Regulation

The EU AI Act, explained.

The world's first horizontal AI law, structured by risk rather than by sector. Here is what Regulation (EU) 2024/1689 actually requires, what already binds, and how AIssure maps your AI use-cases to the obligations that attach — traced to the text.

Jurisdiction
European Union
Regulator
European Commission / national competent authorities
Applies to
Providers & deployers of AI
Penalty
Up to €35M or 7% of global annual turnover

What the EU AI Act is

The EU AI Act — formally Regulation (EU) 2024/1689 — is the European Union's horizontal law for artificial intelligence. Rather than regulate by sector, it regulates by risk: the same technology carries different obligations depending on how it is used. It binds both providers (those who develop or place an AI system on the market) and deployers (those who use one), which is why a bank can find itself in scope as a user even where it did not build the model.

The Act sorts AI systems into four tiers:

  • Prohibited — practices the Act bans outright, such as certain forms of social scoring and manipulative AI.
  • High-risk — systems permitted but subject to the heaviest obligations: risk management, data governance, documentation, human oversight and conformity assessment. Several financial-services use-cases sit here.
  • Limited-risk — systems carrying transparency duties, for example telling a person they are interacting with an AI.
  • Minimal-risk — the majority of AI, left essentially unrestricted by the Act.

You can read the consolidated text on EUR-Lex.

What is already in force

The Act does not switch on all at once. Two sets of obligations already bind:

  • The bans on prohibited AI practices have applied since February 2025.
  • The obligations on general-purpose AI (GPAI) models have applied since August 2025.

Breaches carry the Act's headline enforcement ceiling: fines of up to €35 million or 7% of global annual turnover, whichever is higher, for the most serious infringements.

The part still in motion

The high-risk obligations — which capture a number of financial-services use-cases, creditworthiness assessment among them — are the subject of active political discussion. Proposals under consideration would defer their application to around December 2027. This is a provisional position, not settled law: it has not yet been adopted, and the timeline may change. We state it that way deliberately, because a governance assessment that overstated a deadline would undermine the very defensibility it exists to provide.

How AIssure maps to it

The Act's difficulty is not reading it — it is knowing which tier each of your AI systems falls into, and therefore which obligations attach. That is the mapping AIssure performs. For every AI use-case in scope, the assessment:

  • Places the use-case against its risk tier — prohibited, high-risk, limited or minimal — on the evidence of how it is actually used.
  • Identifies the obligations that attach at that tier: risk management, data governance, technical documentation, human oversight, transparency, and where relevant conformity assessment.
  • Traces each finding to the primary text of Regulation (EU) 2024/1689, so the result reads as "the regulation says", not "the AI says".

That grounding runs on a regulatory knowledge graph of 14,000+ provisions across eight jurisdictions, and a fabricated citation is stripped before it ever reaches the report. The output is a point-in-time, independent assessment over your governance — certification-ready, never "certified" — and it consumes your monitoring evidence rather than replacing the runtime controls that produce it.

FAQ

The EU AI Act — the questions we get.

What risk, compliance and data teams ask about the Act and how AIssure maps to it.

Is the EU AI Act in force yet?

Partly. The EU AI Act is Regulation (EU) 2024/1689 and it applies in phases. The bans on prohibited AI practices have applied since February 2025, and the obligations on general-purpose AI (GPAI) models have applied since August 2025. Other obligations, including those on high-risk systems, phase in later — so the correct answer for any given AI system depends on which tier it falls into.

When do the high-risk obligations apply?

This is the part in motion. As of mid-2026 the timing of the high-risk obligations is the subject of active political discussion, and proposals under consideration would defer their application to around December 2027. Treat that date as provisional: it is not yet adopted in law and the position may still change. AIssure states it as a provisional, not-yet-settled position rather than a fixed deadline.

Are our financial-services AI systems high-risk?

Some may be. The Act captures a number of financial-services use-cases in its high-risk tier — creditworthiness assessment and credit scoring being the most-cited example. Whether a given system is high-risk, limited-risk or minimal-risk turns on how it is used, which is exactly the mapping an assessment does: each AI use-case is placed against its tier, and the obligations that attach are traced to the text of the Regulation.

Does an AIssure assessment make us compliant with the EU AI Act?

It gives you a cited, point-in-time picture of where you stand. AIssure maps each AI use-case to its risk tier and the obligations that attach, with every finding traced to the primary text of Regulation (EU) 2024/1689 — the difference between 'the AI says' and 'the regulation says'. It is an independent assessment over your governance, not legal advice and not a runtime control; compliance itself remains the firm's responsibility.

Next step

Start with a thirty-minute read on your readiness.

A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.