Regulation · AI · European Union

EU AI Act compliance: risk classes, obligations and the 2027 deadlines

EU AI Act compliance means classifying every AI system you build or use by risk, then meeting the duties for its class. Prohibited practices are banned since February 2025, transparency duties apply from August 2026, and high-risk obligations apply from 2 December 2027 after the 2026 Digital Omnibus.

Key takeaways

What you need to know about EU AI Act

Risk-basedObligations depend on whether a system is prohibited, high-risk, transparency-only or minimal risk.
Providers and deployersBuilders carry most duties, but companies that use high-risk AI have their own.
ExtraterritorialIt applies to providers outside the EU whose AI is used in the EU.
More time for high-riskThe omnibus moved Annex III duties to 2 December 2027.
ISO 42001 helpsA certified AI management system covers much of the QMS and risk work.

Who must comply with the EU AI Act?

Anyone who places AI on the EU market or uses it in the EU, whatever their location.

AI providersCompanies that develop AI systems or general-purpose models and place them on the EU market.
DeployersOrganisations using AI systems in the EU, such as HR teams screening CVs.
Importers and distributorsCompanies bringing third-party AI systems into the EU market.
Non-EU companiesProviders abroad whose AI output is used in the EU.
Product manufacturersMakers of products with AI safety components under Annex I law.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the law requires

What does the EU AI Act require?

The EU AI Act requires you to classify AI systems by risk. Prohibited uses are banned, high-risk systems need risk management, documentation, oversight and conformity assessment, and chatbots and generated content need transparency.

Art. 5 Banned

Prohibited practices

Social scoring, manipulation, some biometric uses and abusive content generation.

In QULDEX: Screening on every inventory entry
Art. 6 Classify

High-risk classification

Annex I safety components and Annex III use areas.

In QULDEX: Classification record per system
Art. 9–15 Build

Provider requirements

Risk management, data, documentation, logging, oversight, robustness.

In QULDEX: Requirements mapped to evidence
Art. 17 QMS

Quality management system

Documented processes across the lifecycle.

In QULDEX: QMS mapped to ISO 42001
Art. 26–27 Use

Deployer duties

Use per instructions, oversight, logs, FRIA where required.

In QULDEX: Deployer tasks per system
Art. 50 Disclose

Transparency

Tell users about AI and mark synthetic content.

In QULDEX: Disclosure tracking
Art. 53–55 GPAI

General-purpose models

Documentation, copyright policy, systemic-risk duties.

In QULDEX: Model documentation file
Article explorer

Which EU AI Act articles matter most?

These 21 articles carry the obligations most organisations work on, grouped by role. Select any article to see what it requires, typical evidence and the matching ISO 42001 control.

Feb 2025prohibitions apply
Aug 2025GPAI duties apply
Aug 2026transparency applies
Dec 2027Annex III high-risk

Showing up to 6 per group. Search, filter, or open a group to see all 21.

Risk classes 4

  1. Art. 5Prohibited AI practices

    Bans manipulative techniques, social scoring, untargeted facial-image scraping, emotion recognition at work and in education, and (since the 2026 omnibus) AI that generates non-consensual intimate content or CSAM.

    In QULDEXEach AI system in the inventory records a prohibited-practice check.

    Typical evidence
    AI inventory with Art. 5 screening
    Maps to
    ISO 42001 A.5

  2. Art. 6Classification of high-risk AI

    An AI system is high-risk if it is a safety component of a product under Annex I law, or is used in an Annex III area such as employment, credit or education.

    In QULDEXClassification decisions are recorded per system with the reasoning.

    Typical evidence
    Classification record
    Maps to
    ISO 42001 6.1.4

  3. Annex IIIHigh-risk use areas

    Biometrics, critical infrastructure, education, employment, essential services and credit, law enforcement, migration and justice.

    In QULDEXAnnex III areas are tags on each AI system.

  4. Art. 50Transparency obligations

    Tell people when they interact with AI, mark synthetic content, and disclose deepfakes and AI-generated public-interest text.

    In QULDEXTransparency notices are tracked per system and channel.

