EU AI Act Compliance Guide
Everything you need to know about the European Union Artificial Intelligence Act (Regulation EU 2024/1689), how it classifies risk, and what documents you need to legally operate.
Overview
The EU AI Act is the world's first comprehensive legal framework for artificial intelligence. It establishes obligations for providers and deployers of AI systems based on a risk-based approach.
Extraterritorial Reach
You do not need to be headquartered in the EU to be affected. If your AI system's output is used within the EU (e.g., an American company providing an AI tool to German customers), you must comply with the EU AI Act.
Risk Tiers
The Act divides AI systems into four distinct risk categories. Your compliance obligations scale proportionally with the risk your system poses to fundamental rights and safety.
1. Prohibited Practices (Unacceptable Risk)
These systems are strictly banned from being deployed or used within the EU under any circumstances.
- Social scoring by governments or public authorities.
- Subliminal manipulation causing physical or psychological harm.
- Emotion recognition in workplaces or educational institutions.
- Predictive policing based solely on profiling.
2. High-Risk Systems (Annex III)
These systems require strict ex-ante compliance, rigorous testing, and continuous monitoring. They require a complete portfolio of compliance dossiers.
- Employment & HR: CV screening, automated hiring, performance evaluation.
- Education: Automated grading, student admissions, proctoring.
- Essential Services: Credit scoring, emergency dispatch, life/health insurance.
- Biometrics: Categorisation based on sensitive traits (non-prohibited).
3. Limited Risk (Transparency)
Systems that interact with humans or generate content must disclose that they are AI.
- Chatbots and customer service virtual assistants.
- Generative AI creating synthetic audio, video, or text (Deepfakes).
4. Minimal Risk
The vast majority of AI systems fall here. They are exempt from mandatory documentation obligations (though voluntary codes of conduct are encouraged).
Required Documents
If your system is classified as High-Risk or handling personal/autonomous decisions, Diliga automatically drafts the complete set of statutory dossiers and governance extensions:
1. Risk Management System (Article 9)
A continuous iterative process to identify, estimate, and evaluate known and foreseeable risks. It requires documenting specific mitigation measures and residual risks.
2. Technical Documentation (Article 11 & Annex IV)
A comprehensive architectural breakdown of the AI system, detailing logic, training data sources, third-party dependencies, and design choices. It must be drawn up before the system is placed on the market.
3. Human Oversight Measures Framework (Article 14)
Documentation proving the system can be effectively overseen by natural persons. It must detail mechanisms for a human to intervene, override, or stop the system.
4. Fundamental Rights Impact Assessment (Article 27)
An evaluation of how the system might negatively impact marginalized groups, privacy, data protection, and equality, complete with a mitigation plan.
5. Transparency Disclosure Notice (Article 50)
Mandatory for both High and Limited risk systems. A drafted notice intended for end-users explicitly stating they are interacting with an AI system.
6. Data Protection Impact Assessment (GDPR Article 35 DPIA)
Required whenever an AI system processes personal or sensitive data. Validates data minimization, legal processing grounds, and user rights alongside the AI Act.
7. Human Review & Recourse Procedure (Art 14 & GDPR Art 22)
A standalone operational procedure for individuals affected by automated AI decisions to request human review, contest results, and seek recourse.
Enforcement Timeline
The AI Act entered into force on August 1, 2024, but its obligations apply in staggered phases to give companies time to prepare:
February 2, 2025 (6 Months)
Prohibited Practices Banned. Systems engaging in social scoring, scraping facial images, or workplace emotion recognition must be decommissioned.
August 2, 2026 (24 Months)
High-Risk (Annex III) & Transparency Rules Apply. General high-risk systems (HR, Education, Credit Scoring) must have their compliance dossiers complete and available. Chatbots and deepfakes must implement transparency disclosures.
August 2, 2027 (36 Months)
Product Safety High-Risk Apply. Systems falling under existing product safety legislation (e.g., medical devices, automotive) must comply with AI Act requirements.
Penalties for Non-Compliance
Fines are severe. Using prohibited practices incurs fines up to €35,000,000 or 7% of global annual turnover. Failure to provide required High-Risk documentation (Articles 9, 11, 14, 27) can result in fines up to €15,000,000 or 3% of global turnover.

