EU AI Act Compliance
EU AI Act Compliance for Forward-Thinking Organisations
The EU AI Act sets different duties for providers and deployers, depending on the system, intended use and applicable dates. Aona provides employee AI visibility, configured policy enforcement and supporting usage evidence on covered endpoints.
- AI usage visibility
- Endpoint
- governance summaries
- Monthly
- supported AI controls
- Policy-led
- AI tools in the risk catalog
- 10,000+
What the EU AI Act Requires
The EU AI Act introduces obligations for both AI providers and deployers, with significant penalties for non-compliance.
Risk ClassificationCore ObligationClassify Every AI System by Risk Level
The EU AI Act establishes four risk categories: unacceptable (banned), high-risk (strict obligations), limited risk (transparency duties), and minimal risk (no specific rules). Organisations must assess every AI system they deploy or develop against these categories. High-risk AI, used in employment, education, law enforcement, or critical infrastructure, faces the most stringent requirements.
Transparency ObligationsArticle 50Disclose AI Use to Affected Individuals
Article 50 sets transparency duties for certain AI systems and uses. These include direct interaction with people, synthetic content, emotion recognition and deepfakes. Duties differ for providers and deployers and include specific exceptions. Check the relevant use and role to determine what disclosure or marking is required.
Conformity AssessmentsHigh-RiskDemonstrate Compliance for High-Risk AI
High-risk AI systems must undergo conformity assessments before being placed on the market or put into service. These assessments evaluate risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, and cybersecurity. Some categories require third-party assessment by a notified body.
AI LiteracyArticle 4Ensure Staff Understand AI Systems They Use
Article 4 requires that all staff dealing with AI systems have sufficient AI literacy, an understanding of AI capabilities, limitations, risks, and the regulatory context. This applies to deployers, not just developers. Organisations must implement training programmes proportionate to the AI systems in use and the roles of the individuals involved.
Record-Keeping and LoggingArticle 12Maintain Logs for High-Risk AI Operations
High-risk AI systems must have automatic logging capabilities to ensure traceability. Deployers must keep logs generated by the AI system for a period appropriate to the intended purpose, at least six months. These logs must be available to market surveillance authorities upon request and are essential for post-market monitoring.
The Shadow AI Problem Under the EU AI Act
You cannot classify AI risk or meet transparency obligations for AI tools you do not know about. Shadow AI is the single biggest compliance gap for the EU AI Act.
Unclassified AI Tools in Use
Employees adopt AI tools without assessing their risk category under the EU AI Act. An AI tool used for candidate screening is high-risk, but if adopted by an HR team without IT oversight, it may never receive the required conformity assessment.
No AI Inventory for Regulators
Market surveillance authorities can request a complete inventory of AI systems deployed. Without visibility into Shadow AI, organisations cannot demonstrate compliance or even identify which AI systems are subject to the Act's requirements.
Missing Transparency Disclosures
Unreviewed AI use can miss transparency duties for a particular system or use. Review the organisation's role, the type of interaction or content, and the applicable Article 50 exceptions to determine what disclosure is required.
Aona in practice
From requirement to a practical control
Connect employee AI visibility with the decisions your AI Act programme needs to make.
Article 6 → use-case reviewStart classification with observed AI use
- The requirement
- High-risk classification depends on the system and its intended purpose under the Act's rules.
- What Aona contributes
- Surface AI tools used on covered endpoints so owners can identify and review the associated use cases.
- Evidence to review
- Use the observed inventory and usage information to start a record of the system, owner and intended purpose.
- Your organisation owns
- Establish your provider or deployer role and classify the use case. Aona's data-risk information does not determine its legal category.
Article 4 → AI literacyBase staff guidance on actual AI use
- The requirement
- Providers and deployers must take measures towards sufficient AI literacy for relevant staff, considering their knowledge and the context of use.
- What Aona contributes
- Use covered-endpoint tool usage and policy events to identify relevant topics for staff guidance.
- Evidence to review
- Pair those findings with your training plan, attendance and assessment records.
- Your organisation owns
- Design appropriate training and assess competence. Usage telemetry and policy notices do not establish that literacy requirements are met.
Article 26(1) and (2) → operating rulesSupport the rules around human oversight
- The requirement
- Relevant high-risk deployers must follow the system's instructions and assign oversight to people with the necessary competence, training and authority.
- What Aona contributes
- Apply your approved tool and sensitive-data policies to supported employee AI interactions.
- Evidence to review
- Compare configured restrictions and recorded policy events with the permitted uses in your operating procedure.
- Your organisation owns
- Assign reviewers, decision rights and intervention procedures. Human approval routing and control of every agent action require their own controls.
Article 26(5) and (6) → monitoring and recordsUse policy events in monitoring reviews
- The requirement
- Relevant high-risk deployers have monitoring, incident and system-log obligations, subject to the Act's conditions.
- What Aona contributes
- Review employee AI usage and policy events from supported interactions as one part of your monitoring process.
- Evidence to review
- Combine relevant Aona events with the AI system's own logs, provider instructions and investigation records.
- Your organisation owns
- Meet applicable log retention, reporting and suspension duties. Aona events do not replace logs generated by the high-risk AI system.
Obligations depend on your role, the system's intended use and applicable dates. The high-risk deployer examples apply only where those duties are relevant and in force.
FAQ
Frequently Asked Questions
When does the EU AI Act come into effect?
Does the EU AI Act apply to companies outside the EU?
What is the AI literacy requirement under Article 4?
How do I classify AI risk under the EU AI Act?
Get Ahead of EU AI Act Requirements
Discover employee AI use on covered endpoints, apply configured policies and gather evidence for your EU AI Act review. Article 4 AI literacy training for your whole team is free.