EU AI Act Compliance

Navigate the world's first comprehensive AI regulation

Evidr automates EU AI Act compliance with risk classification, conformity assessments, and technical documentation management. Prepare for phased deadlines starting February 2025 and avoid penalties up to 7% of global turnover.

Built by the same team that builds platforms for

GoogleAWSBMWPhilips
27
EU member states covered
7%
Max penalty (global turnover)
4
Risk classification levels
2025
First compliance deadlines

Four risk levels define your obligations

The EU AI Act classifies AI systems by risk level. Your compliance requirements depend entirely on where your systems fall in this hierarchy.

Unacceptable Risk

Prohibited AI practices that pose clear threats to safety, livelihoods, or rights

  • Social scoring by governments
  • Real-time remote biometric ID in public spaces
  • Emotion recognition in workplace/education
  • Subliminal manipulation techniques
Banned from the EU market
High Risk

AI systems that significantly impact safety, fundamental rights, or critical decisions

  • Critical infrastructure management
  • Educational scoring and access
  • Employment and recruitment
  • Credit scoring and insurance
  • Law enforcement tools
Strict compliance requirements
Limited Risk

AI systems with specific transparency obligations

  • Chatbots and virtual assistants
  • Emotion recognition systems
  • Deepfake generation
  • AI-generated content
Transparency obligations
Minimal Risk

AI systems with no specific regulatory requirements

  • Spam filters
  • AI-enabled video games
  • Inventory management
  • Content recommendations
No specific requirements

8 Requirements for High-Risk AI Systems

High-risk AI systems face the most stringent compliance requirements. Evidr automates documentation, tracking, and evidence collection for each mandatory requirement.

Risk Management System
Establish and maintain a risk management system throughout the AI system lifecycle
Data Governance
Ensure training, validation, and testing data meets quality criteria and is representative
Technical Documentation
Draw up comprehensive technical documentation before placing system on market
Record-Keeping
Enable automatic recording of events (logs) throughout system operation
Compliance Dashboard2 Pending
Risk Management System
Data Governance
Technical Documentation - In Progress
Conformity Assessment - Pending
Overall Progress6 / 8 requirements

Everything you need for EU AI Act compliance

From risk classification to post-market monitoring, Evidr provides end-to-end EU AI Act compliance management.

AI Risk Classification

Automatically assess and classify your AI systems against EU AI Act risk categories. Determine if your systems are prohibited, high-risk, limited risk, or minimal risk.

Conformity Assessments

Conduct and document conformity assessments for high-risk AI systems. Generate technical documentation and compliance declarations for notified bodies.

Technical Documentation

Maintain comprehensive technical documentation including system design, training data, testing results, and performance metrics required by the regulation.

Post-Market Monitoring

Implement continuous monitoring systems to track AI performance, detect drift, and report serious incidents to authorities within required timeframes.

Transparency Requirements

Meet transparency obligations with automated disclosures for AI-generated content, emotion recognition systems, and biometric categorization.

Audit Trail Management

Maintain immutable audit logs of AI system decisions, model updates, and compliance activities. Demonstrate accountability to regulators and auditors.

Phased compliance deadlines

The EU AI Act takes effect in stages. Plan your compliance roadmap to meet each deadline before enforcement begins.

February 2025

Prohibited AI Practices

AI systems with unacceptable risk must be removed from the EU market

August 2025

General-Purpose AI (GPAI)

GPAI model providers must comply with transparency and documentation requirements

August 2026

High-Risk AI Systems

Full compliance required for high-risk AI systems in Annex III categories

August 2027

Embedded High-Risk AI

Compliance deadline for high-risk AI embedded in regulated products

Manual vs. automated EU AI Act compliance

Without Evidr
Months to classify AI system portfolio
Manual technical documentation in Word
No systematic risk management tracking
Expensive external conformity assessments
Reactive incident management
Audit-ready evidence scattered across systems
With Evidr
Automated AI system inventory and classification
Structured documentation with version control
Continuous risk monitoring and alerts
Streamlined conformity assessment preparation
Real-time incident detection and reporting
Centralized evidence with audit trail

EU AI Act compliance roadmap

Follow our structured approach to achieve compliance before critical deadlines arrive.

