EU AI Act
The EU AI Act is the world's first comprehensive AI law. It classifies AI by risk tier, bans certain uses, imposes conformity assessment on high-risk systems, and creates specific obligations for general-purpose AI models. Prohibitions took effect February 2025; GPAI obligations August 2025; high-risk obligations largely August 2026.
Who it applies to
Providers and deployers of AI systems placed on the EU market, plus certain uses of general-purpose AI models.
How ISO-STANDARD.app helps with EU AI Act
10 in-depth articles
The four risk tiers of the EU AI Act
Prohibited, high-risk, limited-risk, minimal-risk. Getting your system's tier wrong is the fastest way to non-compliance.
Prohibited practices
Social scoring by public authorities, real-time remote biometric identification in public spaces (with narrow exceptions), emotion recognition in workplaces and schools, exploitative manipulation. These are bans, not risk assessments.
High-risk
AI in safety components of regulated products, or listed in Annex III (recruitment, education, essential services, law enforcement, migration, administration of justice). Conformity assessment required.
Limited-risk
Chatbots, deepfakes, and generative content need transparency notices — users must know they're interacting with AI.
Minimal risk
Everything else. No mandatory obligations under the Act, but voluntary codes of practice are encouraged.
How ISO-STANDARD.app helps with EU AI Act
Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.
High-risk AI: the nine mandatory requirements
Articles 9–15 set the obligations you must meet before placing a high-risk AI system on the market.
The nine
Risk management system, data governance, technical documentation, record-keeping, transparency to deployers, human oversight, accuracy/robustness/cybersecurity, quality management system, post-market monitoring.
Data governance
Training, validation and test datasets must be relevant, representative, free of errors and complete for the intended purpose. Documented data lineage is required.
Human oversight
Not a policy — a system feature. Users must be able to interpret the output, override decisions, and stop the system safely.
Post-market monitoring
Log real-world performance and report serious incidents to authorities. This continues for the system's operational life.
How ISO-STANDARD.app helps with EU AI Act
Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.
General-purpose AI model obligations
GPAI providers have their own regime — including the enhanced regime for models with systemic risk.
Baseline GPAI
Technical documentation, information to downstream deployers, copyright policy, training data summary. Applies to every GPAI provider.
Systemic risk threshold
Models trained above 10^25 FLOPs are presumed to pose systemic risk. The Commission can add or remove models based on additional criteria.
Systemic-risk GPAI extras
Model evaluation including adversarial testing, systemic risk assessment and mitigation, incident reporting, and cybersecurity of the model itself.
Code of Practice
The GPAI Code of Practice is the pragmatic way to demonstrate compliance until harmonised standards land. Sign it, and you get presumption of conformity.
How ISO-STANDARD.app helps with EU AI Act
Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.
Transparency obligations for deployers and providers
Article 50 is the article the marketing team needs to read. It's short and it applies broadly.
Chatbots and voice assistants
Users must know they're interacting with AI unless it's obvious. A one-line notice usually suffices.
AI-generated content
Providers of systems that generate synthetic content must mark it as artificially generated — increasingly via watermarking or provenance metadata.
Deepfakes and public interest content
Deployers of deepfakes must disclose it. Public-interest content has narrower carve-outs — journalistic use is treated differently but not exempted.
Emotion recognition and biometric categorisation
Explicit notice to affected individuals is required, even in limited-risk deployments.
How ISO-STANDARD.app helps with EU AI Act
Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.
Conformity assessment for high-risk AI
You self-assess against harmonised standards, or you go to a notified body. The choice depends on the Annex III use case.
Internal control assessment
Most Annex III high-risk systems use internal control — you follow harmonised standards, keep the technical file, and self-declare conformity.
Third-party notified body
Required for biometric categorisation and remote biometric identification. Notified bodies audit and certify — expect a multi-month process.
CE marking and EU declaration
High-risk AI systems carry CE marking and a declaration of conformity. The declaration names the specific harmonised standards applied.
Post-market changes
Substantial modifications trigger re-assessment. Log every change and decide on the reassessment threshold with clear criteria.
How ISO-STANDARD.app helps with EU AI Act
Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.
EU AI Act fines: up to €35M or 7% of turnover
The AI Act's fines are higher than GDPR's. Prohibited practices attract the top band.
Prohibited practices
€35M or 7% of global annual turnover — whichever is higher.
Non-compliance with obligations
€15M or 3% — for high-risk system obligations, GPAI provider obligations, transparency requirements.
Incorrect information to authorities
€7.5M or 1%. Includes late reporting, misleading responses to information requests.
SME discount
For SMEs and start-ups, the lower of the two applies rather than the higher. Small mitigation, meaningful in practice.
How ISO-STANDARD.app helps with EU AI Act
Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.
EU AI Act vs ISO 42001: how they fit together
ISO 42001 is a management system standard. The AI Act is law. Use one to deliver the other.
Different instruments
ISO 42001 tells you how to structure an AI Management System. The AI Act tells you what outcomes you must achieve. They don't conflict; they complement.
Presumption of conformity
A future ISO/EN standard for AI management is expected to give presumption of conformity for parts of the Act. Building on ISO 42001 now positions you for that.
Governance overlap
AI policy, risk register, impact assessment, supplier management, incident logging — all appear in both frameworks. Build once, use twice.
Certification value
ISO 42001 certification signals to buyers and regulators that you have a working management system for AI. AI Act compliance is a floor, not a ceiling.
How ISO-STANDARD.app helps with EU AI Act
Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.
The AI literacy obligation nobody talks about
Article 4 requires all providers and deployers to ensure staff have sufficient AI literacy. Effective February 2025.
Who it applies to
Every provider and deployer of AI in scope of the Act. Not just data science teams — every function that uses or is affected by AI.
What counts
Training that gives staff the knowledge, skills and understanding to make informed AI decisions. General 'awareness training' probably isn't enough.
Evidence
Attendance logs, materials, refresh cycles. Include agencies and outsourced staff who touch AI on your behalf.
Levels of literacy
Tailor to role: an executive making commissioning decisions needs different literacy from an engineer building the system. Both need something.
How ISO-STANDARD.app helps with EU AI Act
Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.
EU AI Act timeline: what applies when
The Act is phased. Missing a phase gate is missing the law.
2 February 2025
Prohibited practices become unlawful. AI literacy obligation applies. Do not deploy systems that fall in the prohibited category.
2 August 2025
GPAI model obligations apply for new models. Existing models get more time. Codes of Practice open for signature.
2 August 2026
High-risk system obligations largely apply. Conformity assessment, technical documentation, human oversight — all live.
2 August 2027
High-risk AI embedded in regulated products (Annex I) reaches its final compliance date. The Act is fully phased in.
How ISO-STANDARD.app helps with EU AI Act
Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.
Starting an EU AI Act programme: the first 60 days
Inventory, classify, prioritise. Then build the register that becomes your evidence pack.
Inventory
Every AI system in use — built, bought, embedded in tools. Shadow AI counts. Interview business functions, not just IT.
Classify
Against the risk tiers. This is where most programmes underestimate — Annex III catches more HR, education and administration tools than teams expect.
Prioritise
Anything prohibited: stop or remediate. Anything high-risk: start the conformity assessment pathway now. Anything transparency-only: add notices this quarter.
Register
One register of AI systems, with tier, purpose, data sources, human oversight approach, and evidence links. It's the artefact regulators will ask for.
How ISO-STANDARD.app helps with EU AI Act
Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.
Ready to evidence EU AI Act?
Load the pre-mapped controls, capture evidence continuously, and publish your EU AI Act posture to buyers on demand.
Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.