HomeFrameworksAI Governance & Privacy FrameworksEU AI Act

Framework  AI Governance & Privacy Frameworks

EU AI Act

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is the European Union's horizontal law on AI.

It sorts AI systems by risk: a short list of prohibited practices, a set of high-risk uses (Annex III standalone systems such as hiring, credit scoring, and critical infrastructure, plus Annex I systems embedded in products already covered by EU product safety law), transparency duties for chatbots and synthetic content, and a separate regime for general-purpose AI models.

The prohibitions have applied since February 2, 2025 and the general-purpose model obligations since August 2, 2025. The Digital Omnibus on AI, reported as entering into force on July 27, 2026, pushed the high-risk deadlines back: Annex III systems to December 2, 2027 and Annex I systems to August 2, 2028 (verify against the consolidated text).

The Article 50 transparency duties kept their August 2, 2026 date.

For a provider of a high-risk system the law is largely a documentation statute. It requires a written risk management system that runs across the lifecycle, data governance records for training and testing sets, technical documentation per Annex IV, automatic logging, instructions for use, a human oversight design, a quality management system, a declaration of conformity, and post-market monitoring with serious incident reporting.

Deployers must follow those instructions, keep logs, assign trained human oversight, and in some cases complete a fundamental rights impact assessment. Every organization, whatever its role, must ensure staff have adequate AI literacy.

AI-compiled
Share
Sponsored
Policy  Acknowledgment  Proof
AcknowledgedAI use policy v1by name, on record
Article 4 Handledwith AllyMatter
Govern the Modern WayEvery AI-use policy, acknowledged by the people who deploy the system
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every operator on record
Who read which version, and when
03
Show the market surveillance authority the trail
From $29/mo, 20 editors, unlimited staff (published)

Who has to comply

Providers that place AI systems or general-purpose models on the EU market, deployers established in the EU, and importers and distributors. Providers and deployers outside the EU are caught when the system's output is used in the EU. Obligations scale with the risk tier; most SMEs using off-the-shelf tools face only the AI literacy and transparency duties.

What the assessor asks to see

AI system inventory and risk classification rationale; risk management system documentation; data governance records (provenance, bias examination, relevance of training data); Annex IV technical documentation; logging design and retained logs; instructions for use; human oversight measures; quality management system; conformity assessment record and EU declaration of conformity; EU database registration; post-market monitoring plan and incident reports; AI literacy training records; for deployers, the fundamental rights impact assessment where required.

Where the requirement sits: Art 4 AI literacy; Art 26 deployer obligations; Art 9 risk management; Art 11 technical documentation; Art 17 QMS

Application timeline

Entry into force August 1, 2024. Prohibited practices and AI literacy from February 2, 2025. General-purpose AI model obligations and governance provisions from August 2, 2025.

Transparency obligations (Article 50) from August 2, 2026. High-risk Annex III systems deferred by the AI Omnibus to December 2, 2027 and Annex I systems to August 2, 2028; these amended dates were reported by legal commentary after the Omnibus entered into force on July 27, 2026 and should be verified against the Official Journal text.

What AllyMatter does here

AI-use policy and literacy-acknowledgment layer.

AllyMatter publishes this site.

Assessors

Who assesses EU AI Act

Depends on the system. Most Annex III high-risk providers self-assess through the internal control procedure in Annex VI. Third-party assessment by a notified body is required for certain biometric systems where harmonized standards are not fully applied, and for Annex I products it runs through the notified body already used under the sectoral product law.

General-purpose model providers are supervised directly by the AI Office. Accredited by National notifying authorities designate notified bodies, normally on the basis of accreditation by the national accreditation body under Regulation (EC) 765/2008. Designations are published in the Commission's NANDO database.

Public register of assessors: https://webgate.ec.europa.eu/single-market-compliance-space/#/notified-bodies

No firm has claimed a EU AI Act assessor listing yet. Claim yours →

Consultants

Who helps with EU AI Act

A fast-growing ecosystem of law firms, AI governance consultancies, and GRC platform vendors. Typical engagements start with an inventory and risk classification of AI systems, then build the risk management system, technical documentation, and quality management system for anything high-risk, and often map the work onto ISO/IEC 42001.

Engagements run from a few weeks for classification to many months for a high-risk provider.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a EU AI Act consultant listing yet. Claim yours →

Software

Tools for EU AI Act

Tools that name this framework in their own material.

Related reading

  1. High-level summary of the AI ActClause-by-clause plain-language walkthrough of the risk tiers and what providers and deployers must actually do for each.Future of Life Institute
  2. EU AI Act Omnibus Agreement: postponed high-risk deadlines and other key changesExplains the Digital Omnibus changes that moved the high-risk compliance dates, and what stayed on the original timetable.Gibson Dunn
  3. U.S. companies face the EU AI Act's compliance deadlineSets out when the Act reaches a non-EU company and which documentation and governance duties follow from that.Holland & Knight

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for EU AI Act

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Run the Policy Side of EU AI Act in AllyMatter

Approve the policies EU AI Act asks for, keep every version, and record a named acknowledgment from each person who has to read them.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.