Regulation · AI · European Union
EU AI Act compliance means classifying every AI system you build or use by risk, then meeting the duties for its class. Prohibited practices are banned since February 2025, transparency duties apply from August 2026, and high-risk obligations apply from 2 December 2027 after the 2026 Digital Omnibus.
Anyone who places AI on the EU market or uses it in the EU, whatever their location.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
The EU AI Act requires you to classify AI systems by risk. Prohibited uses are banned, high-risk systems need risk management, documentation, oversight and conformity assessment, and chatbots and generated content need transparency.
Social scoring, manipulation, some biometric uses and abusive content generation.
In QULDEX: Screening on every inventory entryAnnex I safety components and Annex III use areas.
In QULDEX: Classification record per systemRisk management, data, documentation, logging, oversight, robustness.
In QULDEX: Requirements mapped to evidenceDocumented processes across the lifecycle.
In QULDEX: QMS mapped to ISO 42001Use per instructions, oversight, logs, FRIA where required.
In QULDEX: Deployer tasks per systemTell users about AI and mark synthetic content.
In QULDEX: Disclosure trackingDocumentation, copyright policy, systemic-risk duties.
In QULDEX: Model documentation fileThese 21 articles carry the obligations most organisations work on, grouped by role. Select any article to see what it requires, typical evidence and the matching ISO 42001 control.
Showing up to 6 per group. Search, filter, or open a group to see all 21.
Art. 5Prohibited AI practicesBans manipulative techniques, social scoring, untargeted facial-image scraping, emotion recognition at work and in education, and (since the 2026 omnibus) AI that generates non-consensual intimate content or CSAM.
In QULDEXEach AI system in the inventory records a prohibited-practice check.
Art. 6Classification of high-risk AIAn AI system is high-risk if it is a safety component of a product under Annex I law, or is used in an Annex III area such as employment, credit or education.
In QULDEXClassification decisions are recorded per system with the reasoning.
Annex IIIHigh-risk use areasBiometrics, critical infrastructure, education, employment, essential services and credit, law enforcement, migration and justice.
In QULDEXAnnex III areas are tags on each AI system.
Art. 50Transparency obligationsTell people when they interact with AI, mark synthetic content, and disclose deepfakes and AI-generated public-interest text.
In QULDEXTransparency notices are tracked per system and channel.
Art. 9Risk management systemProviders run a risk management process across the high-risk system's lifecycle.
In QULDEXThe AI risk register holds risks, treatments and reviews.
Art. 10Data and data governanceTraining, validation and test data must be relevant, representative and examined for bias.
In QULDEXData governance evidence is linked to each model version.
Art. 11Technical documentationDraw up Annex IV technical documentation before placing the system on the market.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.
Art. 12Record-keepingSystems must log events automatically to support traceability.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.
Art. 13Transparency to deployersGive deployers instructions for use covering capabilities, limits and oversight.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.
Art. 14Human oversightDesign systems so people can oversee, interpret and stop them.
In QULDEXOversight measures are tested like any other control.
Art. 15Accuracy, robustness and cybersecurityAchieve appropriate accuracy, robustness and cybersecurity throughout the lifecycle.
In QULDEXSecurity evidence is reused from ISO 27001.
Art. 17Quality management systemProviders keep a documented QMS covering design, testing, data and post-market monitoring.
In QULDEXThe QMS maps to ISO 42001 clauses already in QULDEX.
Art. 43Conformity assessmentMost Annex III systems use internal control; some biometric systems need a notified body.
In QULDEXAssessment steps and evidence sit in the audit workspace.
Art. 49RegistrationRegister high-risk systems in the EU database before placing them on the market.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.
Art. 72–73Post-market monitoring and incidentsMonitor systems in use and report serious incidents to market surveillance authorities.
In QULDEXIncidents are logged with reporting deadlines.
Art. 26Obligations of deployersUse high-risk systems per instructions, assign human oversight, monitor operation, keep logs and inform workers.
In QULDEXDeployer duties are tasks with owners per system.
Art. 27Fundamental rights impact assessmentPublic bodies and some private deployers (credit, insurance) assess impacts on fundamental rights before use.
In QULDEXThe FRIA runs as an assessment in QULDEX with sign-off.
Art. 4AI literacyOrganisations should ensure staff have sufficient AI literacy; the 2026 omnibus simplified this duty and gave the Commission and Member States a stronger role.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.
Art. 53General-purpose AI model providersKeep technical documentation, give information to downstream providers, respect copyright and publish a training-content summary.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.
Art. 55GPAI models with systemic riskEvaluate models, assess and mitigate systemic risks, report serious incidents and ensure cybersecurity.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.
Art. 99PenaltiesUp to €35m or 7% of worldwide turnover for prohibited practices, €15m or 3% for most other breaches, and €7.5m or 1% for misleading information.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.
Nothing matches that search.
Article numbers follow Regulation (EU) 2024/1689 as amended by the 2026 AI Omnibus. Summaries are QULDEX paraphrases, not legal advice; the official text is the authority.
There is no EU AI Act certificate for most systems. You inventory AI, classify it, close the gaps for each class and keep evidence. Most organisations need 6 to 12 months for high-risk systems, so December 2027 is closer than it looks.
