HomeResourcesEU AI Act
Regulation (EU) 2024/1689

EU AI Act Compliance: What Your Organisation Actually Needs to Do

The EU AI Act is the world's first binding horizontal AI law. It applies to any organisation placing AI systems on the EU market — including Australian enterprises with EU customers, partners, or supply chains. Compliance deadlines are live.

EU AI Act risk classification

Four tiers. Your obligations depend on which tier your AI system sits in.

The EU AI Act uses a risk-based approach. Obligations scale with the risk tier of each AI system. Classification happens at intake — before development decisions are made.

Unacceptable risk

Prohibited outright. AI systems that manipulate human behaviour, exploit vulnerabilities, enable real-time biometric surveillance in public spaces, or operate social scoring systems are banned entirely.

  • Social scoring by public authorities
  • Subliminal manipulation
  • Real-time remote biometric ID in public spaces (with narrow exceptions)
High risk

Subject to mandatory obligations including risk management systems, technical documentation, human oversight, data governance, and in some cases conformity assessment before deployment.

  • Critical infrastructure (energy, water, transport)
  • Education and vocational training
  • Employment and HR decisions
  • Essential services (credit scoring, insurance)
  • Law enforcement
  • Migration and border control
Limited risk

Subject to transparency obligations only. Users must be informed they are interacting with an AI system — chatbots, deepfakes, and emotion recognition systems fall here.

  • Chatbots and conversational AI
  • AI-generated content and deepfakes
  • Emotion recognition systems
Minimal risk

No mandatory obligations. Voluntary codes of conduct encouraged. Applies to most AI applications currently in use — spam filters, AI-enabled video games, recommendation engines.

  • Spam filters
  • AI-enabled games
  • Inventory management AI
High-risk AI obligations

Eight mandatory requirements for high-risk AI systems

High-risk AI systems cannot be placed on the EU market until these obligations are met. Each requires documented evidence — not just policy statements.

01

Risk management system

Establish, implement, document, and maintain a risk management system covering the entire lifecycle of the high-risk AI system.

02

Data governance

Training, validation, and testing datasets must meet quality criteria: relevance, representativeness, absence of errors, completeness.

03

Technical documentation

Detailed technical documentation before placing the system on the market, demonstrating conformity with the Regulation.

04

Record-keeping

Automatic logging of events over the system's lifetime to support post-market monitoring and incident investigation.

05

Transparency and information

Instructions for use enabling deployers to interpret outputs and exercise human oversight.

06

Human oversight

Design and deployment measures enabling natural persons to monitor, understand, and override the AI system.

07

Accuracy, robustness, cybersecurity

Systems must achieve appropriate levels of accuracy, be resilient to errors and adversarial manipulation.

08

Conformity assessment

Before market placement — either internal or third-party assessment depending on the system category.

Penalties: Up to EUR 35 million or 7% of global annual turnover for prohibited AI practices. Up to EUR 15 million or 3% for other violations. Non-EU providers must appoint an EU-authorised representative before market entry.

Compliance timeline

Key EU AI Act deadlines

August 2024

EU AI Act enters into force

February 2025

Prohibited AI practices apply — unacceptable risk systems must cease

August 2025

Rules for general-purpose AI (GPAI) models apply, including capability thresholds

August 2026

High-risk AI system obligations fully applicable

August 2027

Product safety integration — high-risk AI systems covered by product legislation

For Australian enterprises

Does the EU AI Act apply to your Australian AI program?

The Act applies wherever AI systems are placed or used in the EU — not only where providers are incorporated. Australian enterprises with EU exposure need to assess their AI portfolio now.

EU market exposure

Any Australian enterprise selling products or services in the EU where AI is embedded — directly or via a vendor — must comply with the Act's deployer obligations. Third parties have embedded AI for over a decade; the Act holds deployers accountable regardless of origin.

GPAI model obligations

Australian enterprises using general-purpose AI models with systemic risk (capability thresholds defined in August 2025 rules) face specific transparency and risk management obligations.

Dual classification at intake

Wahid AI dual-screens every AI use case against both the Australian DTA Policy v2.0 and the EU AI Act risk classification at intake — so the right obligations are identified before development begins, not after deployment.

APRA and EU AI Act overlap

APRA CPS 230 requires critical operations to identify and manage AI-related operational risk. EU AI Act obligations for risk management, documentation, and human oversight directly reinforce CPS 230 compliance for APRA-regulated entities with EU exposure.

FAQ

EU AI Act — common questions

01

Does the EU AI Act apply to Australian companies?

Yes. The EU AI Act applies to any organisation that places AI systems on the EU market or deploys AI systems within the EU, regardless of where the organisation is headquartered. Australian businesses with EU customers, partners, or operations are subject to the Act.

02

What are high-risk AI systems under the EU AI Act?

High-risk AI systems include those used in critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice. These require risk management systems, technical documentation, human oversight, and in some cases third-party conformity assessment.

03

What are the EU AI Act penalties?

Penalties range up to EUR 35 million or 7% of global annual turnover for prohibited AI practices. EUR 15 million or 3% for other violations. EUR 7.5 million or 1.5% for incorrect information provided to authorities.

04

When does the EU AI Act come into force?

Prohibited AI practices applied from February 2025. GPAI model rules from August 2025. High-risk AI system obligations fully apply from August 2026.

05

How does the EU AI Act relate to ISO 42001?

ISO 42001 provides a strong governance foundation that overlaps significantly with EU AI Act requirements — particularly for risk management, documentation, human oversight, and third-party controls. It does not fully substitute for EU AI Act conformity assessment for high-risk systems.

Know where your AI systems sit under the EU AI Act — before August 2026.

Wahid AI dual-screens every AI use case against the EU AI Act risk tiers at intake. Obligations derive automatically. Evidence tracks to closed.