1.5 The EU AI Act (Regulation 2024/1689): Risk Tiers, Compliance Obligations & Timeline

Key Takeaways

  • The EU AI Act (Regulation 2024/1689) is the world's first comprehensive, binding statutory AI law, establishing a risk-tiered product safety framework.
  • Prohibited AI practices (Unacceptable Risk) face an absolute ban, including subliminal manipulation, social scoring, biometric categorization for sensitive attributes, and untargeted facial image scraping.
  • High-Risk AI systems (Annex I & III) must comply with rigorous mandatory obligations under Articles 9–15, including risk management, data governance, technical documentation, logging, transparency, human oversight, and accuracy.
  • General-Purpose AI (GPAI) model providers face specialized transparency rules, with additional systemic risk requirements applied to models trained using exceeding $10^{25}$ FLOPs.
  • ISO/IEC 42001 serves as a key presumption-of-conformity standard under European CEN-CENELEC harmonization for High-Risk AI compliance.
Last updated: July 2026

1.5 The EU AI Act (Regulation 2024/1689): Risk Tiers, Compliance Obligations & Timeline

Entering into force in 2024, Regulation (EU) 2024/1689 (commonly known as the EU AI Act) represents the world's first binding, comprehensive statutory legal framework for artificial intelligence. Applying an extraterritorial scope similar to the GDPR, the AI Act regulates any provider or deployer placing AI systems on the EU market or whose AI outputs affect individuals within the European Union. For an ISO/IEC 42001 Lead Implementer, mastering the EU AI Act is vital for establishing audit-ready AIMS controls that satisfy European statutory mandates.


The EU AI Act Risk Pyramid

The EU AI Act categorizes AI applications into a four-tiered Pyramid of Risk, imposing compliance obligations proportionate to potential harm:

                     /
                    /  Unacceptable Risk  \   ◄── Absolutely Prohibited (Article 5)
                   /-----------------------\   
                  /     High-Risk AI        \  ◄── Mandatory Articles 9-15 Compliance
                 /---------------------------\ 
                /  Specific Transparency Risk \ ◄── Disclosure Obligations (Article 50)
               /-------------------------------\ 
              /   Minimal / Low Risk AI Systems \ ◄── Voluntary Codes of Conduct
             /-----------------------------------\

1. Unacceptable Risk (Prohibited AI Practices — Article 5)

Certain AI applications are deemed contrary to fundamental European values and are strictly banned:

  • Subliminal or Deceptive Manipulation: Manipulating human behavior to cause significant harm.
  • Exploitation of Vulnerabilities: Exploiting age, disability, or socio-economic status.
  • Social Scoring: Classifying individuals based on social behavior or personality traits leading to detrimental treatment.
  • Biometric Categorization: Categorizing individuals based on sensitive attributes (race, political orientation, religion).
  • Untargeted Facial Image Scraping: Creating facial recognition databases via untargeted scraping of the internet or CCTV footage.
  • Emotion Recognition: Inferring emotions in workplace and educational environments (except medical/safety reasons).
  • Predictive Policing: Assessing risk of individual criminal offense based solely on profiling or personality traits.

2. High-Risk AI Systems (Articles 6, Annex I & Annex III)

AI systems classified as High-Risk encompass:

  • Annex I: AI used as safety components of regulated products (e.g., medical devices, aviation, automobiles).
  • Annex III Standalone Applications: Biometrics, critical infrastructure management, educational admissions/evaluations, employment and HR management (recruitment, performance ranking), access to essential private/public services (credit scoring, health insurance), law enforcement, migration and asylum administration, and justice administration.

3. General-Purpose AI (GPAI) Models (Articles 51–56)

Large-scale foundation models capable of performing a wide range of tasks are subject to specific rules:

  • Standard GPAI Models: Must provide technical documentation, comply with EU copyright law, and publish a detailed summary of training data content.
  • GPAI Models with Systemic Risk: Models trained using total computing capacity exceeding $10^{25}$ FLOPs (Floating Point Operations) are designated as systemic, triggering mandatory model evaluations, adversarial red-teaming, cybersecurity protection, and incident reporting to the European AI Office.

4. Specific Transparency Risk (Article 50)

AI systems interacting directly with humans (chatbots), generating synthetic media (deepfakes), or generating text published to inform the public must explicitly disclose that the output is artificially generated.


