Table of contents

EU AI Act: risk tiers, timeline, and compliance requirements

EU AI Act: risk tiers, timeline, and compliance requirements - Featured image EU AI Act

What is the EU AI Act?

The EU AI Act is a regulatory framework governing the development, deployment, and use of artificial intelligence within the European Union. The European Commission proposed it to keep AI systems placed on the EU market safe and transparent and to make sure they respect fundamental rights. The Act sets obligations for AI providers, users, and other stakeholders to address risks associated with AI while still supporting innovation and investment in the sector.

A central feature of the EU AI Act is its risk-based approach, which categorizes AI systems by the level of risk they pose to health, safety, or fundamental rights. By imposing stricter requirements on higher-risk systems and lighter measures on low-risk applications, the Act balances technological advancement with public trust and ethical standards. The legislation also introduces enforcement mechanisms and steep penalties for non-compliance, underlining the EU’s commitment to responsible AI governance.

Who must comply with the EU AI Act?

A broad range of entities involved in the AI lifecycle must comply with the EU AI Act, including:

  • Providers who develop and market AI systems
  • Importers who bring these systems into the EU
  • Distributors who supply them
  • Users who employ AI in their operations

The Act applies whether these entities are based inside or outside the EU, as long as their AI systems are used within the Union’s jurisdiction or affect EU citizens.

Organizations that develop general-purpose AI models, integrate AI into products, or use AI in regulated sectors such as healthcare, transportation, or finance need to pay attention to the Act’s requirements. Many of the same organizations also fall under the EU Cyber Resilience Act, which covers the security of digital products. Even companies with no physical presence in the EU can fall under its scope if their AI systems affect the European market or individuals. That broad reach means every AI system interacting with the EU must meet the same standards for safety, transparency, and accountability.

Related content: Read our guide to AI compliance.

EU AI Act implementation timeline

The EU AI Act (Regulation (EU) 2024/1689) entered into force on August 1, 2024, but its requirements are introduced gradually. This phased approach gives EU institutions, national authorities, AI providers, and organizations time to build governance structures, prepare technical standards, assess affected systems, and put required controls in place. Different obligations apply depending on the type of AI system, its risk classification, and the organization’s role in the AI supply chain.

  • February 2, 2025: Rules prohibiting certain unacceptable-risk AI practices began to apply. Organizations also became responsible for ensuring that personnel involved in operating or using AI systems have an appropriate level of AI literacy.
  • August 2, 2025: Governance provisions and obligations for providers of general-purpose AI models began to apply. These include requirements related to technical documentation, information for downstream providers, copyright compliance, and training-content summaries. Penalty provisions also took effect.
  • August 2, 2026: Most remaining provisions began to apply. These include transparency duties for certain AI systems, responsibilities for providers and deployers, conformity-assessment rules, regulatory sandbox provisions, and enforcement and market-monitoring requirements.
  • December 2, 2027: Under the implementation timeline EU policymakers agreed to in May 2026, requirements for high-risk AI systems used in areas such as biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and the administration of justice are scheduled to apply from this date. This timetable gives organizations and regulators extra time to work with supporting standards, guidance, and compliance tools.
  • August 2, 2028: Requirements are scheduled to apply to high-risk AI systems that serve as safety components of regulated products or are themselves regulated products, including certain machinery, medical devices, toys, lifts, vehicles, and aviation systems. These systems may also need to satisfy conformity-assessment requirements under existing EU product-safety legislation.

Providers of general-purpose AI models placed on the market before August 2, 2025, get a longer transition period and are expected to comply with applicable requirements by August 2, 2027. Organizations should start preparing well before the final application dates. Early activities include building an AI inventory, assigning system risk classifications, identifying the organization’s legal role, strengthening documentation, putting human oversight in place, and setting up processes for monitoring incidents and regulatory changes.

Does the EU AI Act apply outside the EU?

