EU AI Act Compliance

Navigate the world's first comprehensive AI regulation

Evidr automates EU AI Act compliance with risk classification, conformity assessments, and technical documentation management. Prepare for phased deadlines starting February 2025 and avoid penalties up to 7% of global turnover.

EU AI ActEUAI Act
EU AI ActRegulation (EU) 2024/1689On every plan
  • Controls and evidence requirements mapped in advance
  • Every upload read and scored by the AI reviewer
  • Policies, monitoring and the auditor portal included
Shares evidence withNIST AI RMFISO 42001SOC 2
27EU member states covered
7%Max penalty (global turnover)
4Risk classification levels
2025First compliance deadlines

Inside the product

EU AI Act in the console, control by control.

The Evidr dashboard in a live workspace: SOC 2 Type II at 100% with 68 of 68 controls, 68 approved evidence items, a 99% pass rate on 103 checks, and quick actions beside them.

01EU AI Act

Four risk tiers

Obligations scale with risk. Most of the Act is written for the high-risk tier.

  • 01Banned from the EU market

    Unacceptable Risk

    Prohibited AI practices that pose clear threats to safety, livelihoods, or rights

    • Social scoring by governments
    • Real-time remote biometric ID in public spaces
    • Emotion recognition in workplace/education
    • Subliminal manipulation techniques
  • 02Strict compliance requirements

    High Risk

    AI systems that significantly impact safety, fundamental rights, or critical decisions

    • Critical infrastructure management
    • Educational scoring and access
    • Employment and recruitment
    • Credit scoring and insurance
    • Law enforcement tools
  • 03Transparency obligations

    Limited Risk

    AI systems with specific transparency obligations

    • Chatbots and virtual assistants
    • Emotion recognition systems
    • Deepfake generation
    • AI-generated content
  • 04No specific requirements

    Minimal Risk

    AI systems with no specific regulatory requirements

    • Spam filters
    • AI-enabled video games
    • Inventory management
    • Content recommendations

02EU AI Act

High-risk obligations

What Articles 9 to 15 ask of a provider of a high-risk system.

  • Risk Management SystemEstablish and maintain a risk management system throughout the AI system lifecycle
  • Data GovernanceEnsure training, validation, and testing data meets quality criteria and is representative
  • Technical DocumentationDraw up comprehensive technical documentation before placing system on market
  • Record-KeepingEnable automatic recording of events (logs) throughout system operation
  • TransparencyProvide clear information to deployers about system capabilities and limitations
  • Human OversightDesign systems to be effectively overseen by natural persons
  • Accuracy & RobustnessAchieve appropriate levels of accuracy, robustness, and cybersecurity
  • Conformity AssessmentUndergo conformity assessment before placing on market or putting into service

03EU AI Act

Deadlines

The Act applies in stages.

  • February 2025Prohibited AI PracticesAI systems with unacceptable risk must be removed from the EU market
  • August 2025General-Purpose AI (GPAI)GPAI model providers must comply with transparency and documentation requirements
  • August 2026High-Risk AI SystemsFull compliance required for high-risk AI systems in Annex III categories
  • August 2027Embedded High-Risk AICompliance deadline for high-risk AI embedded in regulated products

04What Evidr does

Everything EU AI Act asks for, handled.

  • 01

    AI Risk Classification

    Automatically assess and classify your AI systems against EU AI Act risk categories. Determine if your systems are prohibited, high-risk, limited risk, or minimal risk.

  • 02

    Conformity Assessments

    Conduct and document conformity assessments for high-risk AI systems. Generate technical documentation and compliance declarations for notified bodies.

  • 03

    Technical Documentation

    Maintain comprehensive technical documentation including system design, training data, testing results, and performance metrics required by the regulation.

  • 04

    Post-Market Monitoring

    Implement continuous monitoring systems to track AI performance, detect drift, and report serious incidents to authorities within required timeframes.

  • 05

    Transparency Requirements

    Meet transparency obligations with automated disclosures for AI-generated content, emotion recognition systems, and biometric categorization.

  • 06

    Audit Trail Management

    Maintain immutable audit logs of AI system decisions, model updates, and compliance activities. Demonstrate accountability to regulators and auditors.

05The path

EU AI Act readiness, step by step.

  1. 01Month 1-2

    AI Inventory & Classification

    Catalog all AI systems in your organization. Classify each system according to EU AI Act risk categories and identify prohibited practices that must be discontinued.

  2. 02Month 2-3

    Gap Analysis & Risk Assessment

    Assess high-risk systems against regulatory requirements. Identify compliance gaps in data governance, documentation, human oversight, and technical safeguards.

  3. 03Month 3-5

    Documentation & Governance

    Establish technical documentation frameworks. Implement risk management systems, data quality processes, and governance structures for AI oversight.

  4. 04Month 5-7

    Conformity Assessment Preparation

    Prepare conformity assessment documentation. Conduct internal assessments and engage notified bodies where required for specific high-risk categories.

  5. 05Month 7+

    Monitoring & Continuous Compliance

    Implement post-market monitoring systems. Establish incident reporting procedures, regular audits, and ongoing compliance verification processes.

06Questions

EU AI Act, answered.

Ready for EU AI Act?

Start on the free Starter plan, or talk to us and see EU AI Act set up on your own stack.