EU AI Act
The world's first comprehensive AI regulation, establishing risk-based rules for the placing on the market, putting into service and use of AI systems in the Union. Adopted 13 Jun 2024 (OJ L 1689/2024); entered into force 1 Aug 2024 with staged application: prohibited practices and AI literacy from 2 Feb 2025; GPAI obligations from 2 Aug 2025; most high-risk AI obligations from 2 Aug 2026; full application from 2 Aug 2027. 113 articles across 13 chapters: general provisions, prohibited AI practices, high-risk AI systems (classification, requirements, operator obligations, notified bodies, conformity assessment, standards), transparency for certain AI, general-purpose AI models (incl systemic-risk GPAI), measures for innovation (regulatory sandboxes), governance (AI Office, AI Board, scientific panel), the EU database for high-risk AI, post-market monitoring and market surveillance, codes of conduct and guidelines, delegation/committee, penalties, and final provisions including the right to explanation of individual decision-making.
EU AI Act is a compliance framework from European Union with 10 domains and 64 controls that map to 14 other frameworks. The largest domains are EU AI Act - High-Risk Operator Obligations (13 controls), EU AI Act - High-Risk Classification and Requirements (10 controls), EU AI Act - Notified Bodies, Standards and Conformity Assessment (9 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
EU AI Act - Codes, Penalties and Final Provisions
| Code | Title |
|---|---|
| EUAI-Art.102-110 | Amendments to other Union legal acts |
| EUAI-Art.111-113 | Transitional provisions, evaluation and entry into force (Arts 111 to 113) |
| EUAI-Art.95-96 | Codes of conduct and Commission guidelines (Arts 95 to 96) |
| EUAI-Art.97-98 | Exercise of the delegation and committee procedure |
| EUAI-Art.99-101 | Penalties and administrative fines (Arts 99 to 101) |
EU AI Act - General Provisions and Prohibited Practices
| Code | Title |
|---|---|
| EUAI-Art.4 | AI literacy |
| EUAI-Art.5 | Prohibited AI practices |
EU AI Act - General-Purpose AI Models
| Code | Title |
|---|---|
| EUAI-Art.51 | Classification of general-purpose AI models as general-purpose AI models with systemic risk |
| EUAI-Art.52 | Procedure |
| EUAI-Art.53 | Obligations for providers of general-purpose AI models |
| EUAI-Art.54 | Authorised representatives of providers of general-purpose AI models |
| EUAI-Art.55 | Obligations of providers of GPAI models with systemic risk |
| EUAI-Art.56 | Codes of practice |
EU AI Act - Governance and EU Database
| Code | Title |
|---|---|
| EUAI-Art.64-66 | AI Office and European Artificial Intelligence Board (Arts 64 to 66) |
| EUAI-Art.67-70 | Advisory forum, scientific panel and national competent authorities (Arts 67 to 70) |
| EUAI-Art.71 | EU database for high-risk AI systems |
EU AI Act - High-Risk Classification and Requirements
| Code | Title |
|---|---|
| EUAI-Art.10 | Data and data governance |
| EUAI-Art.11 | Technical documentation |
| EUAI-Art.12 | Record-keeping (logs) |
| EUAI-Art.13 | Transparency and provision of information to deployers |
| EUAI-Art.14 | Human oversight |
| EUAI-Art.15 | Accuracy, robustness and cybersecurity |
| EUAI-Art.6 | Classification rules for high-risk AI systems |
| EUAI-Art.6-7 | Amendment of Annex III by delegated act (Art.7) |
| EUAI-Art.8 | Compliance with the requirements |
| EUAI-Art.9 | Risk management system |
EU AI Act - High-Risk Operator Obligations
| Code | Title |
|---|---|
| EUAI-Art.16 | Obligations of providers of high-risk AI systems |
| EUAI-Art.17 | Quality management system |
| EUAI-Art.18 | Documentation keeping |
| EUAI-Art.19 | Automatically generated logs |
| EUAI-Art.20 | Corrective actions and duty of information |
| EUAI-Art.21 | Cooperation with competent authorities |
| EUAI-Art.22 | Authorised representatives of providers of high-risk AI systems |
| EUAI-Art.23 | Obligations of importers |
| EUAI-Art.24 | Obligations of distributors |
| EUAI-Art.25 | Responsibilities along the AI value chain |
| EUAI-Art.26 | Obligations of deployers of high-risk AI systems |
| EUAI-Art.27 | Fundamental rights impact assessment for high-risk AI systems |
