Framework guide • European Union

EU AI Act: EU Artificial Intelligence Act

The EU AI Act (Regulation (EU) 2024/1689) is the European Union's law on artificial intelligence. It sorts AI systems into risk tiers: prohibited practices (Article 5), high-risk systems (Annex I and Annex III), transparency-only systems (Article 50) and minimal-risk systems. General-purpose AI models get separate rules. It entered into force on 1 August 2024 and applies in phases.

Last updated · By the Faseel compliance team · Not legal advice

EU AI Act at a glance

Legal instrument
Regulation (EU) 2024/1689, directly applicable in all EU Member States
Entered into force
1 August 2024
Phased application
Prohibitions from 2 February 2025; general-purpose AI obligations from 2 August 2025; most remaining obligations scheduled from 2 August 2026, with some high-risk timelines subject to proposed EU amendments. Check the current timeline
Risk tiers
Prohibited (Art. 5) · High-risk (Annex I / III) · Limited / transparency (Art. 50) · Minimal. GPAI is tracked separately
Applies to
Providers, deployers, importers and distributors of AI systems placed on or used in the EU market, including non-EU companies
In Komply
A risk classifier and obligation mapper, paired with the 29-control ISO/IEC 42001 AI management system

Who it applies to

Providers

Organisations that develop an AI system or GPAI model and place it on the EU market, wherever they are based.

Deployers

Organisations using AI systems in the EU in a professional capacity.

Importers & distributors

Businesses bringing AI systems into, or making them available on, the EU market.

How the risk tiers work

  • Prohibited (Article 5): practices such as harmful manipulation or social scoring are banned outright.
  • High-risk (Annex I and III): risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, and conformity assessment.
  • Limited risk (Article 50): transparency duties, e.g. telling people they are interacting with AI or labelling synthetic content.
  • Minimal risk: no specific obligations, though voluntary codes of conduct are encouraged.
  • General-purpose AI (Chapter V): documentation and copyright duties, with extra duties for models with systemic risk.

EU AI Act and ISO 42001

ISO/IEC 42001 (the AI management system standard) is the most practical backbone for AI Act readiness. Komply pairs the AI Act classifier with its 29 ISO 42001 controls, so governance evidence is reused.

Komply classifies each of your AI systems against the AI Act tiers, lists the obligations that apply, and tracks them next to ISO 42001 and ISO 27001. Pair it with EvilGum to enforce tool permissions on AI agents in production. See how Komply works.

EU AI Act FAQ

What is the EU AI Act?

The EU AI Act is Regulation (EU) 2024/1689, the European Union's law regulating artificial intelligence. It applies a risk-based approach, banning some practices, placing strict obligations on high-risk systems, requiring transparency for some others, and setting separate rules for general-purpose AI models.

When does the EU AI Act apply?

It entered into force on 1 August 2024 and applies in phases. Prohibitions apply from 2 February 2025, general-purpose AI obligations from 2 August 2025, and most remaining obligations were scheduled from 2 August 2026. Some high-risk timelines are subject to proposed EU amendments, so check the current official timeline.

Does the EU AI Act apply to companies outside the EU?

Yes. It applies to providers placing AI systems on the EU market, and to providers and deployers outside the EU whose AI output is used in the EU.

How is the EU AI Act related to ISO 42001?

ISO/IEC 42001 is a voluntary international management-system standard for AI. It isn't the law, but it provides the governance, risk and documentation structure that makes AI Act obligations much easier to meet and evidence.

How does Komply help with the EU AI Act?

Komply includes an EU AI Act risk classifier. It works through Article 5, then Annex I/III, then Article 50, and tracks GPAI separately. It maps the resulting obligations and manages them alongside the ISO 42001 AI management system.

Do ISO 27001 once. Prove EU AI Act too.

Komply maps 14 frameworks and 1,100+ controls into one control set. Start with a free gap assessment.