EU AI Act Compliance

Understanding how AuditTrue supports alignment with the EU AI Act.

Informational Disclaimer: This page describes how AuditTrue's platform supports organizations under the EU AI Act (Regulation 2024/1689). AuditTrue is not a certified regulatory body, conformity assessment entity, or notified body. This is not legal advice.

Related: For a compliance-focused summary, see our EU AI Act compliance page. This page provides the full technical article-by-article breakdown.

Our Approach

The EU AI Act (Regulation 2024/1689) establishes the first comprehensive legal framework for artificial intelligence. It takes a risk-based approach — categorizing AI systems by their level of risk and imposing corresponding obligations on providers and deployers. AuditTrue provides tools to help organizations operationalize AI governance aligned with the Act's principles, from risk classification through post-market monitoring.

Risk Classification — Four Tiers

The Act defines four risk categories, each with distinct obligations:

Unacceptable Risk (Prohibited)

AI systems that pose a clear threat to safety, livelihoods, or fundamental rights are banned. This includes social scoring by public authorities, real-time biometric identification in public spaces (with limited exceptions for law enforcement), manipulative or deceptive techniques, untargeted facial scraping, and exploitative profiling of vulnerable groups.

High Risk (Regulated)

AI systems used in critical domains — employment screening, credit scoring, medical diagnostics, law enforcement, border control, education access, essential services, and democratic processes — are subject to the Act's most stringent requirements under Articles 9-15. Providers must undergo conformity assessment, maintain technical documentation, implement risk management systems, and ensure human oversight.

Limited Risk (Transparency Obligations)

AI systems that interact with humans (chatbots, emotion recognition, deep fakes) must disclose that users are interacting with AI. Content generated or manipulated by AI must be marked as artificial.

Minimal Risk (Voluntary)

AI systems with no significant risk face no mandatory obligations. Providers may voluntarily adopt codes of conduct.

High-Risk System Support — Article-by-Article

Article 9 — Risk Management System

Providers must establish a continuous, iterative risk management process throughout the AI system's lifecycle. This includes identification, estimation, and evaluation of known and reasonably foreseeable risks, adoption of risk treatment measures, and documentation of residual risks. AuditTrue provides structured risk assessment templates, continuous monitoring dashboards, and automated risk re-evaluation triggers when model or data changes occur.

Article 10 — Data and Data Governance

Training, validation, and testing datasets must meet quality criteria — relevant, representative, free of errors, and complete to the extent possible. Special category data requires additional safeguards. AuditTrue's data governance module tracks data lineage, documents dataset provenance, records preprocessing steps, flags potential bias sources, and maintains data quality metrics across the lifecycle.

Article 11 — Technical Documentation

Providers must maintain comprehensive technical documentation (Annex IV) before placing systems on the market. This includes general description, intended purpose, development methodology, design specifications, data requirements, performance metrics, and human oversight measures. AuditTrue's documentation engine auto-generates model cards, system specifications, training methodology descriptions, performance reports, and change logs — all version-controlled and export-ready.

Article 12 — Record-Keeping (Logging)

High-risk systems must automatically log events during operation. Logs must be kept for a period appropriate to the intended purpose and enable traceability. AuditTrue implements tamper-evident logging of every inference, decision, model version change, and human intervention — with configurable retention periods and cryptographic integrity verification.

Article 13 — Transparency to Deployers

Providers must supply deployers with instructions for use, including system capabilities, limitations, human oversight measures, and expected accuracy/durability. AuditTrue generates deployer-facing documentation packets with capability descriptions, known limitations, oversight protocol templates, and accuracy declarations.

Article 14 — Human Oversight

High-risk systems must be designed to allow effective human oversight before and during use. Oversight measures must be proportionate to the risks, level of autonomy, and context of use. AuditTrue supports human-in-the-loop workflows, intervention logging, override documentation, and review checkpoint scheduling — ensuring oversight is both enabled and demonstrable.

Article 15 — Accuracy, Robustness & Cybersecurity

Providers must achieve appropriate levels of accuracy, robustness, and cybersecurity throughout the lifecycle. This includes resilience to errors, faults, and unauthorized access. AuditTrue tracks accuracy metrics against declared baselines, monitors for drift, documents adversarial testing results, and maintains vulnerability assessment records.

Conformity Assessment Paths

Depending on the system type, providers follow one of two conformity assessment routes:

  • Internal Control (Annex VI): For most high-risk systems, providers conduct their own conformity assessment and compile a technical documentation file. A post-market monitoring plan is required. An EU declaration of conformity must be drawn up.
  • Notified Body (Annex VII): For systems used in biometrics, critical infrastructure, or law enforcement, third-party assessment by an accredited notified body is mandatory. The notified body examines the technical documentation, verifies the quality management system, and issues an EU type examination certificate.

AuditTrue organizes and version-controls all evidence needed for either path, with export formats aligned to notified body submission requirements.

Implementation Timeline

  • February 2, 2025: Provisions on prohibited AI practices (unacceptable risk) apply. AI literacy requirements take effect.
  • August 2, 2025: Governance framework provisions fully operational — European AI Office, national competent authorities, and notification framework established.
  • August 2, 2026: Full application of obligations for high-risk AI systems listed in Annex III (employment, credit, law enforcement, education, essential services, etc.). General-purpose AI model obligations apply.
  • August 2, 2027: Obligations extend to high-risk AI systems listed in Annex I (medical devices, machinery, aviation, automotive, marine, etc.).

Penalties for Non-Compliance

  • Prohibited AI practices: Up to €35 million or 7% of global annual turnover (whichever is higher)
  • High-risk obligation violations: Up to €15 million or 3% of global annual turnover
  • Incorrect, incomplete, or misleading information: Up to €7.5 million or 1% of global annual turnover
  • SMEs and startups: Lower caps apply, proportional to turnover (subject to the €7.5M minimum where applicable)
  • Supplier obligations: Non-compliance can result in withdrawal from the market, recall, or disabling of the AI system

Practical Implementation Steps with AuditTrue

  1. Inventory your AI systems: Use AuditTrue's discovery module to catalog all AI models, including vendor-provided and internally developed systems.
  2. Classify by risk tier: Run each system through the risk assessment engine to determine its EU AI Act category.
  3. Gap assessment: For high-risk systems, generate a gap analysis against Articles 9–15 requirements.
  4. Build documentation: Use auto-generated model cards and technical documentation to close documentation gaps.
  5. Implement monitoring: Deploy continuous monitoring for drift, bias, and accuracy deviations on all high-risk systems.
  6. Prepare conformity package: Export a complete conformity assessment file for internal sign-off or notified body submission.
  7. Establish post-market monitoring: Configure ongoing surveillance workflows and incident reporting channels.
  8. Train your team: Use AuditTrue's training tracking to ensure AI literacy requirements are met across your organization.

What We Do Not Do

  • Provide legal advice or regulatory interpretation
  • Certify organizations as EU AI Act compliant
  • Perform conformity assessments or issue CE markings
  • Act as a notified body
  • Guarantee compliance outcomes

Last updated: July 10, 2026. Informational only — consult a qualified attorney and your regulatory affairs team.