The EU AI Act has extraterritorial reach, meaning its obligations extend to organizations outside the EU if their AI systems are placed on the EU market or affect EU users. This includes providers, importers, or deployers of AI systems, regardless of location, as long as their products or services are accessible in the EU. The Act targets global AI supply chains so risks to EU citizens are managed consistently, no matter where the technology originates.

Companies based in North America, Asia, or elsewhere need to assess whether their AI offerings interact with the EU market or influence individuals within the Union. If so, they must comply with the Act’s requirements, including risk assessments, transparency obligations, and post-market monitoring. The EU’s enforcement mechanisms, such as cooperation with national authorities and penalties for non-compliance, are why global AI providers can’t ignore their obligations under the Act.

What is considered an AI system under the EU AI Act?

The EU AI Act adopts a broad definition of an AI system, covering software developed with machine learning, logic-based, or statistical approaches that can, for a given set of human-defined objectives, generate outputs such as content, predictions, recommendations, or decisions influencing real or virtual environments. That definition spans a wide range of technologies, from rule-based systems to neural networks and generative models.

AI systems under the Act include standalone applications and embedded functionalities within larger products or services. The scope covers:

  • Chatbots
  • Facial recognition tools
  • Automated decision-making platforms
  • Predictive analytics engines

The definition is meant to capture relevant systems under the regulatory framework as technologies evolve.

The EU AI Act’s risk-based approach

1. Unacceptable-risk AI systems

Unacceptable-risk AI systems pose a clear threat to the safety, livelihoods, or fundamental rights of individuals. The EU AI Act prohibits these systems outright, meaning they can’t be placed on the market, put into service, or used within the EU. Examples include AI applications that manipulate human behavior to cause harm, exploit vulnerable groups, or enable social scoring by governments.

The prohibition also covers AI systems used for real-time biometric identification in public spaces for law enforcement, except in narrowly defined circumstances such as searching for missing persons or preventing imminent threats. The goal is to prevent widespread surveillance, discrimination, and abuse of AI technologies. Organizations that develop or deploy unacceptable-risk AI face steep penalties and enforcement actions.

2. High-risk AI systems

High-risk AI systems are subject to strict regulatory requirements because of their potential impact on health, safety, or fundamental rights. These include AI used in critical infrastructure, education, employment, law enforcement, migration, and access to essential services. The Act requires risk management, transparency, data governance, human oversight, and quality control for these systems.

Providers of high-risk AI must conduct conformity assessments, maintain technical documentation, and keep the system traceable throughout its lifecycle. They must also put mechanisms for human oversight in place and establish procedures for addressing incidents or malfunctions. Failure to comply can result in steep fines and restrictions on market access.

3. Limited-risk AI systems

Limited-risk AI systems aren’t prohibited, but they must meet transparency obligations. These systems include applications such as chatbots, deepfakes, or AI-generated content, where users may not realize they’re interacting with an AI. The Act requires that users are clearly informed whenever they’re engaging with an AI system.

Transparency requirements for limited-risk systems may also involve providing users with explanations about the AI’s function or logic, especially if the system generates content or influences user choices. These obligations are less strict than those for high-risk AI, but they still require organizations to update user interfaces, documentation, and communication materials.

4. Minimal- or no-risk AI systems

Minimal- or no-risk AI systems pose little to no threat to individuals or society. Examples include AI powered video games, spam filters, or recommendation engines. For these systems, the EU AI Act imposes no specific regulatory requirements beyond existing product safety or consumer protection laws.

Organizations developing or deploying minimal-risk AI can operate without additional compliance measures under the Act. Even so, they should watch for changes in functionality or context of use, since reclassification into a higher risk category could trigger new obligations.

EU AI Act requirements for high-risk AI systems

Risk management

Providers must establish, implement, document, and maintain a risk management system throughout the lifecycle of a high-risk AI system. It has to be a continuous process that identifies and analyzes known and reasonably foreseeable risks to health, safety, and fundamental rights, including risks that may emerge when the system is used as intended or under reasonably foreseeable misuse.

