Resource · AI governance & EU AI Act

EU AI Act: scope, high-risk systems, and evidence readiness

A practical guide to EU AI Act scope, high-risk systems, role-based obligations, and audit-ready evidence — written for CISOs, risk, compliance, and AI governance leaders.

Published 16 October 2025 · Last updated 3 September 2026 · Informational, not legal advice.

Who is in scope under the EU AI Act?

Any organisation that places on the market or puts into service AI systems or general-purpose AI (GPAI) models in the EU — or whose AI output is used in the EU — is in scope. This includes providers, deployers, importers, distributors, product manufacturers, and authorised representatives.

01

Extraterritoriality

Providers and deployers outside the EU fall in scope where the output is used in the Union.

02

Deployers

Any organisation established or located in the EU that uses AI under its authority.

03

Value chain roles

Importers (Art. 23), distributors (Art. 24), and responsibilities along the value chain (Art. 25).

04

GPAI

Providers of GPAI models have specific, earlier-starting obligations.

What counts as a “high-risk” AI system?

Two routes apply. AI that is a safety component of products under EU harmonisation laws (Annex I) requiring third-party assessment; and standalone uses listed in Annex III.

Route 1

Safety components under Annex I

AI that is a safety component of products covered by EU harmonisation legislation — and where those products undergo third-party conformity assessment — is classified as high-risk.

Route 2 · Annex III examples

Standalone uses listed in Annex III

  • Biometrics (remote identification, categorisation, emotion recognition)
  • Critical infrastructure (e.g., road traffic, energy and water supply)
  • Education and vocational training; employment and workers' management
  • Access to essential public/private services (e.g., credit scoring, emergency dispatch)
  • Law enforcement; migration, asylum and border control
  • Administration of justice and democratic processes

What obligations apply, by role?

Provider, deployer, importer, distributor, and integrator roles each carry different obligations. The summary below focuses on high-risk systems for the two most common roles.

Provider · high-risk systems

Build, document and certify

Establish a risk management system (Art. 9); implement data & data governance (Art. 10); prepare technical documentation (Art. 11 & Annex IV) and logging (Arts. 12, 19); ensure transparency/instructions (Art. 13) and human oversight design (Art. 14); meet accuracy/robustness/cybersecurity (Art. 15); maintain a QMS (Art. 17); complete conformity assessment and EU Declaration of Conformity/CE marking (Art. 43; Arts. 47–48); register where required (Arts. 49, 71); run post-market monitoring and serious-incident reporting (Arts. 72–73).

Evidence to keep

QMS manual, risk file, data sheets/lineage & bias tests, model & control test results, logs (≥6 months), EU DoC/CE, registration records, PMM plan & incident reports.

Deployer · high-risk systems

Operate, oversee and notify

Use the system per instructions and implement oversight by trained personnel (Art. 26); ensure input data is relevant/sufficiently representative if under your control (Art. 26); monitor operation and suspend/notify risks or serious incidents (Art. 26; Art. 73); retain logs (≥6 months) where under your control (Art. 26(6)); conduct FRIA where required (Art. 27); inform workers if used in the workplace (Art. 26(11)); register use when a public-sector deployer (Art. 49(3)).

Evidence to keep

Oversight assignments & training, input-data records, FRIA/DPIA, logs, notifications to provider/authorities, user communications, registration proof.

What evidence should we prepare for audits?

Prepare a concise, Article-mapped “audit kit” that proves your system and operations meet the Act’s lifecycle requirements. Prioritise artefacts that show controls work in practice, not just on paper.

01

Risk management file

Article 9

Hazard/threat analysis, mitigation decisions, and traceability.

02

Data & data governance dossier

Article 10

Lineage, representativeness, quality controls, and bias testing.

03

Technical documentation

Articles 11 & Annex IV

System description, intended purpose, testing, interfaces.

04

Logging & retention plan

Articles 12, 19, 26(6)

Automatic event logs with ≥6-month retention.