    Typical evidence
    Disclosure texts, content-marking evidence
    Maps to
    ISO 42001 A.8.2

Provider obligations 11

  1. Art. 9Risk management system

    Providers run a risk management process across the high-risk system's lifecycle.

    In QULDEXThe AI risk register holds risks, treatments and reviews.

    Typical evidence
    AI risk register
    Maps to
    ISO 42001 6.1A.5.2

  2. Art. 10Data and data governance

    Training, validation and test data must be relevant, representative and examined for bias.

    In QULDEXData governance evidence is linked to each model version.

    Typical evidence
    Data sheets, bias examination
    Maps to
    ISO 42001 A.7

  3. Art. 11Technical documentation

    Draw up Annex IV technical documentation before placing the system on the market.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.

    Typical evidence
    Annex IV file
    Maps to
    ISO 42001 A.6.2.7

  4. Art. 12Record-keeping

    Systems must log events automatically to support traceability.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.

    Typical evidence
    Logging design, log samples
    Maps to
    ISO 42001 A.6.2.8

  5. Art. 13Transparency to deployers

    Give deployers instructions for use covering capabilities, limits and oversight.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.

    Typical evidence
    Instructions for use

  6. Art. 14Human oversight

    Design systems so people can oversee, interpret and stop them.

    In QULDEXOversight measures are tested like any other control.

    Typical evidence
    Oversight design and test results

  7. Art. 15Accuracy, robustness and cybersecurity

    Achieve appropriate accuracy, robustness and cybersecurity throughout the lifecycle.

    In QULDEXSecurity evidence is reused from ISO 27001.

    Typical evidence
    Test reports, security controls
    Maps to
    ISO 27001 A.8.25–A.8.29

  8. Art. 17Quality management system

    Providers keep a documented QMS covering design, testing, data and post-market monitoring.

    In QULDEXThe QMS maps to ISO 42001 clauses already in QULDEX.

    Typical evidence
    QMS manual
    Maps to
    ISO 42001 4–10ISO 9001

  9. Art. 43Conformity assessment

    Most Annex III systems use internal control; some biometric systems need a notified body.

    In QULDEXAssessment steps and evidence sit in the audit workspace.

    Typical evidence
    Conformity assessment file

  10. Art. 49Registration

    Register high-risk systems in the EU database before placing them on the market.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.

    Typical evidence
    EU database entry

  11. Art. 72–73Post-market monitoring and incidents

    Monitor systems in use and report serious incidents to market surveillance authorities.

    In QULDEXIncidents are logged with reporting deadlines.

    Typical evidence
    Monitoring plan, incident log
    Maps to
    ISO 42001 A.6.2.6

Deployer obligations 3

  1. Art. 26Obligations of deployers

    Use high-risk systems per instructions, assign human oversight, monitor operation, keep logs and inform workers.

    In QULDEXDeployer duties are tasks with owners per system.

    Typical evidence
    Use procedures, oversight assignments

  2. Art. 27Fundamental rights impact assessment

    Public bodies and some private deployers (credit, insurance) assess impacts on fundamental rights before use.

    In QULDEXThe FRIA runs as an assessment in QULDEX with sign-off.

    Typical evidence
    FRIA record
    Maps to
    ISO 42001 A.5.4

  3. Art. 4AI literacy

    Organisations should ensure staff have sufficient AI literacy; the 2026 omnibus simplified this duty and gave the Commission and Member States a stronger role.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.

    Typical evidence
    Training records

GPAI and penalties 3

  1. Art. 53General-purpose AI model providers

    Keep technical documentation, give information to downstream providers, respect copyright and publish a training-content summary.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.

    Typical evidence
    Model documentation, training summary

  2. Art. 55GPAI models with systemic risk

    Evaluate models, assess and mitigate systemic risks, report serious incidents and ensure cybersecurity.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.

    Typical evidence
    Evaluation reports

  3. Art. 99Penalties

    Up to €35m or 7% of worldwide turnover for prohibited practices, €15m or 3% for most other breaches, and €7.5m or 1% for misleading information.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to ISO 42001 so one AI governance programme serves both.

