{"id":2835,"date":"2026-07-06T13:19:24","date_gmt":"2026-07-06T12:19:24","guid":{"rendered":"https:\/\/icomply.pm\/resources\/article-eu-ai-act-guide\/"},"modified":"2026-09-08T12:31:46","modified_gmt":"2026-09-08T11:31:46","slug":"eu-ai-act-guide","status":"publish","type":"post","link":"https:\/\/icomply.pt\/en\/resources\/eu-ai-act-guide\/","title":{"rendered":"The 2026 guide to operationalising the EU AI Act"},"content":{"rendered":"<h2 data-dc-tpl=\"25\">EU AI Act Guide<\/h2>\n<p data-dc-tpl=\"25\">The EU\u2019s Artificial Intelligence Regulation is the world\u2019s first comprehensive piece of legislation on artificial intelligence. For compliance, legal and security leaders, the question is no longer <em data-dc-tpl=\"26\">whether <\/em>it applies \u2014 it is how to implement it without creating yet another siloed programme. This guide breaks the Regulation down into actionable parts and shows how it fits in with the regulations already in place.  <\/p>\n<h2 data-dc-tpl=\"27\">To whom the Regulation applies<\/h2>\n<p data-dc-tpl=\"28\">The Regulation applies to the technology, not the company. It covers <strong data-dc-tpl=\"29\">suppliers<\/strong> who develop or place AI systems on the EU market, <strong data-dc-tpl=\"30\">organisations responsible<\/strong> for deployment that use AI professionally, and importers and intermediaries. It also has extraterritorial scope: if the output of your AI system is used in the EU, the Regulation may apply even if your organisation is based elsewhere. For most organisations, the conclusion is simple \u2014 they are almost certainly responsible for the implementation of AI at some stage, and need to know which obligations apply to each use.   <\/p>\n<h2 data-dc-tpl=\"31\">The risk-based model<\/h2>\n<p data-dc-tpl=\"32\">The Regulation classifies AI systems according to the risk they pose, and the obligations increase in line with that risk. Getting this classification right is the foundation for everything else. <\/p>\n<ul data-dc-tpl=\"33\">\n<li data-dc-tpl=\"34\"><strong data-dc-tpl=\"35\">Unacceptable risk.<\/strong> A small set of practices \u2014 such as social classification by public authorities and certain manipulative systems \u2014 are quite simply prohibited.<\/li>\n<li data-dc-tpl=\"36\"><strong data-dc-tpl=\"37\">High risk.<\/strong> Systems used in employment, education, essential services, biometrics and critical infrastructure bear the heaviest responsibilities.<\/li>\n<li data-dc-tpl=\"38\"><strong data-dc-tpl=\"39\">Limited risk.<\/strong> Systems that interact with people or generate content have a duty of transparency \u2014 users must be aware that they are dealing with AI.<\/li>\n<li data-dc-tpl=\"40\"><strong data-dc-tpl=\"41\">Minimal risk.<\/strong> The vast majority of systems remain as they are, with no new obligations.<\/li>\n<li data-dc-tpl=\"42\"><strong data-dc-tpl=\"43\">General-purpose AI (GPAI).<\/strong> Foundational models have their own layer of documentation and, for the most sophisticated ones, systemic risk obligations.<\/li>\n<\/ul>\n<h2 data-dc-tpl=\"44\">The obligations that create work<\/h2>\n<p data-dc-tpl=\"45\">For high-risk systems, the Regulation requires that it be demonstrated \u2014 with evidence \u2014 that the system is governed throughout its life cycle:<\/p>\n<ul data-dc-tpl=\"46\">\n<li data-dc-tpl=\"47\">A <strong data-dc-tpl=\"48\">risk management system <\/strong>that runs continuously, not just once.<\/li>\n<li data-dc-tpl=\"49\"><strong data-dc-tpl=\"50\">Data governance<\/strong> relating to training, validation and test data.<\/li>\n<li data-dc-tpl=\"51\"><strong data-dc-tpl=\"52\">Technical documentation<\/strong> and automatic event <strong data-dc-tpl=\"53\">logging<\/strong>.<\/li>\n<li data-dc-tpl=\"54\"><strong data-dc-tpl=\"55\">Human supervision<\/strong> with the ability to intervene and override.<\/li>\n<li data-dc-tpl=\"56\"><strong data-dc-tpl=\"57\">Accuracy, robustness and cybersecurity<\/strong> appropriate to the use case.<\/li>\n<li data-dc-tpl=\"58\"><strong data-dc-tpl=\"59\">Transparency <\/strong>so that those implementing the system and those affected by it can understand it.<\/li>\n<\/ul>\n<h2 data-dc-tpl=\"60\">How does ISO 42001 fit in?<\/h2>\n<p data-dc-tpl=\"61\">The AI Act tells you<em data-dc-tpl=\"62\"> what <\/em>you must comply with; ISO 42001 \u2014 the AI management system standard \u2014 helps you put this into <em data-dc-tpl=\"63\">practice<\/em>. Use them together: the management system provides you with the policies, roles, controls and continuous improvement, whilst the Regulation sets out the legal obligations that these controls must fulfil. Done properly, a single set of controls addresses both.  <\/p>\n<h2 data-dc-tpl=\"64\">The first 90 days, in practice<\/h2>\n<ul data-dc-tpl=\"65\">\n<li data-dc-tpl=\"66\"><strong data-dc-tpl=\"67\">List<\/strong> each AI system, use case, person responsible, dataset and model provider.<\/li>\n<li data-dc-tpl=\"68\"><strong data-dc-tpl=\"69\">Classify <\/strong>each system according to its risk level and flag anything that is high-risk or prohibited.<\/li>\n<li data-dc-tpl=\"70\"><strong data-dc-tpl=\"71\">Map controls <\/strong>for monitoring, logging, data governance and transparency \u2014 just once \u2014 and reuse them.<\/li>\n<li data-dc-tpl=\"72\"><strong data-dc-tpl=\"73\">Assess <\/strong>high-risk systems using an AIDF and, where personal data is involved, an AIPD.<\/li>\n<li data-dc-tpl=\"74\"><strong data-dc-tpl=\"75\">Identify and continuously monitor<\/strong> these issues, addressing any gaps before a regulator spots them.<\/li>\n<\/ul>\n<p data-dc-tpl=\"76\">The organisations that will suffer are those that treat the AI Act as a stand-alone project. Those that will thrive already manage security, privacy and risk within a single framework of controls \u2014 and simply add AI as another layer on top of those same controls and evidence. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>The AI Act is now in force and is being rolled out in phases across the EU. Here is a practical guide to turning its requirements into controls, evidence and oversight that actually work \u2014 in conjunction with ISO 42001. <\/p>\n","protected":false},"author":1,"featured_media":2851,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_ice_seo_score":0,"_ice_review":"","footnotes":""},"categories":[6],"tags":[],"class_list":["post-2835","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-eu-ai-act"],"_links":{"self":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts\/2835","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/comments?post=2835"}],"version-history":[{"count":5,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts\/2835\/revisions"}],"predecessor-version":[{"id":4069,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/posts\/2835\/revisions\/4069"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/media\/2851"}],"wp:attachment":[{"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/media?parent=2835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/categories?post=2835"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icomply.pt\/en\/wp-json\/wp\/v2\/tags?post=2835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}