Framework guide

The EU AI Act in Practice

Regulation (EU) 2024/1689, the EU's harmonized rules on artificial intelligence. Classifies AI systems as prohibited, high-risk, limited-risk, or minimal-risk and imposes obligations proportionate to the tier.

Instrument
Regulation (EU) 2024/1689
Kind
Binding EU regulation, phased enforcement
Full applicability
August 2027
In the check
Not cited directly by a question
PROHIBITED HIGH-RISK LIMITED-RISK MINIMAL-RISK
Figure 1. The four EU AI Act risk tiers. Obligations are heaviest at the top and thin out toward minimal risk.
Risk tiers

The four risk tiers

Obligations scale with the tier. The high-risk list is where the work is.

TierWhat falls in it
ProhibitedSocial scoring, real-time biometric identification in public spaces (with narrow exceptions), exploitative practices targeting vulnerable groups.
High-riskAI systems used in critical infrastructure, education, employment, essential services, law enforcement, migration, justice, democratic processes. Includes specific AI products (medical devices, autonomous vehicles).
Limited-riskChatbots, deepfakes, emotion-recognition systems. Transparency obligations apply.
Minimal-riskMost AI applications. No specific obligations beyond existing law.
Obligations

High-risk obligations

What a provider or deployer of a high-risk system has to show.

Risk-management system

Data governance

Technical documentation

Record-keeping

Transparency to deployers and users

Human oversight

Accuracy, robustness, and cybersecurity

Conformity assessment

Registration in EU database

Post-market monitoring

Timeline

Enforcement timeline

The Act applies in phases. The dates below are when each set of obligations becomes enforceable.

Applies fromObligations
February 2025Prohibited practices
August 2025General-purpose AI obligations
August 2026Most high-risk obligations
August 2027Full applicability
Posture Check

Where the check cites it

The AI Posture Check gives a first read on EU AI Act exposure. Article-level gap mapping is part of the paid Standard Audit.

The questions cite the control frameworks a regulator would expect you to hold: NIST AI RMF, ISO 42001 and the OWASP LLM Top 10. Your stage on the check is a starting point for an EU AI Act conformity review, not a substitute for one.

Ready when you are

Score yourself against this framework.

Five questions, each citing its source. You get your stage, your place on the chart and the one move that matters next.

  • A few minutes for most people
  • Free, from CWS
  • Your stage, the chart and the next move, by email or live with an engineer