EU AI Act Guide
The EU’s Artificial Intelligence Regulation is the world’s first comprehensive piece of legislation on artificial intelligence. For compliance, legal and security leaders, the question is no longer whether it applies — it is how to implement it without creating yet another siloed programme. This guide breaks the Regulation down into actionable parts and shows how it fits in with the regulations already in place.
To whom the Regulation applies
The Regulation applies to the technology, not the company. It covers suppliers who develop or place AI systems on the EU market, organisations responsible for deployment that use AI professionally, and importers and intermediaries. It also has extraterritorial scope: if the output of your AI system is used in the EU, the Regulation may apply even if your organisation is based elsewhere. For most organisations, the conclusion is simple — they are almost certainly responsible for the implementation of AI at some stage, and need to know which obligations apply to each use.
The risk-based model
The Regulation classifies AI systems according to the risk they pose, and the obligations increase in line with that risk. Getting this classification right is the foundation for everything else.
- Unacceptable risk. A small set of practices — such as social classification by public authorities and certain manipulative systems — are quite simply prohibited.
- High risk. Systems used in employment, education, essential services, biometrics and critical infrastructure bear the heaviest responsibilities.
- Limited risk. Systems that interact with people or generate content have a duty of transparency — users must be aware that they are dealing with AI.
- Minimal risk. The vast majority of systems remain as they are, with no new obligations.
- General-purpose AI (GPAI). Foundational models have their own layer of documentation and, for the most sophisticated ones, systemic risk obligations.
The obligations that create work
For high-risk systems, the Regulation requires that it be demonstrated — with evidence — that the system is governed throughout its life cycle:
- A risk management system that runs continuously, not just once.
- Data governance relating to training, validation and test data.
- Technical documentation and automatic event logging.
- Human supervision with the ability to intervene and override.
- Accuracy, robustness and cybersecurity appropriate to the use case.
- Transparency so that those implementing the system and those affected by it can understand it.
How does ISO 42001 fit in?
The AI Act tells you what you must comply with; ISO 42001 — the AI management system standard — helps you put this into practice. Use them together: the management system provides you with the policies, roles, controls and continuous improvement, whilst the Regulation sets out the legal obligations that these controls must fulfil. Done properly, a single set of controls addresses both.
The first 90 days, in practice
- List each AI system, use case, person responsible, dataset and model provider.
- Classify each system according to its risk level and flag anything that is high-risk or prohibited.
- Map controls for monitoring, logging, data governance and transparency — just once — and reuse them.
- Assess high-risk systems using an AIDF and, where personal data is involved, an AIPD.
- Identify and continuously monitor these issues, addressing any gaps before a regulator spots them.
The organisations that will suffer are those that treat the AI Act as a stand-alone project. Those that will thrive already manage security, privacy and risk within a single framework of controls — and simply add AI as another layer on top of those same controls and evidence.