EU AI Act - Innovation Measures
| Code | Title |
|---|---|
| EUAI-Art.57-63 | AI regulatory sandboxes and measures for SMEs (Arts 57, 58, 62 and 63) |
| EUAI-Art.59 | Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox |
| EUAI-Art.60 | Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes |
| EUAI-Art.61 | Informed consent to participate in testing in real world conditions outside AI regulatory sandboxes |
EU AI Act - Notified Bodies, Standards and Conformity Assessment
| Code | Title |
|---|---|
| EUAI-Art.28-39 | Notifying authorities and notified bodies (Arts 28 to 39) |
| EUAI-Art.40-42 | Harmonised standards and presumption of conformity (Arts 40 and 42) |
| EUAI-Art.41 | Common specifications |
| EUAI-Art.43 | Conformity assessment |
| EUAI-Art.46 | Derogation from conformity assessment procedure |
| EUAI-Art.47 | EU declaration of conformity |
| EUAI-Art.48 | CE marking |
| EUAI-Art.49 | Registration |
EU AI Act - Post-Market Monitoring, Market Surveillance and Rights
| Code | Title |
|---|---|
| EUAI-Art.72 | Post-market monitoring by providers and post-market monitoring plan for high-risk AI systems |
| EUAI-Art.73 | Reporting of serious incidents |
| EUAI-Art.74-83 | Market surveillance and enforcement procedures (Arts 74 to 83) |
| EUAI-Art.84-87 | Union AI testing support structures and the right to lodge a complaint (Arts 84 to 85) |
| EUAI-Art.86 | Right to explanation of individual decision-making |
| EUAI-Art.87 | Reporting of infringements and protection of reporting persons |
| EUAI-Art.88-94 | Commission supervision and enforcement for general-purpose AI models (Arts 88 to 94) |
EU AI Act - Transparency Obligations
| Code | Title |
|---|---|
| EUAI-Art.50 | Transparency obligations for providers and deployers of certain AI systems |
Your Compliance Coverage
If you comply with EU AI Act, you already cover:
ISO/IEC 42001:2023
98%
42 controls mapped
Compare →NIST SP 800-53 Rev 5
91%
39 controls mapped
Compare →SOC 2
77%
33 controls mapped
Compare →+ 11 more: ISO 27001:2022 (77%), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (67%)
See all 14 mapped frameworks ↓Maps to 14 other frameworks
What is EU AI Act and who does it apply to?
EU AI Act is a compliance framework from European Union with 10 domains and 64 controls. The world's first comprehensive AI regulation, establishing risk-based rules for the placing on the market, putting into service and use of AI systems in the Union. Adopted 13 Jun 2024 (OJ L 1689/2024); entered into force 1 Aug 2024 with staged application: prohibited practices and AI literacy from 2 Feb 2025; GPAI obligations from 2 Aug 2025; most high-risk AI obligations from 2 Aug 2026; full application from 2 Aug 2027. 113 articles across 13 chapters: general provisions, prohibited AI practices, high-risk AI systems (classification, requirements, operator obligations, notified bodies, conformity assessment, standards), transparency for certain AI, general-purpose AI models (incl systemic-risk GPAI), measures for innovation (regulatory sandboxes), governance (AI Office, AI Board, scientific panel), the EU database for high-risk AI, post-market monitoring and market surveillance, codes of conduct and guidelines, delegation/committee, penalties, and final provisions including the right to explanation of individual decision-making. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does EU AI Act actually require?
EU AI Act has 64 controls organised across 10 domains. The largest domains are EU AI Act - High-Risk Operator Obligations (13 controls), EU AI Act - High-Risk Classification and Requirements (10 controls), EU AI Act - Notified Bodies, Standards and Conformity Assessment (9 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of EU AI Act do I already cover?
EU AI Act maps to 14 other compliance frameworks. The top mapping partners are ISO/IEC 42001:2023 (98% coverage), NIST SP 800-53 Rev 5 (91% coverage), SOC 2 (77% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement EU AI Act?
Start your EU AI Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EU AI Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 64 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required