How American companies that develop or deploy artificial intelligence must respond to Europe’s landmark AI regulation — and what being classified as a high-risk system means in practice.
Regulation (EU) 2024/1689 | Updated April 2026
Contents
- Overview: What Is the EU AI Act?
- Does the EU AI Act Apply to Your US Business?
- What Is a High-Risk AI System?
- Understanding Your Role: Provider vs. Deployer
- Compliance Obligations for Providers
- Compliance Obligations for Deployers
- The Obligation to Appoint an EU Authorized Representative
- Conformity Assessment, CE Marking, and Registration
- Key Compliance Timelines
- Penalties for Non-Compliance
- Practical Steps US Businesses Should Take Now
1. Overview: What Is the EU AI Act?
The EU AI Act — formally Regulation (EU) 2024/1689 of the European Parliament and of the Council — is the world’s first comprehensive legal framework governing artificial intelligence. Published in the Official Journal of the European Union on 12 July 2024, it entered into force on 1 August 2024 and is being phased in progressively, with the bulk of its requirements applying from 2 August 2026. The regulation adopts a risk-based architecture: the more significant the potential harm that an AI system could cause to health, safety, or fundamental rights, the more demanding the obligations imposed on those who develop and deploy it.
The Act establishes four tiers of risk. At the top, certain AI practices are outright prohibited — including systems that use subliminal manipulation to distort behavior, that exploit the vulnerabilities of specific groups, that enable real-time remote biometric identification of individuals in publicly accessible spaces (save for narrowly defined law enforcement purposes), and that facilitate social scoring by public authorities. Below the prohibited tier sit high-risk AI systems, which are permitted but subject to an extensive pre-market compliance regime. Next come limited-risk systems — such as chatbots — which are subject mainly to transparency obligations. Finally, minimal-risk systems, such as spam filters, face no mandatory requirements under the Act at all.
For US businesses, the high-risk tier is where the most consequential work lies. The compliance obligations it imposes are detailed, technically demanding, and legally enforceable, with penalties calibrated at a level that matches — and in some respects exceeds — those under the GDPR. Understanding whether your AI system qualifies as high-risk, and what the Act requires if it does, is therefore the essential starting point for any transatlantic AI compliance program.
2. Does the EU AI Act Apply to Your US Business?
The EU AI Act has broad extraterritorial reach that will catch many American companies who have no physical presence in Europe. Article 2 of the Regulation sets out its material scope in terms that will be familiar to any lawyer who has worked on GDPR compliance, and the similarities are deliberate. The Act applies to providers who place AI systems on the market or put them into service in the European Union, regardless of whether those providers are established within the EU or in a third country. It also applies to providers and deployers of AI systems that are established in a third country where the output produced by those systems is used within the EU.
Key Extraterritorial Triggers for US Businesses
A US company will fall within the scope of the EU AI Act if it: (i) makes an AI system available to users in the EU market, even if only through a software-as-a-service or API delivery model; (ii) develops an AI system whose outputs — predictions, decisions, recommendations, or generated content — are consumed or acted upon within the EU; or (iii) deploys an AI system within the EU as part of its business operations, for example in human resources, credit assessment, or customer-facing services targeting European consumers.
The critical concept is that it is not physical market presence but market effect that triggers jurisdiction. A US company that develops an AI-powered recruitment screening tool licensed to European employers, or a US fintech that provides automated credit-scoring to EU-based lenders, or a US healthcare technology company whose diagnostic AI is used by EU hospitals — each is a provider placing a system on the EU market and is squarely subject to the Act. Similarly, a US multinational that deploys an AI system within its EU offices to manage employee performance is acting as a deployer subject to the deployer obligations discussed in Section 6 below.
Certain entities are explicitly excluded. The Act does not apply to AI systems developed or used exclusively for national security, military, or defence purposes, nor to AI systems used solely for scientific research and development. There is also a limited exclusion for open-source AI systems, though providers of general-purpose AI models built on open-source foundations may still be caught depending on the circumstances. US companies relying on any such exclusion should document their analysis carefully, since the burden of demonstrating that an exclusion applies will rest with the company if challenged by a national competent authority.
