Skip to content

EU AI Act

Regulation (EU) 2024/1689. Different obligations depending on what you do with AI and how much risk it carries.

What the AI Act is

Regulation (EU) 2024/1689 governs the development, placing on the market and use of artificial intelligence systems in the European Union. It is a regulation, so it applies directly and needs no transposition.

Its logic is risk based. It classifies AI systems into levels and assigns obligations proportionate to each, from prohibited practices through to minimal risk systems with no specific obligations. And it distinguishes by role: provider, deployer, importer or distributor.

It applies in phases over time.

Who the AI Act applies to

  • Anyone developing and placing AI systems on the EU market
  • Anyone using them professionally within the EU
  • Providers outside the EU whose system, or its output, is used in the EU

It applies because of what you do with AI, not because of your sector. A company embedding an AI system in its product can be a provider without having developed it.

What the AI Act requires

It depends on the risk level and the role.

Prohibited practices. Certain uses are banned outright.

High risk. The heaviest block. Risk management system. Data governance. Technical documentation. Record keeping. Transparency towards the deployer. Human oversight. Accuracy, robustness and cybersecurity. Quality management system. Post-market monitoring.

Limited risk. Transparency obligations: a person must know they are interacting with an AI system.

General purpose AI models. A regime of their own for the providers of those models.

The obligations are not the same for a provider as for a deployer. Determining your role is the first step and it conditions everything after it.

How the AI Act is demonstrated

There is no certificate. It is a legal obligation supervised by national authorities. High risk systems have conformity assessment, marking and registration procedures set out in the Regulation itself.

With Zerod

The AI Act hands out obligations by your role and your risk. Zerod starts there.

You record your organisation's risk classification and the role you hold, and Zerod filters the 27-control register by it to show you the controls that apply to you. It generates the Article 9 policy and the Article 72 post-market monitoring plan, and organises evidence collection.

Frequently asked questions

How do I know whether my system is high risk?

The Regulation sets out the high risk cases in its articles and annexes. The determination is yours and depends on the system's purpose and where it is used.

Does the AI Act replace the GDPR?

No. They are separate laws that apply at the same time. An AI system that processes personal data is subject to both.

EU AI Act · Zerod