The Art of CTO EU AI Act Compliance tool classifies AI system risk levels under the EU AI Act and generates compliance checklists based on the determined risk category.
What does the EU AI Act require of our system?
Your system's risk tier and the compliance checklist that follows from it.
About 15 min · Assessment · Free
About this toolWhy it matters, common mistakes, FAQ
What Does The EU AI Act Actually Require Of Your System?
Obligations are set by risk classification, and the classification is driven by use case rather than by model. The same model can be unregulated in one product surface and high-risk in another, which makes 'are we in scope' a per-feature question your roadmap has to answer.
Teams wait for the model provider to hand them compliance. Provider obligations and deployer obligations are separate — using a compliant model in a high-risk context still leaves you owning risk management, logging, human oversight and transparency.
Questions CTOs ask
- What are the EU AI Act risk categories?
- The EU AI Act classifies AI systems into four risk tiers: unacceptable risk (banned outright, including social scoring and real-time biometric surveillance), high risk (subject to strict requirements including conformity assessments, risk management systems, and human oversight — covers AI in hiring, credit scoring, healthcare, and critical infrastructure), limited risk (transparency obligations like disclosing AI-generated content), and minimal risk (no specific requirements). Most enterprise AI applications fall into the high-risk or limited-risk categories.
- When does the EU AI Act take effect?
- The EU AI Act entered into force in August 2024 with a phased implementation timeline. Prohibited AI practices became enforceable in February 2025, general-purpose AI model obligations apply from August 2025, and high-risk AI system requirements take full effect in August 2026. Companies should begin compliance assessments now, as implementing required technical documentation, risk management systems, and human oversight mechanisms for high-risk systems typically takes 12-18 months.
Related Reading
EU AI Act compliance checklist: a CTO guide to risk classification and high-risk assessments
EU AI Act compliance checklist: a CTO guide to risk classification and high-risk assessments
guidesSTAMP Framework for Resilience: A Practical Operational Resilience Assessment Guide for FCA and DORA
STAMP framework for resilience: an operational resilience assessment tool guide for FCA and DORA
guidesVendor Risk Assessment Template for Series A CTOs: A Practical Third-Party Risk Management Tool
Vendor risk assessment template for Series A CTOs: a practical third-party risk management tool