3. What Is a High-Risk AI System?
Article 6 of the AI Act establishes two routes by which an AI system is classified as high-risk. Both routes are important for US businesses to understand, and both carry identical compliance obligations once triggered.
Route 1: AI Systems Embedded in Regulated Products (Article 6(1) / Annex I)
The first route applies where an AI system is itself a product, or is a safety component of a product, that falls under one of the EU’s existing sectoral harmonisation frameworks listed in Annex I to the Act. These frameworks include the Medical Device Regulation, the In Vitro Diagnostic Medical Devices Regulation, the Machinery Regulation, the Radio Equipment Directive, the Toy Safety Directive, the Civil Aviation Safety Regulation, and the Motor Vehicles Regulation, among others. Where such a product is already required to undergo a third-party conformity assessment before it may be sold in the EU, the embedded AI system is automatically classified as high-risk. A US medical device manufacturer integrating an AI-based diagnostic algorithm into a regulated device, or a US automotive supplier incorporating machine learning into an advanced driver assistance system, will therefore fall into this category.
Route 2: Standalone High-Risk AI Systems (Article 6(2) / Annex III)
The second and broader route applies to standalone AI systems that fall within one of the eight high-risk categories listed in Annex III to the Act. These categories were chosen because they involve AI systems operating in domains where errors or misuse could cause serious harm to individuals’ safety, livelihoods, or fundamental rights.
Annex III — Category 1
Biometrics
Remote biometric identification systems; biometric categorisation systems; emotion recognition systems (except in narrow medical or safety contexts).
Annex III — Category 2
Critical Infrastructure
AI used as safety components in the management of critical digital infrastructure, road traffic, water, gas, heating, or electricity supply.
Annex III — Category 3
Education & Vocational Training
Determining access to or assignment in educational institutions; evaluating learning outcomes; proctoring during assessments.
Annex III — Category 4
Employment & Worker Management
AI used for recruitment and selection; performance monitoring; decisions about promotion, pay, termination, or task allocation.
Annex III — Category 5
Essential Services & Benefits
Creditworthiness assessment; life and health insurance risk scoring; emergency services dispatch; social security and public benefit eligibility.
Annex III — Category 6
Law Enforcement
Risk assessment of individuals in criminal contexts; evaluating reliability of evidence; predictive policing; profiling in criminal investigations.
Annex III — Category 7
Migration & Border Control
Assessing migration and asylum risk; examining and verifying authenticity of travel documents; detecting security threats at borders.
Annex III — Category 8
Justice & Democratic Processes
AI assisting in the application of law to facts in individual cases; systems designed to influence the outcome of elections or referenda.
It is important to note that Article 6(3) provides a limited carve-out within Annex III: a provider may assess that its system does not in fact pose a significant risk of harm to health, safety, or fundamental rights — for example because it does not make decisions that have a meaningful legal or similarly significant effect on individuals, or because it performs a narrow preparatory task. Where a provider intends to rely on this carve-out, it must conduct and document a formal assessment before the system is placed on the market and register that assessment in the EU’s public AI database. This is not a loophole to be used casually; competent authorities will scrutinise such self-assessments, and the legal consequences of incorrectly classifying a high-risk system as exempt are severe.
4. Understanding Your Role: Provider vs. Deployer
The obligations imposed by the EU AI Act differ significantly depending on whether a company is acting as a provider or a deployer, and it is essential that US businesses identify their role accurately at the outset.
A provider is any natural or legal person, including a company established outside the EU, that develops an AI system or has an AI system developed and then places it on the EU market or puts it into service in the EU under its own name or trademark. The provider is the primary regulatory actor under the Act and bears the heaviest compliance burden. Typically, a US company that builds and commercially licenses an AI product or service will be acting as a provider.
