUAI-Art.51-52Classification of GPAI models as having systemic risk
EUAI-Art.53-54Obligations of providers of general-purpose AI models
EUAI-Art.55Obligations of providers of GPAI models with systemic risk
EUAI-Art.56Codes of practice for GPAI

EU AI Act - Governance and EU Database

3 controls
Controls in the EU AI Act - Governance and EU Database domain of EU AI Act3 controls
CodeTitle
EUAI-Art.64-66AI Office, AI Board and tasks
EUAI-Art.67-70Advisory forum, scientific panel and national competent authorities
EUAI-Art.71EU database for high-risk AI systems

EU AI Act - High-Risk Classification and Requirements

9 controls
Controls in the EU AI Act - High-Risk Classification and Requirements domain of EU AI Act9 controls
CodeTitle
EUAI-Art.10Data and data governance
EUAI-Art.11Technical documentation
EUAI-Art.12Record-keeping (logs)
EUAI-Art.13Transparency and provision of information to deployers
EUAI-Art.14Human oversight
EUAI-Art.15Accuracy, robustness and cybersecurity
EUAI-Art.6-7Classification rules for high-risk AI systems
EUAI-Art.8Compliance with the requirements
EUAI-Art.9Risk management system

EU AI Act - High-Risk Operator Obligations

6 controls
Controls in the EU AI Act - High-Risk Operator Obligations domain of EU AI Act6 controls
CodeTitle
EUAI-Art.16-22Obligations of providers of high-risk AI systems and authorised representatives
EUAI-Art.23Obligations of importers
EUAI-Art.24Obligations of distributors
EUAI-Art.25Responsibilities along the AI value chain
EUAI-Art.26Obligations of deployers of high-risk AI systems
EUAI-Art.27Fundamental rights impact assessment for high-risk AI systems

EU AI Act - Innovation Measures

1 controls
Controls in the EU AI Act - Innovation Measures domain of EU AI Act1 controls
CodeTitle
EUAI-Art.57-63Regulatory sandboxes, real-world testing and SME measures

EU AI Act - Notified Bodies, Standards and Conformity Assessment

3 controls
Controls in the EU AI Act - Notified Bodies, Standards and Conformity Assessment domain of EU AI Act3 controls
CodeTitle
EUAI-Art.28-39Notified bodies regime (Arts 28-39)
EUAI-Art.40-42Harmonised standards, common specifications and presumption of conformity
EUAI-Art.43-49Conformity assessment, certificates, derogations, declaration of conformity, CE marking and registration

EU AI Act - Post-Market Monitoring, Market Surveillance and Rights

4 controls
Controls in the EU AI Act - Post-Market Monitoring, Market Surveillance and Rights domain of EU AI Act4 controls
CodeTitle
EUAI-Art.72-73Post-market monitoring and reporting of serious incidents
EUAI-Art.74-83Market surveillance, mutual assistance and procedures for AI systems presenting a risk
EUAI-Art.84-87Testing support, complaints, right to explanation and whistleblower protection
EUAI-Art.88-94GPAI model enforcement

EU AI Act - Transparency Obligations

1 controls
Controls in the EU AI Act - Transparency Obligations domain of EU AI Act1 controls
CodeTitle
EUAI-Art.50Transparency obligations for providers and deployers of certain AI systems

Your Compliance Coverage

If you comply with EU AI Act, you already cover:

Maps to 7 other frameworks

36 total controls
EU AI Liability Directive
11 source controls mapped|10 target controls covered
31%
NIST AI Risk Management Framework (AI RMF 1.0)
10 source controls mapped|10 target controls covered
28%
GDPR
5 source controls mapped|4 target controls covered
14%
EU Product Liability Directive (Directive (EU) 2024/2853)
3 source controls mapped|2 target controls covered
8%
EU Machinery Regulation (Regulation (EU) 2023/1230)
2 source controls mapped|1 target controls covered
6%
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data
2 source controls mapped|2 target controls covered
6%
EU Cyber Resilience Act
1 source controls mapped|1 target controls covered
3%

Frequently Asked Questions

What is EU AI Act?

EU AI Act is a compliance framework from European Union with 10 domains and 36 controls. The world's first comprehensive AI regulation, establishing risk-based rules for the placing on the market, putting into service and use of AI systems in the Union. Adopted 13 Jun 2024 (OJ L 1689/2024); entered into force 1 Aug 2024 with staged application: prohibited practices and AI literacy from 2 Feb 2025; GPAI obligations from 2 Aug 2025; most high-risk AI obligations from 2 Aug 2026; full application from 2 Aug 2027. 113 articles across 13 chapters: general provisions, prohibited AI practices, high-risk AI systems (classification, requirements, operator obligations, notified bodies, conformity assessment, standards), transparency for certain AI, general-purpose AI models (incl systemic-risk GPAI), measures for innovation (regulatory sandboxes), governance (AI Office, AI Board, scientific panel), the EU database for high-risk AI, post-market monitoring and market surveillance, codes of conduct and guidelines, delegation/committee, penalties, and final provisions including the right to explanation of individual decision-making. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does EU AI Act have?

EU AI Act has 36 controls organised across 10 domains. The largest domains are EU AI Act - High-Risk Classification and Requirements (9 controls), EU AI Act - High-Risk Operator Obligations (6 controls), EU AI Act - General-Purpose AI Models (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does EU AI Act map to?

EU AI Act maps to 7 other compliance frameworks. The top mapping partners are EU AI Liability Directive (31% coverage), NIST AI Risk Management Framework (AI RMF 1.0) (28% coverage), GDPR (14% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with EU AI Act compliance?

Start your EU AI Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EU AI Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 36 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required