EU AI Act

Get ready for the EU AI Act without building an AI governance team first.

The EU AI Act sets legal obligations for anyone who builds, sells, or uses AI in the EU, scaled to the risk each system carries. A dedicated SecureSlate compliance lead inventories your AI systems, works out your role and risk tier for each, and builds the documentation and controls the Act expects, while our compliance automation platform reuses the evidence your ISO 42001 or security program already produces. One fixed price covers the work.

EU AI Act37 obligations

EU AI Act: 37 obligations, 1 AI literacy, 8 Prohibited practices, 7 High-risk requirements, 10 High-risk provider duties, 2 Deployer duties, 4 Transparency, 5 General-purpose AI. 6 highlighted: Head start from an ISO 42001 program.

Head start from an ISO 42001 programAI Act-specific, built with your compliance lead
Regulation
(EU) 2024/1689, in force since August 2024
Applies
In phases, starting February 2025
Risk tiers
Prohibited, high-risk, transparency, minimal
The standard

EU AI Act compliance depends on your role and each system's risk, not a single certificate.

Regulation (EU) 2024/1689 applies directly in every Member State. Its obligations fall on providers, deployers, importers, and distributors, and they scale with the risk an AI system poses.

Four risk tiers

Some practices are banned outright, such as social scoring and untargeted scraping of facial images. High-risk systems, including AI used in recruitment, credit scoring, and critical infrastructure, carry the heaviest requirements. Chatbots and generated content carry transparency duties, and minimal-risk AI has no specific obligations beyond AI literacy.

Provider and deployer duties

Providers of high-risk AI run risk management, data governance, technical documentation, logging, human oversight, and a quality management system, then complete conformity assessment before the system reaches the market. Deployers use systems as instructed, assign human oversight, keep logs, and in some cases assess the impact on fundamental rights.

Obligations that phase in

Prohibited practices and AI literacy applied from February 2025, and general-purpose AI model obligations from August 2025. Under the original timeline, most remaining obligations apply from August 2026, and high-risk AI in regulated products follows in August 2027. EU proposals to move some high-risk dates mean your plan should follow the dates in force.
How it works

We build your EU AI Act program with you, then keep it current as your AI changes.

Four stages from the scoping call to a program you can evidence, with a named compliance lead accountable at every one.

Inventory and classify your AI

We list the AI systems you build, sell, embed, or use, including the third-party models behind your features, then work out your role for each and whether it is prohibited, high-risk, subject to transparency duties, or minimal risk.

Map obligations and run the gap assessment

Your compliance lead maps the obligations that follow from each role and risk tier, reuses ISO 42001 or security controls where you have them, and ranks the gaps by deadline and risk.

Build the documentation and controls

Risk management, data governance, technical documentation, logging, human oversight, transparency notices, and AI literacy training are put in place, with questions of legal interpretation routed to your counsel.

Monitor and stay ready

Post-market monitoring, incident handling, and reviews run on a schedule, and every new model or use case is classified before it ships, so the program keeps pace with your roadmap.
What is included

Everything the EU AI Act asks you to document, prepared before anyone asks.

EU AI Act compliance software and the expert who runs it arrive together under one fixed price, so AI governance does not become a side project for your engineers.

A dedicated compliance lead

One experienced practitioner owns your EU AI Act program end to end. They classify systems, draft documentation, facilitate risk and impact assessments, and coordinate with your legal counsel, so your team reviews and approves instead of learning the regulation.

An AI inventory with risk classification

Every AI system recorded with its owner, purpose, your role, and its risk tier, with the obligations that follow mapped to controls and evidence, and reviewed whenever a model or use case changes.

AI risk and impact assessments

Risk scenarios for each AI system scored against criteria you agree, with owners and treatment decisions recorded, plus fundamental rights impact assessments where your role and use case require one.

AI vendors and model providers

Model APIs and the AI features inside tools you buy are inventoried and reviewed, with the information providers owe you as a deployer requested and kept on file.

AI literacy training

Training assigned to the people who build, operate, and use AI systems, with completion tracked, so you can show the AI literacy that Article 4 expects for each role.

A Trust Center for AI questions

Publish an AI policy summary, the models you rely on, and your subprocessors on a live page, so buyers find answers to their AI Act questions before they send a questionnaire.
Reuse from ISO 42001

Six EU AI Act obligations build directly on an ISO 42001 program.

ISO 42001 does not prove conformity with the Act, but it gives several obligations a running start. If you hold it or are working toward it, your compliance lead extends these controls to the Act instead of rebuilding them.
Art. 4 builds on ISO 42001 7.2 and 7.3

AI literacy

The competence and awareness records your AIMS keeps become the evidence that people who operate and use AI systems have the AI literacy their role needs.
Art. 9 builds on ISO 42001 6.1

Risk management system

Your AI risk assessment, treatment, and impact assessment process extends to the Act's life cycle risk management for each high-risk system, including testing against the risks you identified.
Art. 10 builds on ISO 42001 A.7

Data and data governance

Controls for data acquisition, quality, provenance, and preparation are the starting point for the Act's rules on training, validation, and testing data, including examination for possible biases.
Art. 12 builds on ISO 42001 A.6.2.8

Record-keeping

The event logging you define for AI systems becomes the automatic recording of events over the system's lifetime that high-risk AI has to support.
Art. 17 builds on ISO 42001 clauses 4 to 10

Quality management system

Policies, roles, documented procedures, internal audit, and corrective action from your AIMS cover much of the quality management system that providers of high-risk AI must run.
Art. 72 builds on ISO 42001 A.6.2.6

Post-market monitoring

Monitoring of AI system operation, performance, and failures becomes the documented post-market monitoring plan that collects and analyzes data throughout the system's lifetime.
Beyond EU AI Act

One AI governance program for the EU AI Act and the frameworks around it.

The Act overlaps with the standards and regulations your buyers already ask about, so shared controls count more than once.

ISO 42001

The certifiable AI management system standard. It builds much of the governance, risk management, and documentation the Act expects, though certification alone does not show conformity.

GDPR

AI systems that process personal data still need a lawful basis, transparency, and data protection impact assessments. Your DPIA work feeds the Act's fundamental rights impact assessment.

NIST AI RMF

The US voluntary framework for AI risk. Its govern, map, measure, and manage functions line up with much of the Act's risk management work.

ISO 27001

Article 15 expects high-risk AI to resist attacks such as data poisoning and adversarial inputs. An ISMS covers the security foundations around the model.

SOC 2

US buyers still ask for a SOC 2 report. Access, change, and vendor controls serve both, so AI features do not need a separate security program.

NIS 2

AI used by essential and important entities sits inside their NIS 2 obligations too, so incident handling and supplier security should cover AI systems.
EU AI Act guides

What the EU AI Act actually asks of your team

Three deep dives your team can read before the scoping call, from the overlap with ISO 42001 to the policy that holds the program together.

ISO 42001
How ISO 42001 helps with EU AI Act compliance: similarities, gaps, and a roadmap
High-risk
The EU AI Act checklist: classification, documentation, and next steps
Policy
AI governance policy: template, requirements, and the audit evidence behind it
Resources

Read up before your scoping call.

Practical guides to AI governance, from the Act's risk categories to the policies and standards that support it.

FAQs

What teams ask before starting EU AI Act compliance.

Find out what the EU AI Act means for your AI

Bring the AI systems you build and use. You will leave the call with a first view of their risk tiers, a gap summary, and a fixed price, whether or not you work with us.

Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?