← Back to blog

EU AI Act: the complete guide to compliance

EU AI Act: the complete guide to compliance

The EU AI Act is the world's first comprehensive law governing artificial intelligence — and its obligations reach any organisation whose AI touches the EU, wherever it is based. This guide explains what the Act is, the four risk categories, what high-risk systems must do, the updated timeline after the 2026 Digital Omnibus, the penalties, and how to comply, with deep-dive links to each topic. It pairs with our guides to AI governance and ISO 42001 certification.

AramGRC Team·AI Compliance & Assurance·September 11, 2026·14 min read

What is the EU AI Act?

The EU AI Act is a European Union regulation that governs how artificial intelligence systems are placed on the market and used in the EU. It entered into force on 1 August 2024 and takes a risk-based approach: the higher the risk an AI system poses to people's health, safety and fundamental rights, the stricter the obligations. Crucially, it applies extraterritorially — an organisation anywhere in the world must comply if its AI system is used in the EU or its outputs are used there.

The EU AI Act at a glance

  • What it is: — the world's first comprehensive, horizontal AI law.
  • In force: — entered into force 1 August 2024, applying in phases.
  • Approach: — risk-based — obligations scale with the system's risk tier.
  • Scope: — extraterritorial — applies to providers and deployers whose AI reaches the EU, wherever they are based.
  • Regulators: — the European AI Office and national market-surveillance authorities.
  • Penalties: — up to €35 million or 7% of worldwide annual turnover, whichever is higher.

Who does the EU AI Act apply to?

The Act reaches the whole value chain, but two roles carry most of the weight:

  • Providers — those who develop an AI system (or have it developed) and place it on the EU market under their name. Providers of high-risk systems carry the heaviest obligations.
  • Deployers — those who use an AI system in the course of their business in the EU.
  • Importers and distributors — also have duties.

Because it is extraterritorial, a US or Indian company whose AI product is used by EU customers is in scope just as much as an EU one.

The four risk categories

The Act sorts every AI system into one of four tiers:

  • Unacceptable risk (prohibited) — practices banned outright, such as social scoring by public authorities and certain manipulative or biometric practices.
  • High risk — AI used in areas like employment, credit scoring, education, essential services, biometric identification, and safety components of regulated products. These carry the full set of obligations.
  • Limited risk (transparency) — systems like chatbots and generative AI, which must meet transparency duties (people must know they're dealing with AI or seeing AI-generated content).
  • Minimal risk — everything else (spam filters, recommendation engines), with no specific obligations.

Your first compliance task is simply to classify each of your AI systems. We break the tiers down in EU AI Act risk categories.

What high-risk AI systems must do

If a system is high-risk, the provider must put in place a risk-management system, data governance, technical documentation, record-keeping/logging, transparency and instructions for use, human oversight, and appropriate accuracy, robustness and cybersecurity — then pass a conformity assessment leading to CE marking. Deployers have their own duties around use and human oversight. Full detail in EU AI Act requirements for high-risk AI.

The EU AI Act timeline (updated after the Digital Omnibus)

The Act applies in phases, and in 2026 the EU's Digital Omnibus package deferred the high-risk deadlines. The current timeline:

  • 1 August 2024 — the Act enters into force.
  • 2 February 2025 — prohibited (unacceptable-risk) practices are banned; new prohibitions were later added.
  • 2 August 2025 — obligations for general-purpose AI (GPAI) models apply.
  • 2 August 2026 — transparency obligations (Article 50) apply, along with governance and penalty provisions and national authorities.
  • 2 December 2027 — high-risk obligations for standalone (Annex III) systems apply — deferred from August 2026 by the Digital Omnibus.
  • 2 August 2028 — high-risk obligations for AI embedded in regulated products (Annex I) apply — deferred from August 2027.

See the full detail and what the Omnibus changed in EU AI Act timeline & deadlines.

EU AI Act penalties

Penalties are deliberately severe: up to €35 million or 7% of worldwide annual turnover for deploying prohibited AI practices, up to €15 million or 3% for breaching other obligations (including high-risk and transparency duties), and up to €7.5 million or 1% for supplying incorrect information to authorities. We break them down in EU AI Act penalties.

