EU AI Act Compliance: How to Assess Your AI Systems

Updated · Assessed Solutions

ProhibitedHigh-riskLimited riskMinimal riskMost obligations sit hereEU AI ACT

Short answer: EU AI Act compliance starts with knowing which AI systems you operate and what each one does. From there, organizations classify each system by risk, determine the obligations that follow from that classification, collect evidence that the required controls exist, and keep that evidence current as the system changes.

Key takeaways

  • Compliance starts with an accurate inventory of every AI system you operate.
  • Risk classification drives the obligations, so it must stay current as systems change.
  • Human oversight must be evidenced in the workflow, not only described in policy.

How the EU AI Act is structured

The EU AI Act regulates AI systems by risk. Some practices are prohibited outright. High-risk systems, such as those used in employment, credit, education, and critical services, carry obligations for risk management, data governance, technical documentation, logging, human oversight, accuracy, and cybersecurity. Limited-risk systems carry transparency obligations, and general-purpose AI models have their own requirements. The Act’s obligations phase in over several years, so organizations should confirm the current timeline for the provisions that apply to them.

A five-step assessment approach

  1. Inventory. Identify every AI system, including models, agents, and third-party AI embedded in products.
  2. Classify. Determine whether each system is prohibited, high-risk, limited-risk, or minimal-risk, and whether you act as a provider or a deployer.
  3. Map obligations. Translate the classification into specific requirements and the controls that satisfy them.
  4. Evidence. Collect proof that each control exists and works, from documentation, configuration, logs, and tests.
  5. Maintain. Re-assess when the system changes and when evidence expires, not once a year.

Where teams struggle

The hardest part is rarely reading the law. It is knowing which systems are in scope, keeping classification accurate as capabilities change, and producing evidence that holds up. Human oversight is a common gap: a written policy that a person reviews automated decisions is not the same as evidence that the review step exists in the workflow.

How Assessed Govern helps

Assessed Govern discovers AI systems from code, cloud, and identity, determines whether the EU AI Act is likely in scope, maps the applicable requirements through the ARISE Framework™ crosswalk, and shows the evidence state for each. Its determination record is the document you hand a regulator, and the same assessment covers NIST AI RMF and ISO 42001 at the same time.

Questions

Does the EU AI Act apply to companies outside the EU?

It can. The Act applies to providers that place AI systems on the EU market and to deployers whose AI system outputs are used in the EU, regardless of where the organization is established.

What makes an AI system high-risk under the EU AI Act?

A system is generally high-risk when it is a safety component of a regulated product or when it is used in listed areas such as employment, access to essential services, education, law enforcement, or critical infrastructure.

Can one assessment cover the EU AI Act and other frameworks?

Yes, when requirements are mapped through a common control set. Assessed Govern maps each system once to ARISE controls and then to more than 42 frameworks, so shared evidence satisfies overlapping requirements.

Join the beta

Tell us about your organization and which platform you want to run. We use these details only to contact you about the beta, as described in our Privacy Policy.

Interested in

By signing up, you agree that Assessed Solutions may contact you about the beta. You can ask us to delete your details at any time. See our Privacy Policy.

You're on the list.

Thank you for your interest. We will contact you at the email you provided with next steps for the beta.