Published on 12 July 2024, Regulation 2024/1689 — the Artificial Intelligence Act — is the European Union's strategy for setting global standards through its "normative rule-making advantage" rather than competing head-on with the United States and China in technological production.
While AI systems make human life vastly easier, they also carry structures that generate risk — which has made legal regulation and controlled use in this field a necessity. The socio-technical nature of artificial intelligence requires potential risks to be brought under control not only from a technical standpoint, but also through universal rules and ethical considerations.
With this regulation, the EU has made the "trustworthy AI" paradigm — centred on human-centric, safe and transparent systems rather than technical efficiency alone — a legal obligation, and has adopted a risk-based approach.
The Criticality Pyramid: As Risk Rises, So Do Obligations
This approach classifies AI systems according to the severity of potential harm to societal and individual rights. In this model, described as the "criticality pyramid", the greater the risk of the system, the heavier the pre-market and post-market obligations become.
| Risk Category | Example Application | Core Legal Obligation |
|---|---|---|
| Unacceptable Risk | Social scoring, subliminal manipulation, real-time biometric identification. | Outright prohibition: placing on the EU market and use are banned (Article 5). |
| High Risk | Education, employment, critical infrastructure management, law enforcement applications. | Strict compliance: pre-market conformity assessment and mandatory CE marking (Article 6). |
| Limited Risk | Chatbots, deepfake content. | Transparency: obligation to disclose that the user is interacting with an AI system (Article 50). |
| Minimal Risk | Spam filters, AI-assisted games, simple automation. | Minimal oversight: compliance with existing consumer law and voluntary codes of ethics. |
The process defined for high-risk systems is critical: a finding that obligations and responsibilities have not been fully discharged is an obstacle to entering the market. Systems in this category cannot obtain CE marking without completing technical documentation, establishing a risk management system and undergoing third-party assessment. This compels AI actors to operate within a legal compliance and governance system throughout the entire lifecycle.
Obligations of Importing Companies
1. Pre-Market Responsibilities
- Carrying out the conformity assessment procedure
- Preparing the technical documentation
- Ensuring the CE marking is present on the system
- Preparing the EU declaration of conformity and having it accompany the product
- Ensuring instructions for use accompany the product
- Appointing an authorised representative
2. Post-Market Responsibilities
- Notifying the competent authorities in the event of non-conformity or risk
- Displaying the importer's identity and contact details on the product
- Ensuring storage and transport conditions comply with the regulation
- Retaining implementation records for ten years
- Providing the competent authorities with the necessary information and documents
- Cooperating with the competent authorities
Achieving technical conformity alone is not enough for companies to discharge the full set of pre-market and post-market obligations; these obligations also require the establishment of a holistic AI governance and compliance mechanism operating across the entire lifecycle.
A Three-Pillar Roadmap
1. AI Inventory Analysis and Risk Mapping
Producing the company's AI inventory is the first step to take. The answers to which AI systems exist, for what purpose they are used, who they affect, what data they run on, and whether they make decisions or merely provide support, determine the system's position on the risk pyramid. Analysing the legal, technical and operational risks of these systems is critically important, and structuring this phase in alignment with international risk management frameworks (ISO 23894, NIST AI RMF) is essential.
2. A Compliance Architecture Integrated with EU Technical Standards
Software development and product lifecycle processes must be aligned with the technical standards to be published by CEN and CENELEC.
3. A Corporate AI Governance Model
Compliance is not a control activity carried out at the end of a project; it is a governance model embedded into systems from the earliest design stage. In this context, establishing an AI management system aligned with ISO 42001 is important for institutionalising risk management, human oversight, transparency and accountability mechanisms.
Taken together, these three pillars make clear that AI Act compliance is not merely a technical requirement but a corporate transformation process in its own right.
For companies, building an auditable and sustainable AI governance model aligned with international standards is no longer a choice — it is a prerequisite for remaining competitive.