Organizations must evaluate each identified risk and adopt measures to eliminate or reduce it as far as technically feasible. Any remaining risks must be judged acceptable, communicated where appropriate, and addressed through safeguards such as human oversight, technical controls, and user training. High-risk systems must also undergo testing against predefined metrics and thresholds before going on the market and, where necessary, throughout their lifecycle.

Data and data governance

High-risk AI systems that rely on model training must use training, validation, and testing datasets that meet quality standards. These datasets must be relevant, sufficiently representative, and, as far as possible, free of errors and complete for the system’s intended purpose. They should also have statistical properties that suit the people or groups the system will be used on.

Providers must establish data governance and management practices covering data collection, preparation, annotation, labeling, cleaning, updating, and bias detection. They must check whether datasets contain biases that could negatively affect health, safety, fundamental rights, or lead to prohibited discrimination. Where necessary, datasets should reflect the geographical, behavioral, contextual, or functional conditions in which the system is expected to operate.

Technical documentation

Technical documentation must be prepared before a high-risk AI system is placed on the market or put into service, and it must stay current. It should contain enough information to demonstrate compliance with the EU AI Act and let regulators, notified bodies, and other authorized parties assess that compliance.

The documentation should describe the system’s intended purpose, provider, development methods, architecture, algorithms, data requirements, capabilities, limitations, and expected performance. It must also cover the risk management process, testing procedures, validation results, cybersecurity measures, human oversight controls, monitoring arrangements, and relevant changes made during the system’s lifecycle.

Record-keeping and logging

High-risk AI systems must include technical capabilities that automatically record relevant events during operation. These logs should make the system traceable, helping organizations understand system behavior, identify risk situations, and support post-market monitoring and regulatory investigations.

Logging capabilities should let providers and deployers monitor system operation over time and detect abnormal behavior, performance deterioration, incidents, or substantial modifications. For certain systems, logs may need to capture details such as the period of use, input data, reference databases consulted, and the individuals involved in verifying or reviewing outputs. Records must be retained for a period consistent with the system’s purpose and applicable legal requirements.

Transparency and instructions for use

High-risk AI systems must be transparent enough that deployers can interpret outputs and use them appropriately. Providers must supply clear and accessible instructions containing the information needed to operate the system safely and understand its capabilities and limitations.

Instructions should identify the provider, explain the system’s intended purpose, and describe expected accuracy, robustness, cybersecurity characteristics, and known circumstances that could create risks. They must also specify input-data requirements, foreseeable limitations, necessary human oversight measures, maintenance needs, logging arrangements, and changes to performance over the system’s expected lifetime.

Human oversight

High-risk AI systems must be designed so that natural persons can oversee their operation. The level and form of oversight should fit the system’s risks, autonomy, and intended context of use. Oversight measures may be built into the system by the provider or implemented by the deployer according to the provider’s instructions.

Individuals responsible for oversight must understand the system’s capabilities and limitations, monitor its operation, recognize automation bias, and interpret outputs correctly. Where appropriate, they must be able to disregard, override, reverse, or interrupt outputs and stop operation. Oversight should go to individuals with the necessary competence, training, authority, and resources.

Accuracy, robustness, and cybersecurity

High-risk AI systems must achieve an appropriate level of accuracy, robustness, and cybersecurity and maintain performance throughout their lifecycle. Providers must define relevant accuracy metrics in the instructions and design systems to stay resilient when errors, faults, inconsistencies, or unexpected conditions occur.

Systems that continue learning after deployment must include safeguards against feedback loops in which biased or incorrect outputs influence future inputs. Cybersecurity measures must protect against attacks intended to manipulate training data, models, system inputs, or outputs, or to exploit vulnerabilities. Depending on the system, this can include controls against data poisoning, model poisoning, adversarial examples, model evasion, confidentiality attacks, and attempts to exploit technical weaknesses.

