Skip to content

EU AI Act

Miniature domed certification workshop where robots queue at a reception desk to be scanned and sorted into low, medium, high and critical risk chutes

Regulation (EU) 2024/1689: the first comprehensive AI regulation, with a risk-based approach and obligations phasing in over several years. Obligations differ sharply by role (provider vs. deployer) and risk class, so scoping comes first.

What the Digital Omnibus actually changed: The Digital Omnibus didn't delay the AI Act, it rewrote parts of it.

Verifying control text against the regulation itself: regcheck.

Start here

Planned branches

Area Planned artefacts
Scoping & classification Role and risk-class decision checklist (provider / deployer / importer / distributor)
Prohibited practices & AI literacy Quick-reference checklist for the earliest-applying obligations
High-risk AI systems Document inventory (technical documentation, risk management, logging) · responsibility matrix
GPAI models Obligations overview for organizations consuming GPAI
AI governance operating model How to run AI governance alongside existing risk and compliance functions

Under construction

This branch opens after DORA and NIS2 foundations ship. Application dates for individual obligations are staggered. Each artefact will state which dates apply and link the official source, since guidance is still evolving.

From my library

Links from my reading library that help with AI Act work.

Primary sources