30 días de prueba de riesgos de IA generativa -Empezar ahora
Ir al contenido principal

EU AI Act Compliance

EU AI Act Compliance for Forward-Thinking Organisations

The EU AI Act requires risk classification, conformity assessments, transparency obligations, and AI literacy for every organisation deploying AI. Aona provides employee AI visibility, configured policy enforcement and supporting usage evidence on covered endpoints.

AI usage visibility
Endpoint
governance summaries
Monthly
supported AI controls
Policy-led
AI tools in the risk catalog
10,000+

What the EU AI Act Requires

The EU AI Act introduces obligations for both AI providers and deployers, with significant penalties for non-compliance.

Risk ClassificationCore Obligation

Classify Every AI System by Risk Level

The EU AI Act establishes four risk categories: unacceptable (banned), high-risk (strict obligations), limited risk (transparency duties), and minimal risk (no specific rules). Organisations must assess every AI system they deploy or develop against these categories. High-risk AI, used in employment, education, law enforcement, or critical infrastructure, faces the most stringent requirements.

Transparency ObligationsArticle 52

Disclose AI Use to Affected Individuals

AI systems that interact with people must clearly disclose that the person is interacting with AI. This applies to chatbots, AI-generated content, and emotion recognition systems. Deep fakes must be labelled. Organisations deploying AI must ensure transparency requirements are met at the point of interaction.

Conformity AssessmentsHigh-Risk

Demonstrate Compliance for High-Risk AI

High-risk AI systems must undergo conformity assessments before being placed on the market or put into service. These assessments evaluate risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, and cybersecurity. Some categories require third-party assessment by a notified body.

AI LiteracyArticle 4

Ensure Staff Understand AI Systems They Use

Article 4 requires that all staff dealing with AI systems have sufficient AI literacy, an understanding of AI capabilities, limitations, risks, and the regulatory context. This applies to deployers, not just developers. Organisations must implement training programmes proportionate to the AI systems in use and the roles of the individuals involved.

Record-Keeping and LoggingArticle 12

Maintain Logs for High-Risk AI Operations

High-risk AI systems must have automatic logging capabilities to ensure traceability. Deployers must keep logs generated by the AI system for a period appropriate to the intended purpose, at least six months. These logs must be available to market surveillance authorities upon request and are essential for post-market monitoring.

The Shadow AI Problem Under the EU AI Act

You cannot classify AI risk or meet transparency obligations for AI tools you do not know about. Shadow AI is the single biggest compliance gap for the EU AI Act.

  1. Unclassified AI Tools in Use

    Employees adopt AI tools without assessing their risk category under the EU AI Act. An AI tool used for candidate screening is high-risk, but if adopted by an HR team without IT oversight, it may never receive the required conformity assessment.

  2. No AI Inventory for Regulators

    Market surveillance authorities can request a complete inventory of AI systems deployed. Without visibility into Shadow AI, organisations cannot demonstrate compliance or even identify which AI systems are subject to the Act's requirements.

  3. Missing Transparency Disclosures

    Customer-facing teams using AI chatbots, AI-generated emails, or AI-assisted responses may fail to disclose AI involvement, a direct transparency violation. Shadow AI tools deployed without governance are unlikely to include required disclosures.

How Aona Helps With EU AI Act Compliance

Workforce AI security controls and usage evidence to support your organisation's EU AI Act review.

  1. AI Inventory for Your Risk Review

    Aona discovers AI tool use on endpoints where its browser plugin or native app is deployed. Use the inventory and data-risk information to inform your review of EU AI Act risk categories, conformity-assessment needs and prohibited practices. Your organisation determines the legal classification and applicable obligations.

  2. Usage and Policy Reporting

    Review recorded AI usage, policy events and framework coverage to support your compliance evidence collection. Reports reflect supported clients, input paths and configured retention; they do not establish regulatory compliance or replace your assessment of transparency and logging obligations.

  3. Evidence for Conformity Preparation

    Use records of employee AI use and policy events alongside the technical assessments required for your AI systems. Aona does not provide AI agent security testing or evaluate the accuracy and robustness of high-risk AI systems for conformity assessments.

  4. Configured AI Usage Policies

    Approve, restrict or block supported AI tools by role and data sensitivity. Apply configured policies to supported interactions; manage deployment approvals and transparency obligations through your organisation's review process.

FAQ

Frequently Asked Questions

When does the EU AI Act come into effect?
The EU AI Act entered into force on 1 August 2024. Prohibited AI practices apply from February 2025. Requirements for general-purpose AI models apply from August 2025. High-risk AI system obligations apply from August 2026. Organisations should begin preparing now, as compliance requires significant operational changes including AI inventories, risk classification, and governance frameworks.
Does the EU AI Act apply to companies outside the EU?
Yes. The EU AI Act has extraterritorial scope similar to GDPR. It applies to any organisation that places AI systems on the EU market or uses AI systems whose output is used in the EU, regardless of where the organisation is established. This means US, UK, and other non-EU companies deploying AI that affects EU users or markets must comply.
What is the AI literacy requirement under Article 4?
Article 4 requires organisations deploying AI systems to ensure that their staff and other persons dealing with AI on their behalf have a sufficient level of AI literacy. This includes understanding AI capabilities and limitations, potential risks, and the regulatory framework. Organisations must implement training programmes tailored to the technical knowledge, experience, and context of use.
How do I classify AI risk under the EU AI Act?
The EU AI Act defines four risk categories: Unacceptable risk (banned outright, e.g., social scoring), High risk (strict requirements, e.g., AI in employment or education), Limited risk (transparency obligations, e.g., chatbots), and Minimal risk (no specific obligations). Classification depends on the AI system's intended purpose and the sector in which it operates.
Get started

Get Ahead of EU AI Act Requirements

Discover employee AI use on covered endpoints, apply configured policies and gather evidence for your EU AI Act review. Article 4 AI literacy training for your whole team is free.

EU AI Act Compliance, Preparing Your Organisation for AI Regulation | Aona AI