Article numbers follow Regulation (EU) 2024/1689 as amended by the 2026 AI Omnibus. Summaries are QULDEX paraphrases, not legal advice; the official text is the authority.

Compliance path

How do you prepare for the EU AI Act?

There is no EU AI Act certificate for most systems. You inventory AI, classify it, close the gaps for each class and keep evidence. Most organisations need 6 to 12 months for high-risk systems, so December 2027 is closer than it looks.

  1. Build an AI inventory

    List every AI system you build, buy or use, with its purpose, data and owner.

  2. Classify by risk and role

    Screen for prohibited practices, check Annex I and III, and record whether you are provider, deployer or both.

  3. Close transparency gaps now

    Article 50 duties apply from August 2026: disclose AI interactions and mark synthetic content.

  4. Build the high-risk controls

    Risk management, data governance, technical documentation, logging, human oversight and a QMS.

  5. Conformity assessment and registration

    Run internal control or a notified-body assessment, sign the EU declaration and register in the EU database.

  6. Monitor after launch

    MonitorPost-market monitoring plan
    ReportSerious incidents to authorities
    UpdateRe-assess on substantial change

Dates follow Regulation (EU) 2024/1689 as amended by the AI Omnibus (in force 27 July 2026). Durations are QULDEX planning ranges.

Records to keep

Which documents does EU AI Act compliance need?

For high-risk systems the Act names the technical documentation in Annex IV. These records cover the rest of the duties most organisations face.

DocumentArticleWhere it lives in QULDEX
AI system inventory and classificationArt. 6Risk register
Prohibited-practice screeningArt. 5Control library
Risk management fileArt. 9Risk register
Data governance and bias examinationArt. 10Evidence vault
Annex IV technical documentationArt. 11Evidence vault
Instructions for useArt. 13Evidence vault
Quality management systemArt. 17Policy library
EU declaration of conformityArt. 47Audit workspace
Fundamental rights impact assessmentArt. 27Audit workspace
Post-market monitoring plan and incident logArt. 72–73CAPA automation

Document names follow the Act; storage locations are QULDEX recommendations.

Time and cost

How long does EU AI Act compliance take and what drives the effort?

Transparency-only obligations take weeks. A high-risk system usually takes 6 to 12 months to document, test and assess, depending on data quality, how many systems you have and whether you already run ISO 42001.

Where the time goes

Inventory and classification4–10 wk
Transparency fixes2–6 wk
High-risk controls4–9 mo
Conformity assessment1–3 mo
Monitoring set-up1–2 mo

Bars show the upper end of each range on one scale (12 months = full width).

What changes the effort

  • Number of AI systems: each needs classification and records
  • High-risk use areas: Annex III systems carry most of the work
  • Provider vs deployer: providers carry the build-time duties
  • Data quality: bias examination can surface rework
  • ISO 42001 in place: its QMS and risk process carry over
Readiness check · 2 minutes

How ready are you for the EU AI Act?

Check these eight things first. Nothing you enter leaves this page.

Art. 6Do you have an inventory of every AI system you build, buy or use?
Art. 5Have you screened each system for prohibited practices?
Art. 6Is each system classified by risk class and your role?
Art. 50Do users know when they deal with AI, and is synthetic content marked?
Art. 9Do high-risk systems have a documented risk management process?
Art. 11Is Annex IV technical documentation in place for high-risk systems?
Art. 14Are human oversight measures designed and tested?
Art. 26Do deployers follow instructions, keep logs and assign oversight?
Crosswalk

How the EU AI Act maps to ISO 42001, GDPR and NIST AI RMF

ISO 42001 gives you the management system the Act expects of providers; GDPR still governs personal data in AI. One AI governance programme can serve all three.

EU AI Act vs ISO 42001 at a glance

EU AI ActISO/IEC 42001:2023
TypeBinding EU regulationVoluntary, certifiable standard
ScopeAI systems by risk classAny organisation's AI management system
OutcomeConformity assessment and CE marking for high-riskCertificate from an accredited body
RiskDefined risk classes and prohibited usesOrganisation-defined AI risk assessment
PenaltyUp to €35m or 7% of turnoverNone; certificate can be withdrawn
In QULDEXQULDEX maps each Act article to ISO 42001 clauses and controls, so one evidence set serves both.