A deployer is any person or organisation that uses a high-risk AI system under its own authority for a professional purpose, other than for personal non-professional use. A US multinational using a third-party AI hiring tool within its European operations, or a European bank deploying a US-developed credit-scoring model, will typically be a deployer. Deployers carry meaningful obligations of their own, but these are less extensive than those of providers.
The Dual-Role Complication
Many US technology companies will occupy both roles simultaneously. A company that develops its own AI system and also deploys that system to serve end-users is both a provider and a deployer. Equally, a company that takes a foundation model or third-party AI component and substantially modifies it or integrates it into its own product for market release will typically be treated as a provider of the resulting system, even if it did not build the underlying model. US businesses that fine-tune, retrain, or significantly customise a third-party AI system should assume they are providers and seek legal advice if there is any doubt.
5. Compliance Obligations for Providers of High-Risk AI Systems
Chapter III, Section 2 of the EU AI Act sets out an integrated set of requirements that providers of high-risk AI systems must satisfy before placing their system on the EU market and must maintain throughout the system’s operational life. These requirements are cumulative — all of them apply simultaneously — and they are technically demanding. US companies should budget significant time and resources for compliance, and should begin their readiness programs well in advance of the applicable deadline.
1
Risk Management System (Article 9)
Providers must establish and maintain a documented risk management system that operates throughout the entire lifecycle of the AI system. The system must identify and analyse all reasonably foreseeable risks to health, safety, or fundamental rights; evaluate those risks in light of the intended use and foreseeable misuse of the system; adopt suitable risk mitigation measures; and test the adequacy of those measures. Risk management must be treated as an iterative process, updated in light of post-market data and operational feedback. The Act explicitly requires providers to take into account the potential impact on children and other vulnerable groups when conducting their risk analysis. Unlike a one-time assessment, this is an ongoing operational obligation that must be embedded into the provider’s quality management processes.
2
Data and Data Governance (Article 10)
Where a high-risk AI system involves the training of machine learning models, the provider must implement governance practices covering the training, validation, and testing datasets. Those datasets must be subject to appropriate data governance practices including assessment of their origin, scope, and characteristics; examination of possible biases; assessment of the availability, quantity, and suitability of the data; and examination of any possible shortcomings. Datasets used for training must be relevant, sufficiently representative, and, to the extent possible, free from errors and complete with regard to the intended purpose. Where the processing of special categories of personal data — such as health data, racial or ethnic origin, or biometric data — is strictly necessary for the purpose of bias detection and correction, the Act permits such processing subject to appropriate safeguards, though this must be read alongside the requirements of the GDPR, which continues to apply in parallel.
3
Technical Documentation (Article 11 and Annex IV)
Providers must draw up comprehensive technical documentation before placing a high-risk AI system on the market and keep it up to date throughout the system’s operational life. Annex IV specifies the contents of this documentation in considerable detail: it must include a general description of the system and its intended purpose; a description of the system’s components and development process, including the algorithms and training methodologies; information about the training, validation, and testing datasets; details of the monitoring, operation, and control measures; a description of the risk management system; a copy of the instructions for use; and — importantly — information about any known limitations of the system. This documentation must be made available to national market surveillance authorities on request. For US businesses, creating this documentation requires disciplined engineering record-keeping practices that many will not yet have in place.
4
Automatic Logging and Record-Keeping (Article 12)
High-risk AI systems must be designed and built to automatically generate logs — event records — of their operation to the extent that such logs are technically feasible. These logs must be capable of enabling monitoring of the system’s operation throughout its intended lifecycle, and in particular of facilitating the identification of situations that may present a risk or lead to a substantial modification of the system. Where the high-risk AI system is used by a public authority, or where a deployer is using the system to make or support decisions affecting natural persons, the logging capability takes on particular significance because deployers are required to retain those logs for specified periods. Providers must therefore design their systems’ logging architecture with downstream deployer obligations in mind, and ensure that the logs generated are meaningful, readable, and usable without proprietary tools that might not be available to regulators.
