Short answer: EU AI Act compliance starts with knowing which AI systems you operate and what each one does. From there, organizations classify each system by risk, determine the obligations that follow from that classification, collect evidence that the required controls exist, and keep that evidence current as the system changes.
- Compliance starts with an accurate inventory of every AI system you operate.
- Risk classification drives the obligations, so it must stay current as systems change.
- Human oversight must be evidenced in the workflow, not only described in policy.
How the EU AI Act is structured
The EU AI Act regulates AI systems by risk. Some practices are prohibited outright. High-risk systems, such as those used in employment, credit, education, and critical services, carry obligations for risk management, data governance, technical documentation, logging, human oversight, accuracy, and cybersecurity. Limited-risk systems carry transparency obligations, and general-purpose AI models have their own requirements. The Act’s obligations phase in over several years, so organizations should confirm the current timeline for the provisions that apply to them.
A five-step assessment approach
- Inventory. Identify every AI system, including models, agents, and third-party AI embedded in products.
- Classify. Determine whether each system is prohibited, high-risk, limited-risk, or minimal-risk, and whether you act as a provider or a deployer.
- Map obligations. Translate the classification into specific requirements and the controls that satisfy them.
- Evidence. Collect proof that each control exists and works, from documentation, configuration, logs, and tests.
- Maintain. Re-assess when the system changes and when evidence expires, not once a year.
Where teams struggle
The hardest part is rarely reading the law. It is knowing which systems are in scope, keeping classification accurate as capabilities change, and producing evidence that holds up. Human oversight is a common gap: a written policy that a person reviews automated decisions is not the same as evidence that the review step exists in the workflow.
How Assessed Govern helps
Assessed Govern discovers AI systems from code, cloud, and identity, determines whether the EU AI Act is likely in scope, maps the applicable requirements through the ARISE Framework⢠crosswalk, and shows the evidence state for each. Its determination record is the document you hand a regulator, and the same assessment covers NIST AI RMF and ISO 42001 at the same time.
Questions
Does the EU AI Act apply to companies outside the EU?
It can. The Act applies to providers that place AI systems on the EU market and to deployers whose AI system outputs are used in the EU, regardless of where the organization is established.
What makes an AI system high-risk under the EU AI Act?
A system is generally high-risk when it is a safety component of a regulated product or when it is used in listed areas such as employment, access to essential services, education, law enforcement, or critical infrastructure.
Can one assessment cover the EU AI Act and other frameworks?
Yes, when requirements are mapped through a common control set. Assessed Govern maps each system once to ARISE controls and then to more than 42 frameworks, so shared evidence satisfies overlapping requirements.
