The EU AI Act, Regulation 2024/1689, is the world's first horizontal AI law. It sorts systems into prohibited, high-risk, limited-risk and minimal-risk tiers and layers a separate regime on general-purpose AI models. Article 50 transparency duties are live from 2 August 2026. The heavy high-risk obligations in Articles 9 to 18 apply once phased in, and the GDPR sits alongside for any personal data used to build or run AI.
All 12 AI-governance controls we track apply here, graded by how firmly the law requires each one.
Classifying each AI system by risk and running an impact assessment (AIA/FRIA; DPIA where personal data is used). AI Act risk tiers plus GDPR Article 35 DPIA for personal data.
Governing training/input data: quality, provenance, lawful basis for personal data, minimisation and bias. AI Act Article 10 data governance for high-risk systems.
Telling people when they deal with AI or AI-generated content; labelling output; chatbot/deepfake disclosure. AI Act Article 50 - live from 2 August 2026: label AI interaction and AI-generated content.
Meaningful human oversight, and governance of solely-automated decisions with legal or significant effect on individuals. AI Act Article 14 human oversight; GDPR Article 22 automated decisions.
AI-specific security: access to models and training data, protection against prompt injection/model abuse, secrets. AI Act cybersecurity duties plus GDPR Article 32.
Detecting, handling and (where required) reporting AI failures and serious incidents to regulators. AI Act Article 73 serious-incident reporting; GDPR Articles 33-34 for data breaches.
Keeping the logs, technical documentation and conformity evidence regulators expect. AI Act Articles 11 and 12 technical documentation and logging.
A named owner (or committee) accountable for AI, and a written AI policy setting principles, scope and roles. AI literacy and accountability expectations under Article 4 and the GDPR.
A maintained register of every AI system and use-case: purpose, owner, data used, risk tier and vendor.
Ongoing checks that AI performs as intended and does not degrade, with metrics and a review cadence.
Due diligence on AI vendors and general-purpose/foundation models, recorded in model cards and supplier assessments. Articles 53-55 general-purpose AI duties flow down through the supply chain (live).
An internal policy governing employees' use of generative AI: approved tools, data rules, output review. Article 4 AI-literacy duty makes a staff AI-use policy near-mandatory.
Answer a few questions and PrivMatrix shows exactly where you stand against the AI Act by risk tier, then generates the policies, registers and disclosures that close each gap - written for the EU.