5
Transparency and Instructions for Use (Article 13)
High-risk AI systems must be designed and developed in such a way that their operation is sufficiently transparent to enable deployers to understand the system’s outputs and use them appropriately. Providers must supply deployers with instructions for use in a clear and accessible format. Those instructions must include the identity and contact details of the provider; the system’s intended purpose, performance levels, and limitations; any foreseeable circumstances that may give rise to risks; the technical capabilities and limitations relevant to human oversight; the expected lifetime of the system and any maintenance requirements; and a description of the input data that the system requires. US providers accustomed to sparse API documentation will need to significantly enhance the depth and precision of the documentation they supply to European deployers.
6
Human Oversight Measures (Article 14)
One of the most distinctive features of the EU AI Act is its emphasis on human oversight as a design requirement rather than merely a deployment best practice. Providers must design high-risk AI systems in a way that enables the natural persons assigned to exercise oversight to effectively understand the system’s capabilities and limitations, monitor its operation, detect and address anomalies, intervene to override or interrupt outputs, and — where appropriate — refrain from using the system’s output. Where technically feasible, the system must be capable of being operated by a human who can disregard, override, or reverse its outputs. The level and nature of human oversight measures must be proportionate to the risks of the system and calibrated to the context of its deployment. Designing for human oversight from the ground up, rather than as an afterthought, will require providers to reconsider interface design, decision workflow architecture, and the documentation they provide to deployers.
7
Accuracy, Robustness, and Cybersecurity (Article 15)
High-risk AI systems must achieve an appropriate level of accuracy, robustness, and cybersecurity throughout their lifecycle. The Act requires that providers define accuracy metrics in their technical documentation and demonstrate that the system performs consistently against those metrics across different conditions and inputs. Systems must be resilient against errors, faults, and inconsistencies, including those arising from the use of data or outputs from third-party components integrated into the system. Where a high-risk AI system makes continuous predictions or recommendations, it must be designed so that its accuracy does not degrade meaningfully over time without triggering logging and alerting mechanisms. On cybersecurity, the Act requires that systems be resilient against attempts by third parties to exploit vulnerabilities to alter the use, behaviour, or performance of the system, including through so-called adversarial attacks on machine learning models. Providers should treat this obligation as complementary to, but distinct from, their obligations under the EU’s NIS2 Directive and the Cyber Resilience Act, both of which may independently apply to their products.
Quality Management System (Article 17)
In addition to the above product-level requirements, providers of high-risk AI systems must implement a quality management system covering the entire development and deployment process. The QMS must include documented policies on data management, technical documentation, post-market monitoring, incident reporting, and personnel training. Providers that already hold ISO 9001 certification or operate under established quality frameworks in regulated sectors such as medical devices will find points of overlap, but the AI Act’s QMS requirements are distinct and require explicit attention. For smaller US companies that have never operated under a formal quality framework, building a compliant QMS from scratch will require sustained investment in processes, documentation, and governance infrastructure.
6. Compliance Obligations for Deployers of High-Risk AI Systems
Article 26 of the EU AI Act sets out the obligations of deployers — those who use high-risk AI systems in a professional context. While these obligations are less extensive than those of providers, they are substantive and carry their own significant compliance workload. US companies with European operations that deploy high-risk AI systems built by third-party providers must not assume that responsibility for compliance lies entirely with the provider.
Deployers are required to use high-risk AI systems only in accordance with the instructions for use supplied by the provider, and must ensure that the individuals assigned to exercise human oversight have the necessary competence, training, and authority to do so effectively. Deployers must not assign human oversight tasks to persons who lack the technical understanding necessary to interpret the system’s outputs intelligently. Where the provider’s instructions indicate that certain inputs are required for the system to perform accurately, deployers must take appropriate steps to ensure that those input conditions are met in practice.
Deployers must monitor the operation of the high-risk AI system on the basis of the instructions for use and must report to the provider any serious incidents or malfunctions — defined as incidents that result in or have the potential to result in death, serious injury, damage to property, or significant disruption to the provision of essential services. Deployers are also required to retain the automatically generated logs for a minimum period (which for deployers that are public authorities is at least six months), and must cooperate with national competent authorities in any investigation or market surveillance activity.
