Back to Frameworks

EU AI Act

European Union
v2024-03-13
10 domains
64 controls

The world's first comprehensive AI regulation, establishing risk-based rules for the placing on the market, putting into service and use of AI systems in the Union. Adopted 13 Jun 2024 (OJ L 1689/2024); entered into force 1 Aug 2024 with staged application: prohibited practices and AI literacy from 2 Feb 2025; GPAI obligations from 2 Aug 2025; most high-risk AI obligations from 2 Aug 2026; full application from 2 Aug 2027. 113 articles across 13 chapters: general provisions, prohibited AI practices, high-risk AI systems (classification, requirements, operator obligations, notified bodies, conformity assessment, standards), transparency for certain AI, general-purpose AI models (incl systemic-risk GPAI), measures for innovation (regulatory sandboxes), governance (AI Office, AI Board, scientific panel), the EU database for high-risk AI, post-market monitoring and market surveillance, codes of conduct and guidelines, delegation/committee, penalties, and final provisions including the right to explanation of individual decision-making.

Verified

EU AI Act is a compliance framework from European Union with 10 domains and 64 controls that map to 14 other frameworks. The largest domains are EU AI Act - High-Risk Operator Obligations (13 controls), EU AI Act - High-Risk Classification and Requirements (10 controls), EU AI Act - Notified Bodies, Standards and Conformity Assessment (9 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (10)

EU AI Act - Codes, Penalties and Final Provisions

5 controls
Controls in the EU AI Act - Codes, Penalties and Final Provisions domain of EU AI Act5 controls
CodeTitle
EUAI-Art.102-110Amendments to other Union legal acts
EUAI-Art.111-113Transitional provisions, evaluation and entry into force (Arts 111 to 113)
EUAI-Art.95-96Codes of conduct and Commission guidelines (Arts 95 to 96)
EUAI-Art.97-98Exercise of the delegation and committee procedure
EUAI-Art.99-101Penalties and administrative fines (Arts 99 to 101)

EU AI Act - General Provisions and Prohibited Practices

3 controls
Controls in the EU AI Act - General Provisions and Prohibited Practices domain of EU AI Act2 controls
CodeTitle
EUAI-Art.4AI literacy
EUAI-Art.5Prohibited AI practices

EU AI Act - General-Purpose AI Models

8 controls
Controls in the EU AI Act - General-Purpose AI Models domain of EU AI Act6 controls
CodeTitle
EUAI-Art.51Classification of general-purpose AI models as general-purpose AI models with systemic risk
EUAI-Art.52Procedure
EUAI-Art.53Obligations for providers of general-purpose AI models
EUAI-Art.54Authorised representatives of providers of general-purpose AI models
EUAI-Art.55Obligations of providers of GPAI models with systemic risk
EUAI-Art.56Codes of practice

EU AI Act - Governance and EU Database

3 controls
Controls in the EU AI Act - Governance and EU Database domain of EU AI Act3 controls
CodeTitle
EUAI-Art.64-66AI Office and European Artificial Intelligence Board (Arts 64 to 66)
EUAI-Art.67-70Advisory forum, scientific panel and national competent authorities (Arts 67 to 70)
EUAI-Art.71EU database for high-risk AI systems

EU AI Act - High-Risk Classification and Requirements

10 controls
Controls in the EU AI Act - High-Risk Classification and Requirements domain of EU AI Act10 controls
CodeTitle
EUAI-Art.10Data and data governance
EUAI-Art.11Technical documentation
EUAI-Art.12Record-keeping (logs)
EUAI-Art.13Transparency and provision of information to deployers
EUAI-Art.14Human oversight
EUAI-Art.15Accuracy, robustness and cybersecurity
EUAI-Art.6Classification rules for high-risk AI systems
EUAI-Art.6-7Amendment of Annex III by delegated act (Art.7)
EUAI-Art.8Compliance with the requirements
EUAI-Art.9Risk management system

EU AI Act - High-Risk Operator Obligations

13 controls
Controls in the EU AI Act - High-Risk Operator Obligations domain of EU AI Act12 controls
CodeTitle
EUAI-Art.16Obligations of providers of high-risk AI systems
EUAI-Art.17Quality management system
EUAI-Art.18Documentation keeping
EUAI-Art.19Automatically generated logs
EUAI-Art.20Corrective actions and duty of information
EUAI-Art.21Cooperation with competent authorities
EUAI-Art.22Authorised representatives of providers of high-risk AI systems
EUAI-Art.23Obligations of importers
EUAI-Art.24Obligations of distributors
EUAI-Art.25Responsibilities along the AI value chain
EUAI-Art.26Obligations of deployers of high-risk AI systems
EUAI-Art.27Fundamental rights impact assessment for high-risk AI systems

