EU AI Act Compliance
EU AI Act Compliance for Forward-Thinking Organisations
The EU AI Act requires risk classification, conformity assessments, transparency obligations, and AI literacy for every organisation deploying AI. Aona provides employee AI visibility, configured policy enforcement and supporting usage evidence on covered endpoints.
- AI usage visibility
- Endpoint
- governance summaries
- Monthly
- supported AI controls
- Policy-led
- AI tools in the risk catalog
- 10,000+
What the EU AI Act Requires
The EU AI Act introduces obligations for both AI providers and deployers, with significant penalties for non-compliance.
Risk ClassificationCore ObligationClassify Every AI System by Risk Level
The EU AI Act establishes four risk categories: unacceptable (banned), high-risk (strict obligations), limited risk (transparency duties), and minimal risk (no specific rules). Organisations must assess every AI system they deploy or develop against these categories. High-risk AI, used in employment, education, law enforcement, or critical infrastructure, faces the most stringent requirements.
Transparency ObligationsArticle 52Disclose AI Use to Affected Individuals
AI systems that interact with people must clearly disclose that the person is interacting with AI. This applies to chatbots, AI-generated content, and emotion recognition systems. Deep fakes must be labelled. Organisations deploying AI must ensure transparency requirements are met at the point of interaction.
Conformity AssessmentsHigh-RiskDemonstrate Compliance for High-Risk AI
High-risk AI systems must undergo conformity assessments before being placed on the market or put into service. These assessments evaluate risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, and cybersecurity. Some categories require third-party assessment by a notified body.
AI LiteracyArticle 4Ensure Staff Understand AI Systems They Use
Article 4 requires that all staff dealing with AI systems have sufficient AI literacy, an understanding of AI capabilities, limitations, risks, and the regulatory context. This applies to deployers, not just developers. Organisations must implement training programmes proportionate to the AI systems in use and the roles of the individuals involved.
Record-Keeping and LoggingArticle 12Maintain Logs for High-Risk AI Operations
High-risk AI systems must have automatic logging capabilities to ensure traceability. Deployers must keep logs generated by the AI system for a period appropriate to the intended purpose, at least six months. These logs must be available to market surveillance authorities upon request and are essential for post-market monitoring.
The Shadow AI Problem Under the EU AI Act
You cannot classify AI risk or meet transparency obligations for AI tools you do not know about. Shadow AI is the single biggest compliance gap for the EU AI Act.
Unclassified AI Tools in Use
Employees adopt AI tools without assessing their risk category under the EU AI Act. An AI tool used for candidate screening is high-risk, but if adopted by an HR team without IT oversight, it may never receive the required conformity assessment.
No AI Inventory for Regulators
Market surveillance authorities can request a complete inventory of AI systems deployed. Without visibility into Shadow AI, organisations cannot demonstrate compliance or even identify which AI systems are subject to the Act's requirements.
Missing Transparency Disclosures
Customer-facing teams using AI chatbots, AI-generated emails, or AI-assisted responses may fail to disclose AI involvement, a direct transparency violation. Shadow AI tools deployed without governance are unlikely to include required disclosures.
How Aona Helps With EU AI Act Compliance
Workforce AI security controls and usage evidence to support your organisation's EU AI Act review.
AI Inventory for Your Risk Review
Aona discovers AI tool use on endpoints where its browser plugin or native app is deployed. Use the inventory and data-risk information to inform your review of EU AI Act risk categories, conformity-assessment needs and prohibited practices. Your organisation determines the legal classification and applicable obligations.
Usage and Policy Reporting
Review recorded AI usage, policy events and framework coverage to support your compliance evidence collection. Reports reflect supported clients, input paths and configured retention; they do not establish regulatory compliance or replace your assessment of transparency and logging obligations.
Evidence for Conformity Preparation
Use records of employee AI use and policy events alongside the technical assessments required for your AI systems. Aona does not provide AI agent security testing or evaluate the accuracy and robustness of high-risk AI systems for conformity assessments.
Configured AI Usage Policies
Approve, restrict or block supported AI tools by role and data sensitivity. Apply configured policies to supported interactions; manage deployment approvals and transparency obligations through your organisation's review process.
FAQ
Frequently Asked Questions
When does the EU AI Act come into effect?
Does the EU AI Act apply to companies outside the EU?
What is the AI literacy requirement under Article 4?
How do I classify AI risk under the EU AI Act?
Get Ahead of EU AI Act Requirements
Discover employee AI use on covered endpoints, apply configured policies and gather evidence for your EU AI Act review. Article 4 AI literacy training for your whole team is free.