Where a deployer is a public authority, a provider of essential services such as a bank or insurer, or where the system is being used to make decisions in high-stakes domains including credit, insurance, employment, or justice, Article 27 requires the deployer to conduct a Fundamental Rights Impact Assessment (FRIA) before deploying the system. The FRIA is conceptually analogous to a Data Protection Impact Assessment under the GDPR and must identify the categories of persons likely to be affected, the specific fundamental rights at risk, the measures taken to mitigate those risks, and the human oversight mechanisms in place. US companies should note that the FRIA obligation arises even where a DPIA has already been conducted; the two assessments serve overlapping but distinct purposes and both may be required simultaneously.
Deployers must also ensure that natural persons who are subject to decisions made by or with material input from a high-risk AI system are informed that they have been subject to such a system, where such notification is not already provided by the provider. This transparency obligation is particularly relevant for US companies deploying AI in consumer-facing contexts within the EU — for example, using automated credit decisions, insurance pricing models, or candidate screening tools — and dovetails with the transparency requirements under GDPR Articles 13 and 14.
7. The Obligation to Appoint an EU Authorized Representative
US businesses that are providers of high-risk AI systems and that do not have a legal establishment in any EU Member State are required by Article 22 of the AI Act to appoint an authorised representative in the European Union before placing their system on the EU market. This obligation closely mirrors the Article 27 GDPR representative requirement, and many US companies will already have an existing EU representative for GDPR purposes. However, the AI Act’s authorised representative has distinct functions and responsibilities that are not automatically assumed by a GDPR Article 27 representative, meaning that a separate appointment — or a formal extension of an existing representative’s mandate — is required.
The authorised representative is the person or entity to whom EU national market surveillance authorities and the European AI Office will direct inquiries and enforcement action on behalf of the third-country provider. The representative must be named in the provider’s technical documentation and EU Declaration of Conformity, and must have sufficient authority to act on the provider’s behalf in dealings with regulators. The representative must be established in the EU and must retain a copy of the technical documentation and the EU Declaration of Conformity for a period of ten years after the last AI system has been placed on the market.
Practical Note for US Businesses
Appointing an authorised representative is not merely a box-ticking exercise. The representative carries personal legal exposure and must be capable of substantively engaging with regulatory authorities. US businesses should ensure that their representative has access to all relevant technical documentation, understands the system and its risk profile, and has a clear contractual framework with the US provider governing the scope of the mandate, indemnification arrangements, and information-sharing obligations. Law firms and specialist compliance service providers in the EU are frequently appointed to this role.
8. Conformity Assessment, CE Marking, and EU Database Registration
Before placing a high-risk AI system on the EU market, providers must undertake a conformity assessment to demonstrate that the system meets all of the requirements set out in Chapter III, Section 2 of the Act. The nature of that conformity assessment varies depending on the type of high-risk system.
For most Annex III standalone high-risk AI systems, providers have the option of conducting an internal conformity assessment — a structured self-assessment process in which the provider reviews its own documentation, risk management processes, and technical outputs against the Act’s requirements and certifies compliance. This internal assessment must be conducted according to the procedure set out in Annex VI. It must be documented, must be repeatable, and must result in a formal conclusion that the system meets all applicable requirements. While no third-party certification body is required for most Annex III systems, the internal assessment must be rigorous: national authorities will scrutinise it during market surveillance exercises, and a superficial or poorly documented self-assessment will not withstand regulatory challenge.
For high-risk AI systems that are safety components of products subject to Annex I harmonisation legislation, the conformity assessment pathway is determined by the applicable sectoral legislation. Where that legislation already requires third-party conformity assessment by a notified body, the AI Act’s requirements will be incorporated into that assessment process. US companies in regulated sectors such as medical devices or industrial machinery will need to work with their existing notified bodies to ensure that AI-specific requirements are addressed within the established assessment framework.
