EU AI Act
The EU AI Act regulates AI systems placed on the European market, with obligations that scale to the risk category a system falls into. It reaches any organization whose system output is used in the EU, wherever that organization is based.
What the EU AI Act is
The EU AI Act is a regulation governing AI systems placed on the market or put into service in the European Union. It is binding law rather than a voluntary framework, and it carries administrative fines calculated against global turnover.
Its structure is risk-tiered. Obligations attach according to what a system does and the consequences of it going wrong, not to how the model was built or how large it is.
Who it reaches
The Act applies extraterritorially. An organization with no European entity can fall within scope because of where its users are, which is why it surfaces for companies that assumed it was somebody else’s problem.
- –Providers who develop an AI system and place it on the EU market under their own name
- –Deployers using an AI system under their own authority within the EU
- –Providers and deployers established outside the EU where the system’s output is used in the EU
- –Importers and distributors bringing a system into the European market
The risk tiers
Classification is the first and most consequential piece of work, because everything that follows depends on which tier a system lands in.
- –Prohibited practices, including certain manipulative techniques, social scoring, and untargeted scraping to build facial recognition databases
- –High-risk systems, covering the safety components of regulated products and named uses such as employment, education, essential services, and law enforcement. This is where the substantive obligations sit.
- –Limited-risk systems, which carry transparency duties: people should know they are interacting with AI, and synthetic content should be marked as such
- –Minimal-risk systems, which carry no obligations under the Act
- –General-purpose AI models, which sit on a separate track with documentation and copyright obligations, and additional duties where a model presents systemic risk
What a high-risk system requires
If a system is classified as high risk, the Act specifies what has to exist before it goes to market and what has to keep running afterwards.
- –A risk management system operating across the full lifecycle, not a one-off assessment
- –Data governance covering training, validation, and testing data, including examination for bias
- –Technical documentation sufficient for an authority to assess conformity, kept up to date
- –Automatic logging that allows traceability of the system’s functioning
- –Instructions for use that let a deployer meet its own obligations
- –Human oversight designed into the system, and appropriate accuracy, robustness, and cybersecurity
- –A quality management system, a conformity assessment, and registration before placing on the market
Why it does not stay finished
Obligations continue after a system is on the market. Providers run post-market monitoring, report serious incidents, and keep the technical documentation current as the system changes.
Substantial modification is the trap. Retraining a model, changing its intended purpose, or altering it in ways that affect compliance can require the conformity work to be revisited. A record that was accurate at launch does not stay accurate through ordinary product development.
How Verdict helps
Verdict classifies your systems against the tiers, which is where most of the argument actually lives, and documents the reasoning so the classification is defensible rather than asserted.
From there we build and maintain what the tier requires: the risk management system, the technical documentation, the data governance and logging record, and the post-market monitoring loop. You review it in a client portal, with the obligations attached to each system tracked in one place.
EU AI Act is part of ai governance, the work that covers what an organization building or deploying AI has to be able to show about how those systems are governed. The same lane also covers NIST AI RMF, and ISO/IEC 42001. For the mechanics of an engagement, see how we work.
If you are working out which of your systems are in scope and what attaches to them, that classification work is where we would start.
Talk to a Consultant