EU AI Act: scope, high-risk systems, and evidence readiness
A practical guide to EU AI Act scope, high-risk systems, role-based obligations, and audit-ready evidence — written for CISOs, risk, compliance, and AI governance leaders.
Published 16 October 2025 · Last updated 3 September 2026 · Informational, not legal advice.
Who is in scope under the EU AI Act?
Any organisation that places on the market or puts into service AI systems or general-purpose AI (GPAI) models in the EU — or whose AI output is used in the EU — is in scope. This includes providers, deployers, importers, distributors, product manufacturers, and authorised representatives.
Extraterritoriality
Providers and deployers outside the EU fall in scope where the output is used in the Union.
Deployers
Any organisation established or located in the EU that uses AI under its authority.
Value chain roles
Importers (Art. 23), distributors (Art. 24), and responsibilities along the value chain (Art. 25).
GPAI
Providers of GPAI models have specific, earlier-starting obligations.
What counts as a “high-risk” AI system?
Two routes apply. AI that is a safety component of products under EU harmonisation laws (Annex I) requiring third-party assessment; and standalone uses listed in Annex III.
Safety components under Annex I
AI that is a safety component of products covered by EU harmonisation legislation — and where those products undergo third-party conformity assessment — is classified as high-risk.
Standalone uses listed in Annex III
- Biometrics (remote identification, categorisation, emotion recognition)
- Critical infrastructure (e.g., road traffic, energy and water supply)
- Education and vocational training; employment and workers' management
- Access to essential public/private services (e.g., credit scoring, emergency dispatch)
- Law enforcement; migration, asylum and border control
- Administration of justice and democratic processes
What obligations apply, by role?
Provider, deployer, importer, distributor, and integrator roles each carry different obligations. The summary below focuses on high-risk systems for the two most common roles.
Build, document and certify
Establish a risk management system (Art. 9); implement data & data governance (Art. 10); prepare technical documentation (Art. 11 & Annex IV) and logging (Arts. 12, 19); ensure transparency/instructions (Art. 13) and human oversight design (Art. 14); meet accuracy/robustness/cybersecurity (Art. 15); maintain a QMS (Art. 17); complete conformity assessment and EU Declaration of Conformity/CE marking (Art. 43; Arts. 47–48); register where required (Arts. 49, 71); run post-market monitoring and serious-incident reporting (Arts. 72–73).
Evidence to keep
QMS manual, risk file, data sheets/lineage & bias tests, model & control test results, logs (≥6 months), EU DoC/CE, registration records, PMM plan & incident reports.
Operate, oversee and notify
Use the system per instructions and implement oversight by trained personnel (Art. 26); ensure input data is relevant/sufficiently representative if under your control (Art. 26); monitor operation and suspend/notify risks or serious incidents (Art. 26; Art. 73); retain logs (≥6 months) where under your control (Art. 26(6)); conduct FRIA where required (Art. 27); inform workers if used in the workplace (Art. 26(11)); register use when a public-sector deployer (Art. 49(3)).
Evidence to keep
Oversight assignments & training, input-data records, FRIA/DPIA, logs, notifications to provider/authorities, user communications, registration proof.
What evidence should we prepare for audits?
Prepare a concise, Article-mapped “audit kit” that proves your system and operations meet the Act’s lifecycle requirements. Prioritise artefacts that show controls work in practice, not just on paper.
Risk management file
Article 9
Hazard/threat analysis, mitigation decisions, and traceability.
Data & data governance dossier
Article 10
Lineage, representativeness, quality controls, and bias testing.
Technical documentation
Articles 11 & Annex IV
System description, intended purpose, testing, interfaces.
Logging & retention plan
Articles 12, 19, 26(6)
Automatic event logs with ≥6-month retention.
Human oversight design & training
Articles 14, 26(2)
Intervention procedures, training records, over-reliance mitigation.
Conformity evidence
Articles 17, 43, 47–49, 71
QMS, test reports, conformity assessment, EU DoC, CE marking, registration.
Post-market monitoring & serious-incident procedures
Articles 72–73
Roles, thresholds, reporting templates, incident logs.
What is a practical timeline to act?
Use a 90-day sprint to stand up governance and evidence — even if your formal deadlines are further out.