Mandatory Compliance Obligations for High-Risk AI (Articles 9–15)

Providers of High-Risk AI systems must implement a comprehensive compliance framework before placing systems on the market:

  • Article 9 (Risk Management System): Establishing a continuous, iterative risk management system throughout the entire AI lifecycle.
  • Article 10 (Data & Data Governance): Ensuring training, validation, and testing datasets meet high quality standards, addressing bias and data relevance.
  • Article 11 & 12 (Technical Documentation & Record-Keeping): Maintaining detailed technical documentation and enabling automated operational event logging (audit trails).
  • Article 13 (Transparency & Provision of Information): Ensuring clear instructions for use and system performance metrics for deployers.
  • Article 14 (Human Oversight): Designing systems to enable effective human oversight (HITL/HOTL capabilities).
  • Article 15 (Accuracy, Robustness & Cybersecurity): Ensuring resilience against errors, adversarial attacks, and cyber threats.

Enforcement Timeline & Administrative Penalties

The EU AI Act applies a staggered enforcement schedule following its entry into force:

  • 6 Months: Prohibitions on Unacceptable Risk AI systems take effect.
  • 12 Months: Governance rules for GPAI models and AI Office enforcement powers take effect.
  • 24 Months: Full compliance required for High-Risk AI systems listed under Annex III.
  • 36 Months: Compliance required for High-Risk AI systems embedded in Annex I regulated products.

Financial Fines (Article 99)

  • Prohibited AI Violations: Up to €35 Million or 7% of total global annual turnover (whichever is higher).
  • Non-Compliance with High-Risk Obligations: Up to €15 Million or 3% of global turnover.
  • Supplying Incorrect Information to Regulators: Up to €7.5 Million or 1% of global turnover (Article 99(5)).

ISO/IEC 42001 Mapping to EU AI Act High-Risk Requirements

EU AI Act ArticleHigh-Risk Statutory RequirementISO/IEC 42001 AIMS Control Mapping
Article 9Continuous Risk Management SystemClauses 6.1 & 8.2–8.3 (AI risk assessment/treatment) plus Annex A.5 impact assessment
Article 10Data Governance & Bias MitigationAnnex A.7 (Data for AI systems: quality, provenance, preparation)
Article 11 & 12Technical Documentation & LoggingClause 7.5 with Annex A.6.2.7 (technical documentation) and A.6.2.8 (event logs)
Article 13Transparency to Deployers/UsersAnnex A.8 (Information for interested parties)
Article 14Human Oversight MechanismsAnnex A.9 (Use of AI systems / responsible use and oversight)
Article 15Accuracy, Robustness & CybersecurityAnnex A.6 life-cycle controls (verification/validation, operation, and monitoring)

Practical Implementation Scenario

Scenario: EuroLoan AG, a Munich-based fintech firm, develops an AI credit scoring algorithm used by European banks. Under Annex III, the application is classified as a High-Risk AI system. EuroLoan’s Chief Legal Officer warns that failing to comply could result in €15M fines, but the software team lacks a compliance structure.

Lead Implementer Guidance: The Lead Implementer leverages ISO/IEC 42001 to build EuroLoan’s EU AI Act compliance system. The Implementer establishes an AI Risk Assessment process under Clause 6.1 (satisfying Article 9), implements data quality and provenance controls under Annex A.7 (satisfying Article 10), and configures technical documentation plus event logging under Annex A.6.2.7–A.6.2.8 (satisfying Articles 11–12). By completing an ISO/IEC 42001 certification audit, EuroLoan establishes a formal presumption of conformity, satisfying European regulators and securing its market position.

Loading diagram...
EU AI Act Compliance & ISO/IEC 42001 Presumption of Conformity
Test Your Knowledge

An enterprise deploys an AI system that analyzes employee keystrokes, webcam feeds, and vocal tones to infer emotional stress levels in a corporate office environment. How is this application classified under the EU AI Act (Regulation 2024/1689)?

A
B
C
D
Test Your Knowledge

Under the EU AI Act, what calculation threshold triggers the classification of a General-Purpose AI (GPAI) model as possessing 'systemic risk', subjecting it to mandatory adversarial red-teaming and incident reporting?

A
B
C
D
Test Your Knowledge

What is the maximum administrative fine specified under Article 99 of the EU AI Act for violations involving Prohibited AI Practices (Article 5)?

A
B
C
D