Once the conformity assessment has been successfully completed, providers must draw up an EU Declaration of Conformity (Article 47), affix the CE marking to the AI system or its accompanying documentation where applicable (Article 48), and register the system in the EU database for high-risk AI systems administered by the European Commission (Article 49). The EU database is publicly accessible for most high-risk AI systems, meaning that the fact of registration — and certain basic details about the system — will be visible to the public, to competitors, and to the individuals whose lives the system may affect. Registration must be completed before the system is placed on the market, and providers must keep their registration entry up to date as the system evolves.
9. Key Compliance Timelines
The EU AI Act is being phased in over a period of three years from its entry into force. US businesses must understand where the relevant deadlines fall, because some provisions are already in effect and the high-risk obligations will apply from August 2026 at the latest. The following table summarises the key dates.
| Date | What Applies | Status |
| 1 Aug 2024 | Regulation enters into force. Definitions, general principles, and governance architecture take effect. | In Force |
| 2 Feb 2025 | Chapter I (general provisions) and Chapter II (prohibited AI practices) apply. AI systems falling within the prohibited categories must be withdrawn from the EU market or discontinued. | In Force |
| 2 Aug 2025 | Rules on notifying authorities and notified bodies (Chapter III, Section 4); obligations relating to General Purpose AI (GPAI) models (Chapter V); EU governance structures including the AI Office (Chapter VII); and penalty provisions (Chapter XII) apply. | Upcoming |
| 2 Aug 2026 | The full Regulation applies, including all high-risk AI obligations under Chapter III, Sections 2 and 3. High-risk AI systems in Annex III categories must be compliant before being placed on or remaining on the EU market. | High-Risk Deadline |
| 2 Aug 2027 | High-risk AI systems that are safety components of products subject to Annex I harmonisation legislation (Article 6(1) systems) must comply, where those products are already subject to mandatory third-party conformity assessment under the applicable sectoral legislation. | Extended Deadline |
The two-year window to August 2026 may appear generous, but the substantive work required to achieve compliance is considerable. Building a risk management system, restructuring data governance processes, creating comprehensive technical documentation, conducting a conformity assessment, drawing up a Declaration of Conformity, and completing EU database registration — all while ensuring that the underlying AI system has been engineered to meet the robustness, accuracy, logging, and human oversight requirements — is a programme of work that realistically requires eighteen months or more for a mid-sized technology company starting from scratch. US businesses that have not yet begun their EU AI Act readiness work should treat the August 2026 deadline as closer than it appears.
10. Penalties for Non-Compliance
The EU AI Act’s enforcement regime, set out in Article 99, imposes fines calibrated in a manner that will be immediately recognisable to any company familiar with GDPR enforcement. Fines are expressed as the higher of either a fixed euro amount or a percentage of global annual turnover, ensuring that large multinational corporations cannot treat compliance as a minor cost of doing business.
The most serious category of infringement — placing a prohibited AI system on the market, or engaging in one of the prohibited AI practices described in Article 5 — carries a maximum fine of €35 million or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher. This is broadly comparable to the GDPR’s highest tier of fines, and regulators across the EU are already signalling that they intend to use their powers robustly.
Non-compliance with the requirements applicable to high-risk AI systems — including the obligations relating to risk management, data governance, technical documentation, transparency, human oversight, conformity assessment, and registration — carries a maximum fine of €15 million or 3% of global annual turnover. Supplying incorrect, incomplete, or misleading information to a notified body or national competent authority in the context of a conformity assessment or market surveillance inquiry is subject to a maximum fine of €7.5 million or 1.5% of global annual turnover.
Important Note for Smaller Businesses
For small and medium-sized enterprises and start-ups, the Act provides that the applicable fine is the lower of the two figures — the fixed euro cap or the percentage of turnover — rather than the higher, providing some proportionality for smaller operators. However, this does not reduce the compliance obligations themselves, and the reputational and commercial consequences of a public enforcement action — including mandatory product withdrawal from the EU market — can be severe for any business regardless of size.