EU AI Act - Innovation Measures

4 controls
Controls in the EU AI Act - Innovation Measures domain of EU AI Act4 controls
CodeTitle
EUAI-Art.57-63AI regulatory sandboxes and measures for SMEs (Arts 57, 58, 62 and 63)
EUAI-Art.59Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox
EUAI-Art.60Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes
EUAI-Art.61Informed consent to participate in testing in real world conditions outside AI regulatory sandboxes

EU AI Act - Notified Bodies, Standards and Conformity Assessment

9 controls
Controls in the EU AI Act - Notified Bodies, Standards and Conformity Assessment domain of EU AI Act8 controls
CodeTitle
EUAI-Art.28-39Notifying authorities and notified bodies (Arts 28 to 39)
EUAI-Art.40-42Harmonised standards and presumption of conformity (Arts 40 and 42)
EUAI-Art.41Common specifications
EUAI-Art.43Conformity assessment
EUAI-Art.46Derogation from conformity assessment procedure
EUAI-Art.47EU declaration of conformity
EUAI-Art.48CE marking
EUAI-Art.49Registration

EU AI Act - Post-Market Monitoring, Market Surveillance and Rights

8 controls
Controls in the EU AI Act - Post-Market Monitoring, Market Surveillance and Rights domain of EU AI Act7 controls
CodeTitle
EUAI-Art.72Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems
EUAI-Art.73Reporting of serious incidents
EUAI-Art.74-83Market surveillance and enforcement procedures (Arts 74 to 83)
EUAI-Art.84-87Union AI testing support structures and the right to lodge a complaint (Arts 84 to 85)
EUAI-Art.86Right to explanation of individual decision-making
EUAI-Art.87Reporting of infringements and protection of reporting persons
EUAI-Art.88-94Commission supervision and enforcement for general-purpose AI models (Arts 88 to 94)

EU AI Act - Transparency Obligations

1 controls
Controls in the EU AI Act - Transparency Obligations domain of EU AI Act1 controls
CodeTitle
EUAI-Art.50Transparency obligations for providers and deployers of certain AI systems

Your Compliance Coverage

If you comply with EU AI Act, you already cover:

Maps to 14 other frameworks

43 total controls
ISO/IEC 42001:2023
42 source controls mapped|38 target controls covered
98%
NIST SP 800-53 Rev 5
39 source controls mapped|86 target controls covered
91%
SOC 2
33 source controls mapped|47 target controls covered
77%
ISO 27001:2022
33 source controls mapped|45 target controls covered
77%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
29 source controls mapped|61 target controls covered
67%
NIST AI Risk Management Framework (AI RMF 1.0)
24 source controls mapped|62 target controls covered
56%
GDPR
21 source controls mapped|19 target controls covered
49%
NIS2 Directive
12 source controls mapped|14 target controls covered
28%
DORA
11 source controls mapped|10 target controls covered
26%
EU AI Liability Directive
9 source controls mapped|7 target controls covered
21%
EU Machinery Regulation (Regulation (EU) 2023/1230)
1 source controls mapped|1 target controls covered
2%
ISO/IEC 23894:2023
1 source controls mapped|2 target controls covered
2%
ISO 37301:2021
1 source controls mapped|1 target controls covered
2%
EU Cyber Resilience Act
1 source controls mapped|1 target controls covered
2%

What is EU AI Act and who does it apply to?

EU AI Act is a compliance framework from European Union with 10 domains and 64 controls. The world's first comprehensive AI regulation, establishing risk-based rules for the placing on the market, putting into service and use of AI systems in the Union. Adopted 13 Jun 2024 (OJ L 1689/2024); entered into force 1 Aug 2024 with staged application: prohibited practices and AI literacy from 2 Feb 2025; GPAI obligations from 2 Aug 2025; most high-risk AI obligations from 2 Aug 2026; full application from 2 Aug 2027. 113 articles across 13 chapters: general provisions, prohibited AI practices, high-risk AI systems (classification, requirements, operator obligations, notified bodies, conformity assessment, standards), transparency for certain AI, general-purpose AI models (incl systemic-risk GPAI), measures for innovation (regulatory sandboxes), governance (AI Office, AI Board, scientific panel), the EU database for high-risk AI, post-market monitoring and market surveillance, codes of conduct and guidelines, delegation/committee, penalties, and final provisions including the right to explanation of individual decision-making. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does EU AI Act actually require?

EU AI Act has 64 controls organised across 10 domains. The largest domains are EU AI Act - High-Risk Operator Obligations (13 controls), EU AI Act - High-Risk Classification and Requirements (10 controls), EU AI Act - Notified Bodies, Standards and Conformity Assessment (9 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of EU AI Act do I already cover?

EU AI Act maps to 14 other compliance frameworks. The top mapping partners are ISO/IEC 42001:2023 (98% coverage), NIST SP 800-53 Rev 5 (91% coverage), SOC 2 (77% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement EU AI Act?

Start your EU AI Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EU AI Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 64 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required