How to comply with the EU AI Act

Compliance starts with an inventory: list your AI systems, identify which reach the EU, classify each into a risk tier, then meet the obligations for that tier — for high-risk systems, the full risk-management, documentation, oversight and conformity-assessment programme. Aligning to ISO/IEC 42001 makes much of this far easier. Work through EU AI Act compliance.

The EU AI Act and general-purpose AI

Providers of general-purpose AI (GPAI) models — the large foundation models behind many AI products — have had their own obligations since August 2025: technical documentation, transparency about training data, and, for models posing systemic risk, additional evaluation and risk-mitigation duties. If you build on or provide a foundation model, these apply to you.

The EU AI Act and ISO 42001

The Act tells you what to achieve; ISO/IEC 42001 gives you a management system to achieve it. Because the standard's controls — AI inventory, risk and impact assessment, human oversight, data governance, monitoring — map closely onto the Act's high-risk requirements, an ISO 42001-aligned programme is one of the most efficient routes to EU AI Act readiness. See ISO 42001 certification.

The EU AI Act beyond Europe

Like the GDPR before it, the EU AI Act is becoming a global benchmark. US and Indian AI companies selling into Europe must comply, and many are adopting its structure as their default even outside the EU, because it satisfies the strictest regime they face. For Indian organisations, it sits alongside the DPDP Act and India's own AI regulation.

Key takeaways

  • The EU AI Act is the world's first comprehensive AI law, in force since August 2024 and applying in phases.
  • It is risk-based and extraterritorial — any organisation whose AI reaches the EU is in scope.
  • The 2026 Digital Omnibus deferred high-risk obligations to December 2027 (standalone) and August 2028 (embedded), while transparency rules applied from August 2026.
  • Penalties reach €35M or 7% of global turnover.
  • ISO/IEC 42001 is the most efficient foundation for compliance.

How AramGRC helps

AramGRC runs EU AI Act conformity audits and readiness assessments that classify your systems, produce the Annex IV technical documentation the Act expects, and give you a clear, staged roadmap to each deadline. Read more in EU AI Act conformity assessment.

Frequently asked questions

What is the EU AI Act?+

The EU AI Act is the European Union's comprehensive law governing AI. It takes a risk-based approach, applies extraterritorially to any AI used in the EU, and entered into force on 1 August 2024, applying in phases.

Who does the EU AI Act apply to?+

Providers, deployers, importers and distributors of AI systems used in the EU — including companies based outside the EU whose AI reaches EU users, so it applies to US and Indian companies too.

What are the EU AI Act risk categories?+

Four: unacceptable risk (prohibited), high risk (full obligations), limited risk (transparency duties), and minimal risk (no specific obligations).

When does the EU AI Act come into force?+

It entered into force in August 2024 and applies in phases: prohibited practices from February 2025, GPAI from August 2025, transparency from August 2026, and — after the Digital Omnibus — high-risk obligations from December 2027 (standalone) and August 2028 (embedded).

Was the EU AI Act delayed?+

The high-risk obligations were deferred by the 2026 Digital Omnibus — standalone (Annex III) high-risk systems moved from August 2026 to December 2027, and embedded (Annex I) systems to August 2028. Prohibited practices, GPAI and transparency rules were not delayed.

What are the penalties under the EU AI Act?+

Up to €35 million or 7% of worldwide annual turnover for prohibited practices, €15 million or 3% for other breaches, and €7.5 million or 1% for supplying incorrect information.

Does the EU AI Act apply to US and non-EU companies?+

Yes — it applies extraterritorially to any provider or deployer whose AI system or its output is used in the EU, regardless of where the company is based.

How do I comply with the EU AI Act?+

Inventory your AI, identify which systems reach the EU, classify each by risk tier, and meet that tier's obligations — for high-risk systems the full risk-management, documentation, oversight and conformity-assessment programme. Aligning to ISO/IEC 42001 accelerates it.

EU AI ActAI ComplianceRegulation
WhatsApp