EU AI Act

The EU AI Act is the world's first comprehensive AI law. It classifies AI by risk tier, bans certain uses, imposes conformity assessment on high-risk systems, and creates specific obligations for general-purpose AI models. Prohibitions took effect February 2025; GPAI obligations August 2025; high-risk obligations largely August 2026.

Who it applies to

Providers and deployers of AI systems placed on the EU market, plus certain uses of general-purpose AI models.

How ISO-STANDARD.app helps with EU AI Act

Pre-loaded EU AI Act control mapping crosswalked to ISO 27001 Annex A so you don't duplicate work.

Evidence Vault stores signed, versioned artefacts (screenshots, logs, attestations) auditors and buyers accept.

Trust Center publishes your current EU AI Act posture to prospects on demand — no PDF chase.

Internal Audit, CAPA and Management Review workflows built in, mapped to EU AI Act clauses.

Policy templates with attestation, review cycles and change history that satisfy assessor sampling.

10 in-depth articles

The four risk tiers of the EU AI Act

Prohibited, high-risk, limited-risk, minimal-risk. Getting your system's tier wrong is the fastest way to non-compliance.

Prohibited practices

Social scoring by public authorities, real-time remote biometric identification in public spaces (with narrow exceptions), emotion recognition in workplaces and schools, exploitative manipulation. These are bans, not risk assessments.

High-risk

AI in safety components of regulated products, or listed in Annex III (recruitment, education, essential services, law enforcement, migration, administration of justice). Conformity assessment required.

Limited-risk

Chatbots, deepfakes, and generative content need transparency notices — users must know they're interacting with AI.

Minimal risk

Everything else. No mandatory obligations under the Act, but voluntary codes of practice are encouraged.

How ISO-STANDARD.app helps with EU AI Act

Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.

High-risk AI: the nine mandatory requirements

Articles 9–15 set the obligations you must meet before placing a high-risk AI system on the market.

The nine

Risk management system, data governance, technical documentation, record-keeping, transparency to deployers, human oversight, accuracy/robustness/cybersecurity, quality management system, post-market monitoring.

Data governance

Training, validation and test datasets must be relevant, representative, free of errors and complete for the intended purpose. Documented data lineage is required.

Human oversight

Not a policy — a system feature. Users must be able to interpret the output, override decisions, and stop the system safely.

Post-market monitoring

Log real-world performance and report serious incidents to authorities. This continues for the system's operational life.

How ISO-STANDARD.app helps with EU AI Act

Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.

General-purpose AI model obligations

GPAI providers have their own regime — including the enhanced regime for models with systemic risk.

Baseline GPAI

Technical documentation, information to downstream deployers, copyright policy, training data summary. Applies to every GPAI provider.

Systemic risk threshold

Models trained above 10^25 FLOPs are presumed to pose systemic risk. The Commission can add or remove models based on additional criteria.

Systemic-risk GPAI extras

Model evaluation including adversarial testing, systemic risk assessment and mitigation, incident reporting, and cybersecurity of the model itself.

Code of Practice

The GPAI Code of Practice is the pragmatic way to demonstrate compliance until harmonised standards land. Sign it, and you get presumption of conformity.

How ISO-STANDARD.app helps with EU AI Act

Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.

Transparency obligations for deployers and providers

Article 50 is the article the marketing team needs to read. It's short and it applies broadly.

Chatbots and voice assistants

Users must know they're interacting with AI unless it's obvious. A one-line notice usually suffices.

AI-generated content

Providers of systems that generate synthetic content must mark it as artificially generated — increasingly via watermarking or provenance metadata.

Deepfakes and public interest content

Deployers of deepfakes must disclose it. Public-interest content has narrower carve-outs — journalistic use is treated differently but not exempted.

Emotion recognition and biometric categorisation

Explicit notice to affected individuals is required, even in limited-risk deployments.

How ISO-STANDARD.app helps with EU AI Act

Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.

Conformity assessment for high-risk AI

You self-assess against harmonised standards, or you go to a notified body. The choice depends on the Annex III use case.

Internal control assessment

Most Annex III high-risk systems use internal control — you follow harmonised standards, keep the technical file, and self-declare conformity.

