AI Act compliance is the process through which organizations comply with the European regulation on artificial intelligence and implement governance measures and risk controls for AI systems.
The EU AI Act (Regulation (EU) 2024/1689) establishes harmonized rules for the development, deployment and placing on the market of AI systems in the European Union, based on a risk-based approach.
AI Act compliance involves implementing governance, risk management and transparency measures to ensure that AI systems meet the requirements of the European regulation on artificial intelligence.
This guide provides a practical overview for organizations that develop or use AI systems and need to comply with the requirements of the EU AI Act.
Organizations that process personal data should also review our GDPR compliance guide for companies.

1. Scope of application for AI Act compliance
Understanding the scope of the AI Act is essential because it determines the legal obligations applicable to each type of organization.
The regulation applies to the following categories of actors:
- providers of AI systems (entities that develop AI systems and place them on the market)
- deployers (organizations that use an AI system in a professional context)
- importers and distributors
- providers of general-purpose AI models (GPAI)
The AI Act has extraterritorial effect, meaning it also applies to organizations outside the EU if their AI systems affect individuals located in the European Union.
2. Risk classification under the AI Act
The risk classification determines the obligations that apply to an AI system.
a) Unacceptable risk (prohibited AI systems)
Examples include:
- social scoring systems
- subliminal manipulation
- exploitation of vulnerable individuals
- real-time remote biometric identification in public spaces, subject to limited exceptions
These AI systems are prohibited.
b) High-risk AI systems
This category includes AI systems used in sensitive areas such as:
- employment and human resources
- credit scoring and lending decisions
- critical infrastructure
- education
- law enforcement
- migration and border control
These systems are subject to the most stringent obligations.
c) Limited risk
These systems are subject to transparency obligations, including:
- chatbots
- content generators, including deepfakes
- emotion recognition systems
d) Minimal risk
No additional obligations generally apply to systems such as:
- spam filters
- AI-powered video games
- inventory management optimization systems
Correctly classifying AI systems is essential for AI Act compliance and determines the applicable obligations.
From a cybersecurity perspective, organizations should also review the NIS2 compliance guide.

3. Obligations for AI Act compliance
Obligations vary depending on the organization’s role.
A. Obligations for providers of high-risk AI systems
Providers must ensure:
- a risk management system
- appropriate data governance and data quality
- complete technical documentation
- traceability of outputs and results
- transparency regarding system functionality
- appropriate human oversight
- robustness, accuracy and cybersecurity
- conformity assessment and CE marking before placing the system on the market
If your organization needs support with AI Act compliance, contact our team to discuss your AI governance and regulatory requirements.