1

AI Inventory & Classification

Catalog all AI systems in your organization. Classify each system according to EU AI Act risk categories and identify prohibited practices that must be discontinued.

Month 1-2
2

Gap Analysis & Risk Assessment

Assess high-risk systems against regulatory requirements. Identify compliance gaps in data governance, documentation, human oversight, and technical safeguards.

Month 2-3
3

Documentation & Governance

Establish technical documentation frameworks. Implement risk management systems, data quality processes, and governance structures for AI oversight.

Month 3-5
4

Conformity Assessment Preparation

Prepare conformity assessment documentation. Conduct internal assessments and engage notified bodies where required for specific high-risk categories.

Month 5-7
5

Monitoring & Continuous Compliance

Implement post-market monitoring systems. Establish incident reporting procedures, regular audits, and ongoing compliance verification processes.

Month 7+

Frequently asked questions about the EU AI Act

What is the EU AI Act?

The EU AI Act is the world's first comprehensive legal framework for artificial intelligence. Adopted by the European Parliament in March 2024, it establishes harmonized rules for AI systems in the European Union. The regulation takes a risk-based approach, with stricter requirements for higher-risk applications. It covers AI providers, deployers, importers, and distributors operating in or affecting the EU market.

Who needs to comply with the EU AI Act?

The EU AI Act applies to: providers (developers) of AI systems placed on the EU market or put into service in the EU, regardless of their location; deployers (users) of AI systems within the EU; providers and deployers outside the EU whose AI output is used in the EU; importers and distributors of AI systems in the EU. The specific obligations depend on the role and the risk classification of the AI system.

What are the four risk categories?

The EU AI Act classifies AI into four risk levels: Unacceptable Risk (prohibited practices like social scoring and subliminal manipulation), High Risk (systems affecting safety, rights, or critical decisions such as employment, education, and law enforcement), Limited Risk (transparency obligations for chatbots, deepfakes, and emotion recognition), and Minimal Risk (no specific requirements for spam filters, games, and general recommendations).

What are General-Purpose AI (GPAI) requirements?

General-Purpose AI models like large language models have specific requirements including: technical documentation, transparency about training data, compliance with copyright law, and a summary of content used for training. GPAI models with systemic risk (trained with >10^25 FLOPs) face additional requirements including model evaluation, adversarial testing, incident tracking, and cybersecurity protections.

What are the penalties for non-compliance?

The EU AI Act establishes tiered penalties: up to 35 million euros or 7% of global annual turnover for violations involving prohibited AI practices; up to 15 million euros or 3% for violations of high-risk system requirements; up to 7.5 million euros or 1.5% for supplying incorrect or misleading information to authorities. SMEs and startups may receive proportionally reduced fines.

How does the EU AI Act relate to GDPR?

The EU AI Act complements GDPR rather than replacing it. While GDPR focuses on personal data protection, the AI Act addresses broader AI safety and rights concerns. Organizations must comply with both: GDPR for any personal data processing in AI systems, and the AI Act for the AI system itself. Data protection impact assessments under GDPR may inform AI Act risk assessments.

What documentation is required for high-risk AI?

High-risk AI systems require comprehensive technical documentation including: general description and intended purpose, detailed design specifications, training and testing data information, development process documentation, risk management system details, quality management procedures, monitoring and post-market surveillance plans, and instructions for deployers.

How does the EU AI Act apply to US companies?

US companies must comply with the EU AI Act if they: place AI systems on the EU market, provide AI services to EU users, deploy AI in the EU, or have AI outputs used in the EU. This extraterritorial scope means US-based AI developers serving EU customers or deploying systems affecting EU citizens must meet applicable requirements.

Often paired with EU AI Act

Evidr supports 12+ compliance frameworks with shared evidence and unified control mapping.

Ready to achieve EU AI Act compliance?

Schedule a demo with our compliance team. We will walk you through AI risk classification, conformity assessments, and technical documentation management for the EU AI Act.