European regulation
The EU regulation on AI imposes transparency, traceability, and documentation obligations. Compliance cannot be improvised — it has to be built.
The EU regulation on AI imposes specific obligations on high-risk systems. This quick assessment shows where you stand in under 2 minutes.
Key points for executives
The more AI is involved in a sensitive process, the more the organization must be able to document how it is used, its control rules, its responsibilities, and the planned human interventions. The AI Act progressively strengthens this requirement according to the nature of the system and its risk level, with a regime of proportionate penalties for established infringements.
Impact: internal governance, choice of vendors, documentation, human oversight, and the architecture of AI systems.
Read Regulation (EU) 2024/1689 — official text of the AI ActThe AI Act is the world's first legal framework dedicated to artificial intelligence. It imposes obligations proportionate to the risk level of the AI systems deployed.
Published in the Official Journal on July 12, 2024, and in force since August 1, 2024, the regulation applies to organizations that develop, distribute, or use AI systems within the European Union — including non-European companies operating on the EU market. The text of Regulation (EU) 2024/1689 on EUR-Lex is the legal reference; it was amended by Regulation (EU) 2026/1744 (the Digital Omnibus on AI, in force since July 27, 2026), which notably set new application dates for high-risk systems.
For an overview, see the European Commission's presentation of the regulatory framework and the questions and answers from the CNIL (the French data protection authority).
The legislator's stated aim: AI used in Europe that is safe, transparent, and respectful of fundamental rights.
Prohibited AI systems: social scoring, subliminal manipulation, exploitation of vulnerabilities. Fully banned since February 2025. See the European Commission's guidelines on prohibited AI practices. [official source]
Systems subject to the strictest obligations: technical documentation, risk management, traceability, human oversight. Classification is based on uses, not sectors: certain uses in employment, education, access to essential services (including creditworthiness assessment), critical infrastructure, the administration of justice, or migration (Annex III), as well as safety components of regulated products (Annex I), may fall into this category depending on their function and context.
Transparency obligations: users must be informed that they are interacting with an AI. Covers, in particular, chatbots, deepfakes, and AI-generated content.
No specific obligation. Covers spam filters, video games, productivity assistants with no significant impact on decisions.
Prohibition of unacceptable-risk practices (Article 5) and AI literacy obligation (Article 4)
Obligations for general-purpose AI (GPAI) models and establishment of governance
General application of the regulation and transparency obligations (Article 50)
Obligations for Annex III high-risk systems (stand-alone systems: employment, essential services, justice, etc.) — date set by Regulation (EU) 2026/1744
High-risk systems embedded in regulated products covered by Annex I (medical devices, machinery, etc.)
Sources: Regulation (EU) 2024/1689, Article 113, as amended by Regulation (EU) 2026/1744 (OJ of July 24, 2026). The dates for high-risk systems were postponed by the latter; the other deadlines are unchanged.
Every high-risk AI system must be accompanied by complete technical documentation describing how it works, its training data and its performance.
A risk management system must be put in place, covering the identification, analysis, and mitigation of risks throughout the system's lifecycle.
Decisions made by AI must be traceable and explainable. Activity logs must be kept for a period appropriate to the system's intended purpose, of at least six months.
High-risk systems must include human oversight mechanisms that make it possible to understand, monitor, and interrupt the system when necessary.
AI Act checklist
The 7 priority actions to prepare your organization for the AI Act, summarized in 2 pages. PDF format, ready to act on.
Put AI into production with its control rules built in. The KOREV architecture is designed to integrate the governance, human oversight, and traceability requirements expected of sensitive AI uses — each mechanism maps to an article of the regulation:
Technical documentation
The traces retained by the architecture — models and versions called, sources used, rules applied, approvals — feed into the system's technical documentation.
Record-keeping
The process steps are logged (execution context, intermediate results, divergences detected by PRISM, and approval decisions) and available for review and verification.
Transparency
Evidence links the results produced by agents to their sources and retains the execution and approval context, so that users can understand and verify what is presented to them.
Human oversight
Approval rules define where human review is required; when the criteria are not met, PRISM holds the result instead of letting it through.
Regulatory compliance depends on the context, the system, its use, and the organization's role. KOREV provides technical governance capabilities; on its own, it does not constitute a legal certification of compliance.
Operational summary
The priority actions to prepare your organization for the requirements of the EU regulation on artificial intelligence.
The deadlines are now set. The penalties are real. Documentation, traceability, and oversight are built into the architecture — not added the day before the deadline.