The 2026 guide to operationalising the EU AI Act

The AI Act is now in force and is being rolled out in phases across the EU. Here is a practical guide to turning its requirements into controls, evidence and oversight that actually work — in conjunction with ISO 42001.

The iComply Team
AI Governance

EU AI Act Guide

The EU’s Artificial Intelligence Regulation is the world’s first comprehensive piece of legislation on artificial intelligence. For compliance, legal and security leaders, the question is no longer whether it applies — it is how to implement it without creating yet another siloed programme. This guide breaks the Regulation down into actionable parts and shows how it fits in with the regulations already in place.

To whom the Regulation applies

The Regulation applies to the technology, not the company. It covers suppliers who develop or place AI systems on the EU market, organisations responsible for deployment that use AI professionally, and importers and intermediaries. It also has extraterritorial scope: if the output of your AI system is used in the EU, the Regulation may apply even if your organisation is based elsewhere. For most organisations, the conclusion is simple — they are almost certainly responsible for the implementation of AI at some stage, and need to know which obligations apply to each use.

The risk-based model

The Regulation classifies AI systems according to the risk they pose, and the obligations increase in line with that risk. Getting this classification right is the foundation for everything else.

  • Unacceptable risk. A small set of practices — such as social classification by public authorities and certain manipulative systems — are quite simply prohibited.
  • High risk. Systems used in employment, education, essential services, biometrics and critical infrastructure bear the heaviest responsibilities.
  • Limited risk. Systems that interact with people or generate content have a duty of transparency — users must be aware that they are dealing with AI.
  • Minimal risk. The vast majority of systems remain as they are, with no new obligations.
  • General-purpose AI (GPAI). Foundational models have their own layer of documentation and, for the most sophisticated ones, systemic risk obligations.

The obligations that create work

For high-risk systems, the Regulation requires that it be demonstrated — with evidence — that the system is governed throughout its life cycle:

  • A risk management system that runs continuously, not just once.
  • Data governance relating to training, validation and test data.
  • Technical documentation and automatic event logging.
  • Human supervision with the ability to intervene and override.
  • Accuracy, robustness and cybersecurity appropriate to the use case.
  • Transparency so that those implementing the system and those affected by it can understand it.

How does ISO 42001 fit in?

The AI Act tells you what you must comply with; ISO 42001 — the AI management system standard — helps you put this into practice. Use them together: the management system provides you with the policies, roles, controls and continuous improvement, whilst the Regulation sets out the legal obligations that these controls must fulfil. Done properly, a single set of controls addresses both.

The first 90 days, in practice

  • List each AI system, use case, person responsible, dataset and model provider.
  • Classify each system according to its risk level and flag anything that is high-risk or prohibited.
  • Map controls for monitoring, logging, data governance and transparency — just once — and reuse them.
  • Assess high-risk systems using an AIDF and, where personal data is involved, an AIPD.
  • Identify and continuously monitor these issues, addressing any gaps before a regulator spots them.

The organisations that will suffer are those that treat the AI Act as a stand-alone project. Those that will thrive already manage security, privacy and risk within a single framework of controls — and simply add AI as another layer on top of those same controls and evidence.

Here’s how iComply puts this into practice

A platform for every regulation, law and risk — focused on controls and powered by AI.

Read on

Two interconnected circles representing the relationship between the ISO 42001 standard and the European AI Regulation

A management system meets a regulation — and why you operationalise both as a single AI governance suite.

Bar chart showing salaries within a defined range, illustrating an analysis of the gender pay gap at iComply

Analysis of pay gaps, pay bands and auditable remuneration criteria — what to implement now.

Seven ascending layers representing the stages involved in building a unified governance programme with iComply

A step-by-step approach to scope, controls, evidence and ongoing assurance — designed to be scalable across domains.