Skip to main content

The Art of CTO EU AI Act Compliance tool classifies AI system risk levels under the EU AI Act and generates compliance checklists based on the determined risk category.

What does the EU AI Act require of our system?

Your system's risk tier and the compliance checklist that follows from it.

About 15 min · Assessment · Free

About this toolWhy it matters, common mistakes, FAQ

What Does The EU AI Act Actually Require Of Your System?

Obligations are set by risk classification, and the classification is driven by use case rather than by model. The same model can be unregulated in one product surface and high-risk in another, which makes 'are we in scope' a per-feature question your roadmap has to answer.

Teams wait for the model provider to hand them compliance. Provider obligations and deployer obligations are separate — using a compliant model in a high-risk context still leaves you owning risk management, logging, human oversight and transparency.

Questions CTOs ask

What are the EU AI Act risk categories?
The EU AI Act classifies AI systems into four risk tiers: unacceptable risk (banned outright, including social scoring and real-time biometric surveillance), high risk (subject to strict requirements including conformity assessments, risk management systems, and human oversight — covers AI in hiring, credit scoring, healthcare, and critical infrastructure), limited risk (transparency obligations like disclosing AI-generated content), and minimal risk (no specific requirements). Most enterprise AI applications fall into the high-risk or limited-risk categories.
When does the EU AI Act take effect?
The EU AI Act entered into force in August 2024 with a phased implementation timeline. Prohibited AI practices became enforceable in February 2025, general-purpose AI model obligations apply from August 2025, and high-risk AI system requirements take full effect in August 2026. Companies should begin compliance assessments now, as implementing required technical documentation, risk management systems, and human oversight mechanisms for high-risk systems typically takes 12-18 months.

Related Reading