EU AI Act governance, enforcement, and penalties

The EU AI Act sets up a two-level governance structure that divides responsibilities between EU institutions and national authorities. The European AI Office supports consistent implementation across the Union and directly supervises compliance by providers of general-purpose AI models. It also develops guidance, evaluation methods, codes of practice, and other tools that help organizations and regulators apply the Act.

At the national level, each EU Member State must designate at least one market surveillance authority and one notifying authority. Market surveillance authorities investigate possible violations, evaluate whether AI systems create unacceptable risks, and require providers or other operators to correct non-compliance. Their powers include:

  • Requesting documentation and data
  • Accessing source code where necessary
  • Conducting inspections
  • Restricting or recalling systems
  • Imposing penalties under national enforcement procedures

Several EU-level bodies support coordination and technical decision-making. The European Artificial Intelligence Board brings together representatives from Member States to promote consistent enforcement and advise on implementation. A Scientific Panel of independent experts provides technical expertise, particularly around general-purpose AI models and systemic risks. An Advisory Forum gives industry, civil society, academia, startups, and other stakeholders a channel to contribute practical and technical perspectives.

Enforcement isn’t limited to financial penalties. Authorities may:

  • Issue warnings
  • Order operators to bring systems into compliance
  • Require corrective action
  • Restrict an AI system’s availability
  • Prohibit its use
  • Order its withdrawal or recall

Providers are expected to cooperate with authorities, provide requested information, address serious incidents, and correct systems that don’t meet the Act’s requirements.

Penalties under the EU AI Act

The maximum administrative fines depend on the type and seriousness of the violation:

  • Prohibited AI practices: Up to €35 million or 7% of total worldwide annual turnover from the preceding financial year, whichever is higher.
  • Violations of other specified obligations: Up to €15 million or 3% of total worldwide annual turnover, whichever is higher.
  • Incorrect or misleading information: Up to €7.5 million or 1% of total worldwide annual turnover, whichever is higher.
  • General-purpose AI model violations: The European Commission may fine providers up to €15 million or 3% of total worldwide annual turnover, whichever is higher.

For small and medium-sized enterprises, including startups, the applicable ceiling is generally the lower of the fixed monetary amount or turnover percentage. For other organizations, it’s the higher amount. When determining the actual penalty, authorities weigh factors such as severity and duration, the number of affected people, damage caused, previous violations, organizational size, cooperation with regulators, corrective actions, and whether the conduct was intentional or negligent.

EU AI Act compliance best practices

Organizations operating in or providing services to the EU should consider the following practices to stay compliant with the EU AI Act.

1. Maintain a centralized inventory of AI systems and components

A centralized AI inventory is the foundation of an EU AI Act compliance program. Organizations should keep a current record of all AI systems they develop, procure, deploy, or integrate into products and services. The inventory should include supporting components such as models, datasets, APIs, frameworks, and third-party services that contribute to AI functionality.

Each inventory entry should capture the system’s purpose, owner, provider, deployment environment, risk classification, legal role under the Act, data sources, and dependencies. Keeping this information in one place makes it easier to:

  • Identify high-risk systems
  • Perform impact assessments
  • Prepare technical documentation
  • Monitor changes
  • Respond to regulatory requests

Most teams manage this inventory through AI governance platforms rather than spreadsheets.

2. Integrate AI risk management into the development lifecycle

Organizations should build AI risk management into every stage of the system lifecycle rather than treat it as a final compliance exercise. Risk assessments should begin during planning and continue through design, development, testing, deployment, operation, and retirement. This approach helps catch issues early. A structured AI governance implementation strategy gives these review points a home.

Organizations should define review points that evaluate risks related to accuracy, bias, privacy, cybersecurity, safety, and fundamental rights before systems move to the next development stage. Development teams, security specialists, legal advisors, and business stakeholders should:

  • Document decisions
  • Verify mitigation measures
  • Confirm that changes don’t introduce new compliance risks

3. Secure the AI software supply chain

Most AI systems depend on third-party models, libraries, datasets, cloud services, and development frameworks. Each external component introduces potential security, licensing, operational, and compliance risks that should be assessed before adoption and monitored during use.