Enforcement will be carried out by national market surveillance authorities in each EU Member State, coordinated at a pan-European level by the newly established European AI Office, which sits within the European Commission and has a specific oversight role in relation to general-purpose AI models. The AI Office will also maintain the EU database for high-risk AI systems and will publish guidance, standards references, and enforcement decisions as the regime matures. US businesses should monitor AI Office publications carefully, as the Office is expected to issue significant secondary guidance during 2025 and 2026 that will shape how the Act’s requirements are interpreted in practice.
11. Practical Steps US Businesses Should Take Now
For many US companies, the EU AI Act represents the first time they have faced a legally binding, comprehensive regulatory framework specifically governing their AI products or operations. The following steps represent the minimum that a US business with EU market exposure should be taking in the near term.
Conduct an AI inventory and classification exercise. The necessary starting point is a thorough inventory of all AI systems that the business develops or deploys in contexts that could trigger the Act’s jurisdiction. Each system should be assessed against the prohibited practices list, the Annex III high-risk categories, and the Annex I regulated product categories. This exercise should be documented formally and reviewed at least annually, since the business’s AI portfolio will evolve and the classification of any given system may change as its intended use or technical architecture changes. Companies that already maintain a data processing record for GDPR purposes will find structural similarities in this exercise, though the AI Act inventory must capture a different set of characteristics.
Determine your role and appoint an EU authorised representative. For each AI system within scope, identify whether the company is acting as a provider, a deployer, or both. For US providers of high-risk systems who lack an EU establishment, begin the process of appointing an EU authorised representative without delay — this is a precondition for placing the system on the EU market and establishing the authorised representative relationship takes time to negotiate and document properly.
Begin building your technical documentation and risk management infrastructure. The technical documentation required by Annex IV and the risk management system required by Article 9 are the backbone of high-risk AI compliance. They are not documents that can be produced quickly at the end of a development cycle; they must be built in parallel with the AI system itself, capturing design decisions, dataset choices, testing methodologies, and risk assessments as they are made. Engineering and legal teams must work together to establish the documentation practices and governance processes needed to meet this standard.
Assess your data governance framework against Article 10. For AI systems that involve model training, a rigorous assessment of existing data practices is essential. This should address the origin and representativeness of training data, the processes for detecting and mitigating bias, the handling of special categories of personal data in training sets, and the intersection of Article 10 obligations with GDPR data minimisation and purpose limitation requirements. Companies should not assume that GDPR compliance alone satisfies the AI Act’s data governance requirements — the two frameworks are complementary but not identical.
Engage with the emerging standards landscape. The European Commission has mandated the European standards organisations CEN and CENELEC to develop harmonised standards that, once published, will allow providers to certify compliance through conformance with those standards. Monitoring the development of these standards and engaging in the public consultation processes is a practical way for US businesses to anticipate how the Act’s technical requirements will be interpreted and to contribute to shaping standards that reflect commercial reality. The standards process is ongoing, and the first wave of AI Act harmonised standards is expected during 2025 and 2026.
Plan for the intersection of the AI Act with other EU frameworks. The EU AI Act does not exist in isolation. High-risk AI systems frequently process personal data, triggering GDPR obligations — and in particular the requirement for a DPIA under Article 35 GDPR may arise alongside the AI Act’s risk management and FRIA obligations. Systems deployed in critical infrastructure sectors may additionally be subject to the NIS2 Directive’s cybersecurity requirements, and products embedded with AI components may also be subject to the Cyber Resilience Act once its own obligations become applicable. A joined-up compliance strategy that addresses all applicable frameworks holistically, rather than addressing each in isolation, is both more effective and more efficient.
How We Can Help
Our data protection and AI regulation practice advises US companies on every aspect of EU AI Act compliance, from initial scoping and classification exercises through technical documentation frameworks, authorised representative arrangements, conformity assessment planning, and regulatory liaison. We work closely with your engineering, product, and legal teams to build compliance programs that are legally robust, operationally realistic, and capable of evolving as the regulatory landscape matures. If you would like to discuss your company’s specific circumstances, please contact us.