AI governance crosswalk

EU AI ActISO 42001GDPRNIST AI RMFShared evidence
Art. 6 Classification6.1.4 AI system impactArt. 35 DPIAMAPClassification record
Art. 9 Risk management6.1.2–6.1.3Art. 32MANAGEAI risk register
Art. 10 Data governanceA.7Art. 5, 9MEASUREData sheets
Art. 11 DocumentationA.6.2.7Art. 30GOVERNTechnical file
Art. 14 Human oversightA.9Art. 22MANAGEOversight tests
Art. 17 QMSClauses 4–10Art. 24GOVERNQMS manual
Art. 27 FRIAA.5.4Art. 35MAPImpact assessment
Art. 72 Monitoring9.1—MEASUREMonitoring plan

Indicative mapping for planning, not legal advice. The full crosswalk is in the QULDEX control library.

Where QULDEX fits

How QULDEX runs EU AI Act compliance from inventory to conformity

QULDEX is EU AI Act compliance and audit management software built from EGV Group's audit delivery, used by AI providers and deployers, their advisors and the notified bodies and auditors who check them. Pick your role to see who does what.

For companies building or using AI in the EU.

  1. InventoryList AI systemsAI inventory with owners and purposes
  2. ClassifyClassify each systemClassification record with reasoning
  3. BuildImplement controlsRequirements mapped to evidence
  4. AssessRun conformity assessmentAssessment file in the audit workspace
  5. RegisterRegister and declareDeclaration and database entry tracked
  6. MonitorMonitor and report incidentsIncident log with deadlines
Without one systemWith QULDEX
AI tools adopted without a recordOne AI inventory with owners
High-risk decisions in emailClassification records with reasoning
Separate AI Act and ISO 42001 projectsOne programme mapped to both
Incidents found lateMonitoring with reporting deadlines
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

EU AI Act questions people ask

When does the EU AI Act apply?

It entered into force on 1 August 2024. Prohibitions apply since 2 February 2025, general-purpose AI duties since 2 August 2025 and transparency duties from 2 August 2026. After the 2026 AI Omnibus, Annex III high-risk rules apply from 2 December 2027 and Annex I product rules from 2 August 2028.

What did the AI Omnibus change?

It delayed high-risk obligations, simplified AI literacy and some registration duties, extended SME relief to small mid-caps, allowed special-category data to detect bias, and banned AI that generates non-consensual intimate content or CSAM. It entered into force on 27 July 2026.

What are the EU AI Act penalties?

Up to €35 million or 7% of worldwide annual turnover for prohibited practices, up to €15 million or 3% for most other breaches, and up to €7.5 million or 1% for supplying incorrect or misleading information.

Does the EU AI Act apply to companies outside the EU?

Yes. It applies to providers placing AI on the EU market and to providers and deployers abroad when the AI system's output is used in the EU.

Does ISO 42001 certification mean EU AI Act compliance?

No, but it helps. ISO 42001 gives you the management system, risk process and documentation the Act expects; high-risk systems still need their specific requirements and conformity assessment.

Sources

References

  1. Regulation (EU) 2024/1689 (Artificial Intelligence Act). eur-lex.europa.eu
  2. AI Omnibus enters into force, European Commission, 27 Jul 2026. digital-strategy.ec.europa.eu
  3. Timeline for the implementation of the EU AI Act, AI Act Service Desk. ai-act-service-desk.ec.europa.eu
  4. Digital Omnibus on AI, EPRS briefing, 2026. europarl.europa.eu
  5. ISO/IEC 42001:2023. iso.org

Reviewed by

Abhishek Yadav

Lead Auditor · QULDEX

Reviewed this page against Regulation (EU) 2024/1689 and the 2026 AI Omnibus: risk classes, obligations, penalties and dates.

Page history
  • : Page first built: article explorer, omnibus timeline, readiness check and ISO 42001 crosswalk

Find your EU AI Act gaps before December 2027

Answer a short readiness check and get a gap summary by article. No sales call needed to see the result.

Schedule
Book a Demo