Organizations should:

  • Establish processes to evaluate suppliers
  • Verify component integrity
  • Monitor vulnerabilities
  • Track updates
  • Respond to newly disclosed security issues

Supply chain controls should include dependency management, code signing where appropriate, secure artifact repositories, and procedures for replacing unsupported or high-risk components.

4. Generate and maintain an AI bill of materials

An AI bill of materials (AI-BOM) documents the components used to build and operate an AI system. It extends the concept of a software bill of materials by recording assets that influence system behavior and compliance obligations, such as:

  • Models
  • Datasets
  • Prompts
  • Training resources
  • Libraries
  • Frameworks
  • APIs

Maintaining an AI-BOM improves transparency and traceability throughout the AI lifecycle. It lets organizations identify affected systems when vulnerabilities, licensing issues, or regulatory changes arise, and it supports technical documentation requirements.

5. Establish policies for open source models and frameworks

Open source AI models and frameworks can speed up development, but they need governance. Organizations should define policies covering evaluation, approval, licensing, security review, acceptable use, maintenance responsibilities, and ongoing monitoring before introducing these components into production environments.

Policies should require teams to:

  • Verify model origin
  • Review license obligations
  • Assess known limitations
  • Evaluate security and compliance risks
  • Document intended use cases

Organizations should also establish processes for tracking updates, validating new releases before deployment, and retiring components that are no longer supported or no longer meet security or regulatory requirements.

How Mend AI helps you meet EU AI Act requirements

Meeting the EU AI Act’s obligations depends on continuous visibility into every AI component your organization builds or uses: maintaining an accurate inventory of AI systems, managing risk across the AI lifecycle, and demonstrating compliance to regulators. Mend AI automates this work by discovering AI components, assessing their risk, and enforcing governance policies, so your team can align AI systems with regulatory requirements without slowing development.

Key capabilities of Mend AI:

  • Real-time AI inventory: Keeps a continuously updated inventory of every model and framework across the AI supply chain, including hard-to-detect shadow AI, giving your team the visibility needed to identify systems that fall under the Act.
  • AI component discovery and risk assessment: Automatically discovers AI components and assesses their risk with prioritized remediation, helping you understand and reduce exposure across your applications.
  • Policy enforcement and governance: Uses a policy engine and automation workflows to define, set, and govern rules for AI components and AI security posture management (AI-SPM) protocols throughout the software development lifecycle.
  • Regulatory compliance mapping: Maps controls against frameworks including OWASP, NIST, ISO/IEC, and the EU AI Act, identifies compliance gaps, and reports on regulatory alignment.
  • AI behavior testing: Applies red teaming to verify applications against threats such as prompt injection, context leakage, data exfiltration, bias, and hallucinations before they lead to unintended consequences.
  • System prompt hardening and runtime safety: Hardens system prompts and applies real-time safety filters and runtime guardrails between users and AI models to govern live AI interactions.

Learn how Mend AI can help you automate AI risk management and governance and prepare your AI systems for the EU AI Act.

Increase visibility and control over the AI components in your applications

Mend AI

Recent resources

EU AI Act: risk tiers, timeline, and compliance requirements - Featured image Skill Layer Dependency Problem

The skill layer is a dependency problem without a lockfile: what the OWASP Agentic Skills Top 10 gets right

Nine solved supply chain risks, one new gap: the OWASP Agentic Skills Top 10.

Read more
EU AI Act: risk tiers, timeline, and compliance requirements - Featured image OWASP LLM TOP 10 2026

OWASP LLM Top 10 2026: the model will be fooled, the question is what breaks

The 2026 OWASP LLM Top 10 shifts the job from prevention to containment.

Read more
EU AI Act: risk tiers, timeline, and compliance requirements - Featured image Move Faster Than AI Driven Risk 1000x650

Move faster than AI-driven risk: Inside Mend.io’s latest AI application security update

AI agent discovery, runtime guardrails, agentic triage, and zero-day speed.

Read more