European regulation

AI Act: are you prepared?

The EU regulation on AI imposes transparency, traceability, and documentation obligations. Compliance cannot be improvised — it has to be built.

AI Act self-assessment

Assess your AI Act exposure in 5 questions

The EU regulation on AI imposes specific obligations on high-risk systems. This quick assessment shows where you stand in under 2 minutes.

Question 1 / 5

Which sector do you operate in?

Key points for executives

The more AI is involved in a sensitive process, the more the organization must be able to document how it is used, its control rules, its responsibilities, and the planned human interventions. The AI Act progressively strengthens this requirement according to the nature of the system and its risk level, with a regime of proportionate penalties for established infringements.

Impact: internal governance, choice of vendors, documentation, human oversight, and the architecture of AI systems.

Read Regulation (EU) 2024/1689 — official text of the AI Act

Understanding the AI Act in 5 minutes

The AI Act is the world's first legal framework dedicated to artificial intelligence. It imposes obligations proportionate to the risk level of the AI systems deployed.

Published in the Official Journal on July 12, 2024, and in force since August 1, 2024, the regulation applies to organizations that develop, distribute, or use AI systems within the European Union — including non-European companies operating on the EU market. The text of Regulation (EU) 2024/1689 on EUR-Lex is the legal reference; it was amended by Regulation (EU) 2026/1744 (the Digital Omnibus on AI, in force since July 27, 2026), which notably set new application dates for high-risk systems.

For an overview, see the European Commission's presentation of the regulatory framework and the questions and answers from the CNIL (the French data protection authority).

The legislator's stated aim: AI used in Europe that is safe, transparent, and respectful of fundamental rights.

The AI Act's 4 risk levels

Unacceptable

Prohibited AI systems: social scoring, subliminal manipulation, exploitation of vulnerabilities. Fully banned since February 2025. See the European Commission's guidelines on prohibited AI practices. [official source]

High risk

Systems subject to the strictest obligations: technical documentation, risk management, traceability, human oversight. Classification is based on uses, not sectors: certain uses in employment, education, access to essential services (including creditworthiness assessment), critical infrastructure, the administration of justice, or migration (Annex III), as well as safety components of regulated products (Annex I), may fall into this category depending on their function and context.

Limited risk

Transparency obligations: users must be informed that they are interacting with an AI. Covers, in particular, chatbots, deepfakes, and AI-generated content.

Minimal risk

No specific obligation. Covers spam filters, video games, productivity assistants with no significant impact on decisions.

Application timeline

February 2, 2025Active

Prohibition of unacceptable-risk practices (Article 5) and AI literacy obligation (Article 4)

August 2, 2025Active

Obligations for general-purpose AI (GPAI) models and establishment of governance

August 2, 2026Active

General application of the regulation and transparency obligations (Article 50)

December 2, 2027Upcoming

Obligations for Annex III high-risk systems (stand-alone systems: employment, essential services, justice, etc.) — date set by Regulation (EU) 2026/1744

August 2, 2028Upcoming

High-risk systems embedded in regulated products covered by Annex I (medical devices, machinery, etc.)

Sources: Regulation (EU) 2024/1689, Article 113, as amended by Regulation (EU) 2026/1744 (OJ of July 24, 2026). The dates for high-risk systems were postponed by the latter; the other deadlines are unchanged.

Key obligations for companies

Technical documentation

Every high-risk AI system must be accompanied by complete technical documentation describing how it works, its training data and its performance.

Risk management

A risk management system must be put in place, covering the identification, analysis, and mitigation of risks throughout the system's lifecycle.

Transparency and traceability

Decisions made by AI must be traceable and explainable. Activity logs must be kept for a period appropriate to the system's intended purpose, of at least six months.

Human oversight

High-risk systems must include human oversight mechanisms that make it possible to understand, monitor, and interrupt the system when necessary.

AI Act checklist

Get the AI Act checklist, ready to present to your executive committee

The 7 priority actions to prepare your organization for the AI Act, summarized in 2 pages. PDF format, ready to act on.

How KOREV maps to the requirements of the AI Act

Put AI into production with its control rules built in. The KOREV architecture is designed to integrate the governance, human oversight, and traceability requirements expected of sensitive AI uses — each mechanism maps to an article of the regulation:

Art. 11

Technical documentation

The traces retained by the architecture — models and versions called, sources used, rules applied, approvals — feed into the system's technical documentation.

Art. 12

Record-keeping

The process steps are logged (execution context, intermediate results, divergences detected by PRISM, and approval decisions) and available for review and verification.

Art. 13

Transparency

Evidence links the results produced by agents to their sources and retains the execution and approval context, so that users can understand and verify what is presented to them.

Art. 14

Human oversight

Approval rules define where human review is required; when the criteria are not met, PRISM holds the result instead of letting it through.

Regulatory compliance depends on the context, the system, its use, and the organization's role. KOREV provides technical governance capabilities; on its own, it does not constitute a legal certification of compliance.

Operational summary

Checklist: preparing for AI Act compliance

The priority actions to prepare your organization for the requirements of the EU regulation on artificial intelligence.

  1. 1Map the AI systems used across the organization and identify those whose use falls under Annex III (employment, essential services, justice, etc.) or Annex I (regulated products).
  2. 2Classify each AI system according to the AI Act's 4 risk levels (unacceptable, high, limited, minimal).
  3. 3Put traceability of AI processing in place: logging of the models called, the data used, and the rules applied.
  4. 4Ensure transparency: AI outputs must come with information that business teams and control functions can understand.
  5. 5Document AI systems: technical description, training data, measured performance, known limitations.
  6. 6Build in human oversight: make human intervention on critical decisions possible at any time.
  7. 7Carry out an AI audit to see where each system stands relative to the deadlines that apply to it (December 2, 2027 for Annex III, August 2, 2028 for Annex I) and prioritize the work.

Frequently asked questions about the AI Act

Prepare your response to the AI Act

The deadlines are now set. The penalties are real. Documentation, traceability, and oversight are built into the architecture — not added the day before the deadline.

Confidential assessmentPrioritized action planGoverned, traceable infrastructure