Classify · Control · Evidence

EU AI Act Compliance for Enterprises

The EU AI Act has changed what it means to use AI in Europe. If your organisation deploys AI anywhere in the EU — or serves EU customers — the Act applies, and the compliance bar has moved from promises to evidence.

You do not need to rebuild your AI estate to comply. You need to understand it, classify it, and prove you are controlling it. That is exactly what AI governance is for.

UnacceptableProhibited outright
High riskHiring · credit · education · infrastructure
Limited riskTransparency duties
Minimal riskMost everyday enterprise use

Obligations scale with the tier — classify honestly

What the Act requires

From written policy to demonstrable control.

The Act applies on the basis of where AI is used, not where your company is registered — including systems you bought rather than built. Its central shift is evidentiary: previous approaches accepted a policy document as proof of intent; the Act expects proof of control.

Risk management

A defined, ongoing process for identifying and mitigating risk across the AI lifecycle.

Data governance

Control over the data AI systems are trained on and given access to.

Human oversight

Named people able to understand, intervene in and override AI decisions.

Transparency

Clarity about where AI is in use and what it does.

Logging

Records that let you reconstruct what a system did, and why.

Risk classification

Most of your estate is minimal risk. The exceptions matter disproportionately.

The Act tiers AI by the risk it presents, and obligations scale with the tier. Most enterprise use falls into limited or minimal — which is why the classification exercise is really about finding the small number of systems that do not.

High-risk uses include hiring and employment decisions, credit and creditworthiness, education and assessment, and critical infrastructure. If any of your AI touches those areas, the heavier obligations apply to it.

Misclassification is itself a compliance failure — and it is the one a regulator finds first, because it is visible in your own documentation.

Self-assessment

Is my AI system high risk?

Answer yes to any of these and treat it as a candidate for high-risk classification, then confirm the decision formally.

  • Influences hiring, promotion, task allocation or termination
  • Affects access to credit, insurance or essential private services
  • Used in education or training to assess people or determine access
  • Operates in critical infrastructure or a safety component
  • Makes or materially shapes a decision about a person

The path

Five steps to EU AI Act compliance.

The sequence is the same regardless of size or sector. Most organisations stall at step four — policies exist, evidence does not.

01

Inventory

Every model, agent, application and tool that uses AI — including shadow AI — with owner, use case and environment.

02

Classify

Assign each system to a risk tier and record the reasoning, not just the answer.

03

Map to controls

Each obligation gets a control that satisfies it and a person who owns that control.

04

Build evidence

Decisions, approvals, exceptions, assessments and monitoring logs, produced as you operate.

05

Operate

Run the loop continuously so classifications stay accurate as models and usage change.

How Govreign helps

Evidence as a by-product, not a project.

Govreign maps your AI estate to the obligations that actually apply to it, and keeps that mapping current as systems change.

Rather than producing compliance documentation alongside your controls, it generates evidence from the controls themselves — so the audit trail is a by-product of running the estate properly.

  • Map AI systems to applicable law so each carries the obligations relevant to its risk tier and jurisdiction.
  • Manage risk classifications with recorded reasoning, review dates and an approval path for changes.
  • Maintain audit-ready evidence of decisions, approvals, exceptions and monitoring over time.
  • Operate continuously so classifications and controls stay accurate as the estate evolves.

Systems nobody registered are invisible to all of this — see shadow AI. For the GRC view of the same problem, see AI risk & compliance.

Questions

EU AI Act FAQ

Does the EU AI Act apply to my company?

It applies based on where AI is used rather than where your company is based. If you deploy AI within the EU, or your AI systems affect people in the EU, you are in scope — including AI inside third-party tools you have bought rather than built.

What is a high-risk AI system?

A system used in an area the Act designates as high risk — including hiring and employment decisions, credit and creditworthiness, education and assessment, and critical infrastructure. High-risk systems carry the heaviest obligations.

What are the penalties for non-compliance?

The Act sets tiered financial penalties, with the highest reserved for deploying prohibited AI practices. Because exact figures and enforcement practice change as the Act phases in, confirm current penalty levels with your legal counsel rather than relying on a summary.

When do I need to comply?

The Act phases in over time, with different obligations applying from different dates, so your deadline depends on what your systems do. The work that takes longest — an accurate inventory and an evidence trail — is the same regardless of date.

Do we need new AI systems to comply?

Usually not. Compliance is mostly about understanding, classifying and controlling the AI you already run, and being able to evidence it. The gap in most organisations is visibility and record-keeping, not the underlying technology.

What if we misclassify a system?

Misclassification is itself a compliance failure, and it is the one a regulator finds first because it is visible in your own documentation. Recording the reasoning behind each classification is what makes a judgement defensible later.

Get Started

Turn EU AI Act requirements into working controls.

Walk into your next audit with evidence rather than promises.