05

Human oversight design & training

Articles 14, 26(2)

Intervention procedures, training records, over-reliance mitigation.

06

Conformity evidence

Articles 17, 43, 47–49, 71

QMS, test reports, conformity assessment, EU DoC, CE marking, registration.

07

Post-market monitoring & serious-incident procedures

Articles 72–73

Roles, thresholds, reporting templates, incident logs.

What is a practical timeline to act?

Use a 90-day sprint to stand up governance and evidence — even if your formal deadlines are further out.

Days 0–3001

Discovery & mapping

Inventory AI systems/models; classify against Annex III/Art. 6; map roles (provider/deployer) and value-chain parties; appoint owners; start FRIA/DPIA scoping.

Days 31–6002

Controls & documentation

Draft Art. 9–15 controls (risk mgmt, data governance, oversight, accuracy/robustness/cybersecurity); define logging/retention; assemble Annex IV tech docs; outline PMM & incident playbooks.

Days 61–9003

Testing & conformity

Run tabletop tests; finalise QMS and Art. 43 path; prepare EU DoC/CE where applicable; define Art. 49/71 registration triggers; complete FRIA (if required) and worker notices.

Timing context: entry into force 1 August 2024; prohibited practices and AI literacy duties 2 February 2025; GPAI model obligations 2 August 2025; general application and Article 50 transparency duties 2 August 2026. Following the Digital Omnibus on AI (in force 27 July 2026), high-risk Annex III systems — the standalone uses most enterprises will hit, including hiring, credit scoring, education, and critical infrastructure — now apply from 2 December 2027, deferred from 2 August 2026. High-risk Annex I systems embedded in regulated products (medical devices, machinery, toys) now apply from 2 August 2028, deferred from 2 August 2027. Two further Article 5 prohibited-practice categories added by the Omnibus phase in 2 December 2026. Plan your roadmap accordingly.

How do third-party vendors fit?

You remain accountable for compliant use — contracts don’t transfer obligations. Flow down requirements and secure the technical access needed to evidence compliance.

01

Map vendor systems to roles

Map vendor systems to roles (provider vs. your deployer role) and risk class; require an evidence pack aligned to Arts. 9–15.

02

Secure contractual access

Use contractual value-chain terms to secure information/technical access and change-control; know when you “become the provider” (rebranding, substantial modification, purpose change).

03

Monitor post-deployment

Monitor vendor systems post-deployment; define serious-incident reporting and suspension triggers.

Frequently asked questions

Common questions about EU AI Act scope, obligations, and compliance.

From regulation to practice

See how STREAM® Cloud supports AI governance operationally

Connect AI systems, classification rationale, obligations, evidence, reviews and assurance reporting in one configurable workspace.

View use case

Ready to streamline your EU AI Act readiness?

Walk through how STREAM® Cloud could help your team connect AI systems, classifications, obligations, evidence, and assurance in one configurable workspace.

Sources

Page changelog & disclaimer

Disclaimer: this page is informational and not legal advice.

3 September 2026: Corrected the Timing context box, which had fallen behind the Digital Omnibus on AI (in force 27 July 2026). High-risk Annex III obligations now run from 2 December 2027 (previously stated as 2 August 2026) and Annex I obligations from 2 August 2028 (previously stated as 2 August 2027); Article 50 transparency and GPAI obligations were unaffected and remain on their original dates. The text was accurate when it was last touched — this reflects a regulatory change since then, not an error introduced at any point.

19 May 2026: Refined page chrome and ported onto the modern visual system used across the site.

28 October 2025: Enhanced AEO optimisation — added BreadcrumbList, HowTo, and ItemList schemas; expanded FAQ to 8 questions including compliance penalties and STREAM® capabilities; added anchor links; converted to reusable FAQ component.

16 October 2025: Initial publication covering EU AI Act scope, high-risk systems, role-based obligations, evidence requirements, 90-day timeline, and vendor risk management.