Discovery & mapping
Inventory AI systems/models; classify against Annex III/Art. 6; map roles (provider/deployer) and value-chain parties; appoint owners; start FRIA/DPIA scoping.
Controls & documentation
Draft Art. 9–15 controls (risk mgmt, data governance, oversight, accuracy/robustness/cybersecurity); define logging/retention; assemble Annex IV tech docs; outline PMM & incident playbooks.
Testing & conformity
Run tabletop tests; finalise QMS and Art. 43 path; prepare EU DoC/CE where applicable; define Art. 49/71 registration triggers; complete FRIA (if required) and worker notices.
Timing context: entry into force 1 August 2024; prohibited practices and AI literacy duties 2 February 2025; GPAI model obligations 2 August 2025; general application and Article 50 transparency duties 2 August 2026. Following the Digital Omnibus on AI (in force 27 July 2026), high-risk Annex III systems — the standalone uses most enterprises will hit, including hiring, credit scoring, education, and critical infrastructure — now apply from 2 December 2027, deferred from 2 August 2026. High-risk Annex I systems embedded in regulated products (medical devices, machinery, toys) now apply from 2 August 2028, deferred from 2 August 2027. Two further Article 5 prohibited-practice categories added by the Omnibus phase in 2 December 2026. Plan your roadmap accordingly.
How do third-party vendors fit?
You remain accountable for compliant use — contracts don’t transfer obligations. Flow down requirements and secure the technical access needed to evidence compliance.
Map vendor systems to roles
Map vendor systems to roles (provider vs. your deployer role) and risk class; require an evidence pack aligned to Arts. 9–15.
Secure contractual access
Use contractual value-chain terms to secure information/technical access and change-control; know when you “become the provider” (rebranding, substantial modification, purpose change).
Monitor post-deployment
Monitor vendor systems post-deployment; define serious-incident reporting and suspension triggers.
Frequently asked questions
Common questions about EU AI Act scope, obligations, and compliance.
See how STREAM® Cloud supports AI governance operationally
Connect AI systems, classification rationale, obligations, evidence, reviews and assurance reporting in one configurable workspace.
Related resources
Further reading on AI risk, governance, and management systems.
AI Act compliance for finance & healthcare
Sector-specific guidance for high-risk AI applications in regulated industries.
Read moreAI Risk Management guide
Comprehensive framework for identifying and managing AI-related risks.
Read moreISO 42001 AI Management
Implement the international standard for AI management systems.
Read moreReady to streamline your EU AI Act readiness?
Walk through how STREAM® Cloud could help your team connect AI systems, classifications, obligations, evidence, and assurance in one configurable workspace.
Sources
- Regulation (EU) 2024/1689 (Official Journal): eur-lex.europa.eu/eli/reg/2024/1689/oj
- Article 6 & Annex III (high-risk classification & use cases) — EUR-Lex/Official Journal.
- Digital Omnibus on AI (amending Regulation (EU) 2024/1689; in force 27 July 2026) — deferred high-risk timeline: ai-act-service-desk.ec.europa.eu/en/ai-act/timeline
- NIST AI RMF 1.0: nist.gov/itl/ai-risk-management-framework
- ISO/IEC 42001 (AI management systems): iso.org/standard/81205.html
Page changelog & disclaimer
Disclaimer: this page is informational and not legal advice.
3 September 2026: Corrected the Timing context box, which had fallen behind the Digital Omnibus on AI (in force 27 July 2026). High-risk Annex III obligations now run from 2 December 2027 (previously stated as 2 August 2026) and Annex I obligations from 2 August 2028 (previously stated as 2 August 2027); Article 50 transparency and GPAI obligations were unaffected and remain on their original dates. The text was accurate when it was last touched — this reflects a regulatory change since then, not an error introduced at any point.
19 May 2026: Refined page chrome and ported onto the modern visual system used across the site.
28 October 2025: Enhanced AEO optimisation — added BreadcrumbList, HowTo, and ItemList schemas; expanded FAQ to 8 questions including compliance penalties and STREAM® capabilities; added anchor links; converted to reusable FAQ component.
16 October 2025: Initial publication covering EU AI Act scope, high-risk systems, role-based obligations, evidence requirements, 90-day timeline, and vendor risk management.