List every AI system you build, buy or use, with its purpose, data and owner.
Screen for prohibited practices, check Annex I and III, and record whether you are provider, deployer or both.
Article 50 duties apply from August 2026: disclose AI interactions and mark synthetic content.
Risk management, data governance, technical documentation, logging, human oversight and a QMS.
Run internal control or a notified-body assessment, sign the EU declaration and register in the EU database.
Dates follow Regulation (EU) 2024/1689 as amended by the AI Omnibus (in force 27 July 2026). Durations are QULDEX planning ranges.
For high-risk systems the Act names the technical documentation in Annex IV. These records cover the rest of the duties most organisations face.
| Document | Article | Where it lives in QULDEX |
|---|---|---|
| AI system inventory and classification | Art. 6 | Risk register |
| Prohibited-practice screening | Art. 5 | Control library |
| Risk management file | Art. 9 | Risk register |
| Data governance and bias examination | Art. 10 | Evidence vault |
| Annex IV technical documentation | Art. 11 | Evidence vault |
| Instructions for use | Art. 13 | Evidence vault |
| Quality management system | Art. 17 | Policy library |
| EU declaration of conformity | Art. 47 | Audit workspace |
| Fundamental rights impact assessment | Art. 27 | Audit workspace |
| Post-market monitoring plan and incident log | Art. 72–73 | CAPA automation |
Document names follow the Act; storage locations are QULDEX recommendations.
Transparency-only obligations take weeks. A high-risk system usually takes 6 to 12 months to document, test and assess, depending on data quality, how many systems you have and whether you already run ISO 42001.
Bars show the upper end of each range on one scale (12 months = full width).
Check these eight things first. Nothing you enter leaves this page.
ISO 42001 gives you the management system the Act expects of providers; GDPR still governs personal data in AI. One AI governance programme can serve all three.
| EU AI Act | ISO/IEC 42001:2023 | |
|---|---|---|
| Type | Binding EU regulation | Voluntary, certifiable standard |
| Scope | AI systems by risk class | Any organisation's AI management system |
| Outcome | Conformity assessment and CE marking for high-risk | Certificate from an accredited body |
| Risk | Defined risk classes and prohibited uses | Organisation-defined AI risk assessment |
| Penalty | Up to €35m or 7% of turnover | None; certificate can be withdrawn |
| In QULDEX | QULDEX maps each Act article to ISO 42001 clauses and controls, so one evidence set serves both. | |
| EU AI Act | ISO 42001 | GDPR | NIST AI RMF | Shared evidence |
|---|---|---|---|---|
| Art. 6 Classification | 6.1.4 AI system impact | Art. 35 DPIA | MAP | Classification record |
| Art. 9 Risk management | 6.1.2–6.1.3 | Art. 32 | MANAGE | AI risk register |
| Art. 10 Data governance | A.7 | Art. 5, 9 | MEASURE | Data sheets |
| Art. 11 Documentation | A.6.2.7 | Art. 30 | GOVERN | Technical file |
| Art. 14 Human oversight | A.9 | Art. 22 | MANAGE | Oversight tests |
| Art. 17 QMS | Clauses 4–10 | Art. 24 | GOVERN | QMS manual |
| Art. 27 FRIA | A.5.4 | Art. 35 | MAP | Impact assessment |
| Art. 72 Monitoring | 9.1 | — | MEASURE | Monitoring plan |
Indicative mapping for planning, not legal advice. The full crosswalk is in the QULDEX control library.
QULDEX is EU AI Act compliance and audit management software built from EGV Group's audit delivery, used by AI providers and deployers, their advisors and the notified bodies and auditors who check them. Pick your role to see who does what.
For companies building or using AI in the EU.
For AI governance consultants and internal audit.
For notified bodies and ISO 42001 certification auditors.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →It entered into force on 1 August 2024. Prohibitions apply since 2 February 2025, general-purpose AI duties since 2 August 2025 and transparency duties from 2 August 2026. After the 2026 AI Omnibus, Annex III high-risk rules apply from 2 December 2027 and Annex I product rules from 2 August 2028.
It delayed high-risk obligations, simplified AI literacy and some registration duties, extended SME relief to small mid-caps, allowed special-category data to detect bias, and banned AI that generates non-consensual intimate content or CSAM. It entered into force on 27 July 2026.
Up to €35 million or 7% of worldwide annual turnover for prohibited practices, up to €15 million or 3% for most other breaches, and up to €7.5 million or 1% for supplying incorrect or misleading information.
Yes. It applies to providers placing AI on the EU market and to providers and deployers abroad when the AI system's output is used in the EU.
No, but it helps. ISO 42001 gives you the management system, risk process and documentation the Act expects; high-risk systems still need their specific requirements and conformity assessment.
What moved, what didn't and what to do now.
blog.quldex.comLive tracker of high-risk guidance and dates.
blog.quldex.comA worked example that also feeds the FRIA.
blog.quldex.comEU AI Act, ISO 42001 and NIST AI RMF articles.
Reviewed by
Answer a short readiness check and get a gap summary by article. No sales call needed to see the result.