Platform AI governance Coverage Pricing Partners Sign in
Free readiness checkTalk to us
HomeAI laws › EU AI Act (Regulation 2024/1689)
AI governance law · European Union

๐Ÿ‡ช๐Ÿ‡บ EU AI Act (Regulation 2024/1689)

The EU AI Act, Regulation 2024/1689, is the world's first horizontal AI law. It sorts systems into prohibited, high-risk, limited-risk and minimal-risk tiers and layers a separate regime on general-purpose AI models. Article 50 transparency duties are live from 2 August 2026. The heavy high-risk obligations in Articles 9 to 18 apply once phased in, and the GDPR sits alongside for any personal data used to build or run AI.

Cited to primary sources
AI Act (Reg 2024/1689) + GDPR
Governing framework
European Commission AI Office + national market-surveillance authorities
Supervisory authority
7
Controls this market requires
12
Required or strongly expected
Good to know: the "EU Digital Omnibus" is understood to defer the high-risk AI obligations to 2 December 2027, but that deferral is provisional until it is published in the Official Journal. Article 50 transparency and the general-purpose AI rules in Articles 53 to 55 are already live, so plan for them now.
Status: provisional overview (v0.1), reviewed against primary sources dated 24 Aug 2026; not legal advice.

What European Union expects of you

All 12 AI-governance controls we track apply here, graded by how firmly the law requires each one.

Required mandated by binding law Expected near-mandatory / guidance-backed Prudent advisable Optional emerging n/a not applicable
AI RiskRequired

AI risk classification & impact assessment

Classifying each AI system by risk and running an impact assessment (AIA/FRIA; DPIA where personal data is used). AI Act risk tiers plus GDPR Article 35 DPIA for personal data.

Closes with: AI risk classification + impact assessment (AIA/FRIA)
AI DataRequired

Data governance for AI

Governing training/input data: quality, provenance, lawful basis for personal data, minimisation and bias. AI Act Article 10 data governance for high-risk systems.

Closes with: AI data-governance standard
AI TransparencyRequired

Transparency & disclosure

Telling people when they deal with AI or AI-generated content; labelling output; chatbot/deepfake disclosure. AI Act Article 50 - live from 2 August 2026: label AI interaction and AI-generated content.

Closes with: AI transparency + disclosure notices
AI OversightRequired

Human oversight & automated decisions

Meaningful human oversight, and governance of solely-automated decisions with legal or significant effect on individuals. AI Act Article 14 human oversight; GDPR Article 22 automated decisions.

Closes with: Human-oversight + automated-decision safeguards note
AI SecurityRequired

Security of AI systems

AI-specific security: access to models and training data, protection against prompt injection/model abuse, secrets. AI Act cybersecurity duties plus GDPR Article 32.

Closes with: AI security controls statement
AI IncidentRequired

AI incident response & serious-incident reporting

Detecting, handling and (where required) reporting AI failures and serious incidents to regulators. AI Act Article 73 serious-incident reporting; GDPR Articles 33-34 for data breaches.

Closes with: AI incident-response plan + reporting templates
AI AssuranceRequired

Record-keeping, logging & conformity

Keeping the logs, technical documentation and conformity evidence regulators expect. AI Act Articles 11 and 12 technical documentation and logging.

Closes with: AI logging + technical-documentation pack
AI GovernanceExpected

AI governance ownership & policy

A named owner (or committee) accountable for AI, and a written AI policy setting principles, scope and roles. AI literacy and accountability expectations under Article 4 and the GDPR.

Closes with: AI policy + governance charter
AI InventoryExpected

AI system inventory / register

A maintained register of every AI system and use-case: purpose, owner, data used, risk tier and vendor.

Closes with: AI system register
AI AssuranceExpected

Accuracy, robustness & drift monitoring

Ongoing checks that AI performs as intended and does not degrade, with metrics and a review cadence.

Closes with: Model monitoring + drift-review plan
AI Supply ChainExpected

Third-party / vendor AI & foundation models

Due diligence on AI vendors and general-purpose/foundation models, recorded in model cards and supplier assessments. Articles 53-55 general-purpose AI duties flow down through the supply chain (live).

Closes with: Vendor AI due-diligence + model cards
AI UseExpected

Acceptable use of AI by staff

An internal policy governing employees' use of generative AI: approved tools, data rules, output review. Article 4 AI-literacy duty makes a staff AI-use policy near-mandatory.

Closes with: Acceptable-use policy for generative AI

Get EU-ready before the high-risk clock runs out

Answer a few questions and PrivMatrix shows exactly where you stand against the AI Act by risk tier, then generates the policies, registers and disclosures that close each gap - written for the EU.

Other markets

See all AI laws →
๐Ÿ‡ฌ๐Ÿ‡ง UK๐Ÿ‡ฆ๐Ÿ‡ช UAE๐Ÿ‡ธ๐Ÿ‡ฆ Saudi Arabia๐Ÿ‡ฎ๐Ÿ‡ณ India๐Ÿ‡ถ๐Ÿ‡ฆ Qatar