EU AI Act
The EU AI Act is the European Union's regulation for artificial intelligence, applying tiered obligations to AI systems according to the level of risk they pose.
The EU AI Act introduces a risk-based approach to regulating AI. It distinguishes between prohibited practices, high-risk systems, limited-risk systems with transparency duties, and minimal-risk systems. The obligations on a provider or deployer scale with the risk category.
High-risk systems carry the most extensive requirements, including risk management, data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy and robustness measures. Providers must also establish a quality management system and, in many cases, complete a conformity assessment before placing a system on the market.
Because the Act layers AI-specific duties on top of existing data-protection and security obligations, organizations often manage EU AI Act readiness alongside GDPR and security frameworks, mapping shared controls across all of them.
Related terms
- AI ComplianceAI compliance is the practice of ensuring artificial-intelligence systems meet applicable legal, regulatory, and ethical requirements throughout their lifecycle.
- NIST AI RMFThe NIST AI Risk Management Framework is a voluntary US framework that helps organizations identify, assess, and manage risks associated with AI systems.
- GDPRThe General Data Protection Regulation (GDPR) is the European Union law governing the processing of personal data, granting individuals rights over their data and imposing accountability obligations on organizations.
- Control MappingControl mapping is the practice of linking a single control to the multiple framework requirements it satisfies, so that one piece of evidence can support several frameworks at once.