Third-party notified body

Required for biometric categorisation and remote biometric identification. Notified bodies audit and certify — expect a multi-month process.

CE marking and EU declaration

High-risk AI systems carry CE marking and a declaration of conformity. The declaration names the specific harmonised standards applied.

Post-market changes

Substantial modifications trigger re-assessment. Log every change and decide on the reassessment threshold with clear criteria.

How ISO-STANDARD.app helps with EU AI Act

Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.

EU AI Act fines: up to €35M or 7% of turnover

The AI Act's fines are higher than GDPR's. Prohibited practices attract the top band.

Prohibited practices

€35M or 7% of global annual turnover — whichever is higher.

Non-compliance with obligations

€15M or 3% — for high-risk system obligations, GPAI provider obligations, transparency requirements.

Incorrect information to authorities

€7.5M or 1%. Includes late reporting, misleading responses to information requests.

SME discount

For SMEs and start-ups, the lower of the two applies rather than the higher. Small mitigation, meaningful in practice.

How ISO-STANDARD.app helps with EU AI Act

Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.

EU AI Act vs ISO 42001: how they fit together

ISO 42001 is a management system standard. The AI Act is law. Use one to deliver the other.

Different instruments

ISO 42001 tells you how to structure an AI Management System. The AI Act tells you what outcomes you must achieve. They don't conflict; they complement.

Presumption of conformity

A future ISO/EN standard for AI management is expected to give presumption of conformity for parts of the Act. Building on ISO 42001 now positions you for that.

Governance overlap

AI policy, risk register, impact assessment, supplier management, incident logging — all appear in both frameworks. Build once, use twice.

Certification value

ISO 42001 certification signals to buyers and regulators that you have a working management system for AI. AI Act compliance is a floor, not a ceiling.

How ISO-STANDARD.app helps with EU AI Act

Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.

The AI literacy obligation nobody talks about

Article 4 requires all providers and deployers to ensure staff have sufficient AI literacy. Effective February 2025.

Who it applies to

Every provider and deployer of AI in scope of the Act. Not just data science teams — every function that uses or is affected by AI.

What counts

Training that gives staff the knowledge, skills and understanding to make informed AI decisions. General 'awareness training' probably isn't enough.

Evidence

Attendance logs, materials, refresh cycles. Include agencies and outsourced staff who touch AI on your behalf.

Levels of literacy

Tailor to role: an executive making commissioning decisions needs different literacy from an engineer building the system. Both need something.

How ISO-STANDARD.app helps with EU AI Act

Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.

EU AI Act timeline: what applies when

The Act is phased. Missing a phase gate is missing the law.

2 February 2025

Prohibited practices become unlawful. AI literacy obligation applies. Do not deploy systems that fall in the prohibited category.

2 August 2025

GPAI model obligations apply for new models. Existing models get more time. Codes of Practice open for signature.

2 August 2026

High-risk system obligations largely apply. Conformity assessment, technical documentation, human oversight — all live.

2 August 2027

High-risk AI embedded in regulated products (Annex I) reaches its final compliance date. The Act is fully phased in.

How ISO-STANDARD.app helps with EU AI Act

Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.

Starting an EU AI Act programme: the first 60 days

Inventory, classify, prioritise. Then build the register that becomes your evidence pack.

Inventory

Every AI system in use — built, bought, embedded in tools. Shadow AI counts. Interview business functions, not just IT.

Classify

Against the risk tiers. This is where most programmes underestimate — Annex III catches more HR, education and administration tools than teams expect.

Prioritise

Anything prohibited: stop or remediate. Anything high-risk: start the conformity assessment pathway now. Anything transparency-only: add notices this quarter.

Register

One register of AI systems, with tier, purpose, data sources, human oversight approach, and evidence links. It's the artefact regulators will ask for.

How ISO-STANDARD.app helps with EU AI Act

Inside the workspace, this topic maps to concrete artefacts: pre-loaded EU AI Act controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the EU AI Act shape.

Ready to evidence EU AI Act?

Load the pre-mapped controls, capture evidence continuously, and publish your EU AI Act posture to buyers on demand.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.