EU AI Act

The EU's risk-based regulation of AI systems, phasing in through 2027

The EU AI Act regulates AI systems by risk level, from minimal to prohibited. The heaviest duties fall on high-risk categories, and they phase in through 2027. If you build or deploy AI in areas like recruitment, credit, or critical infrastructure, the clock is already running.

Who it applies to

Providers and deployers of AI systems in the EU. The high-risk categories include AI used for HR screening and recruitment, credit scoring, critical infrastructure, education, and law enforcement. Many companies are deployers without thinking of themselves as AI companies, for example by using AI-supported recruitment tools.

What OptiTech provides

  • Risk classification: scoping questions determine which of your AI systems fall into which risk category
  • High-risk requirements as controls: risk management, data governance, human oversight, logging, and accuracy monitoring
  • Technical documentation: the conformity documentation high-risk systems require, drafted from your actual system descriptions
  • Transparency duties: user information requirements for limited-risk systems like chatbots
  • Timeline tracking: requirements activate as they phase in, so you work on what's actually due

Sanctions

Up to 35 million euros or 7 percent of global revenue, the steepest sanctions of any framework OptiTech covers.

Cross-mapping

The AI Act's risk management and logging requirements overlap with ISO 27001, and its data governance duties connect to GDPR.

Get started

The EU AI Act is available on every plan. Book a free gap analysis to classify your AI systems, or compare plans.

Need help?

Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.

Was this page helpful?

On this page

Copy neon init command