Frameworks — EU AI Act
Build trust in your AI systems with EU AI Act compliance.
The EU AI Act (Regulation 2024/1689) is the world's first comprehensive horizontal law governing artificial intelligence, classifying AI systems by risk level and setting binding obligations for providers and deployers. If your company builds or deploys AI systems used in or affecting the EU — the AI Act applies regardless of where your company is headquartered, and non-compliance carries real regulatory and commercial risk.
Subscribe to our newsletter and never skip a step in your EU AI Act journey.
In the Spotlight
Start your EU AI Act journey with DSALTA's complete checklist.
The EU AI Act entered into force on August 1, 2024, and applies progressively through a phased timeline: prohibited practices and AI literacy obligations since February 2, 2025, general-purpose AI (GPAI) model obligations since August 2, 2025, and the bulk of high-risk AI system obligations under Annex III originally set for August 2, 2026. A Digital Omnibus package is under negotiation that would defer Annex III obligations to December 2, 2027, but it has not been formally adopted — treat August 2026 as the operative deadline until it is.
The AI Act can feel dense, spanning four risk tiers and dozens of provider and deployer obligations depending on your system's classification, but DSALTA® makes it manageable. With automated evidence collection, continuous obligation monitoring, and AI-driven gap analysis, you can reach compliance — and stay compliant as deadlines shift — without drowning in manual work. Use this checklist to guide your EU AI Act journey.
Why EU AI Act compliance matters?
Complying with the EU AI Act is more than a checkbox exercise. It shows EU regulators, enterprise buyers, and procurement teams that your AI systems have been classified, documented, and governed to a binding legal standard — not just described in a policy document. Non-compliance can result in:
Fines of up to €35 million or 7% of global annual turnover for prohibited-practice violations, whichever is higher
Loss of enterprise vendor contracts over unmet transparency or high-risk obligations
Legal and reputational exposure from unaddressed compliance gaps
Deals stalled or lost in vendor security and regulatory review
Easily accessible AI compliance for growing teams.
Many companies delay AI Act readiness because the risk-tiered structure and shifting deadlines feel hard to track. But it doesn't have to be overwhelming. With tools like DSALTA, the EU AI Act becomes easier to manage — especially for lean, fast-moving AI and SaaS teams. By using automation and a proactive approach, you can:
Save time tracking which obligations apply to which systems
Make informed decisions using real-time compliance dashboards
Reduce manual evidence-gathering and focus on shipping product
Key steps to EU AI Act compliance
Here's how to get EU AI Act ready while keeping your product shipping fast.
Classify your AI systems by risk tier
The AI Act applies different obligations depending on risk classification, not a single standard for every system. This includes:
Screening for unacceptable-risk (prohibited) practices, such as social scoring or manipulative AI
Determining whether any system falls under Annex III high-risk use cases (e.g., employment, credit, law enforcement)
Identifying limited-risk systems subject to transparency obligations and minimal-risk systems with no binding obligations
Confirm your role and run a gap assessment
Obligations differ depending on whether you're a provider, deployer, importer, or distributor of an AI system. This includes:
Mapping each in-scope system to its applicable provider or deployer obligations
Identifying and prioritizing gaps by risk level and deadline proximity
Confirming GPAI model obligations if you build or fine-tune foundation models
Build the required technical and governance documentation
High-risk and GPAI obligations require substantial documentation, not just internal policy. This includes:
Maintaining technical documentation, risk management systems, and logging for high-risk AI systems
Meeting transparency obligations, including AI-generated content labeling and watermarking
Establishing human oversight mechanisms for high-risk systems
Complete conformity assessment where required
Certain high-risk AI systems require third-party conformity assessment before market placement. This includes:
Engaging a notified body for conformity assessment where self-assessment isn't sufficient
Registering high-risk AI systems in the EU database where required
Remediating any findings before placing the system on the market
Align with adjacent frameworks and standards
The EU AI Act is designed to work alongside AI governance standards you may already hold. This includes:
Mapping AI Act obligations to ISO 42001 and NIST AI RMF controls you're already tracking
Using harmonised standards, once available, to demonstrate presumption of conformity
Using AI Act readiness to answer customer AI security and regulatory questionnaires faster
Maintain compliance over time
EU AI Act compliance isn't one-and-done — it requires ongoing monitoring as obligations phase in and systems change. This includes:
Tracking upcoming deadlines, including any changes from the pending Digital Omnibus
Re-assessing risk classification whenever a system changes materially
Keeping evidence current so regulatory inquiries don't turn into a fresh project
Get it faster with DSALTA.



