AI Act • AI Governance • Risk Management

AI Act Requirements

AI Act requirements depend on the system, role and risk category. A practical compliance plan starts with classification.

Last updated4 May 2026
Update workflowWeekly monitoring, monthly edits
MethodOfficial sources + practical governance controls
Quick next step

Not sure where your AI use stands?

Run the free AI compliance checkup to get a practical readiness score, likely risk bucket, missing controls and next actions.

Requirement categories

  • Prohibited practices: avoid or stop banned unacceptable-risk uses.
  • High-risk systems: maintain risk management, documentation, data governance, logging, transparency, human oversight, robustness and monitoring.
  • Transparency obligations: inform people when they interact with AI or view certain AI-generated content.
  • GPAI obligations: specific rules for providers of general-purpose AI models, with additional expectations for systemic-risk models.
  • AI literacy: ensure relevant people understand AI use, limitations and risks.
Advertisement

How to translate requirements into tasks

Create one task list for each AI system. Do not create a generic compliance plan detached from real use cases. For a chatbot, focus on transparency, escalation, data handling and monitoring. For an HR tool, focus on risk classification, human oversight, bias, documentation and legal review. For a GPAI model provider, focus on provider-specific obligations and evidence.

Who should be involved

AI Act readiness is cross-functional. Product understands functionality. Engineering understands architecture and logs. Security understands misuse and access risk. Privacy understands personal data. HR understands employee impact. Legal and compliance interpret obligations. Leadership decides risk appetite and resources.

Advertisement

FAQ

Are requirements the same for providers and deployers?

No. Obligations vary by role and use case.

What is the best first document?

An AI inventory with classification notes and responsible owners.

Can requirements change?

Guidance and implementation support can evolve, so monitor official updates.

Sources and review method

This page is written as general business guidance, not legal advice. It is maintained from official AI Act materials, European Commission / AI Office updates, the NIST AI Risk Management Framework and practical AI governance controls.

Reviewed byAI Compliance Checkup Editorial Team
Review methodOfficial AI Act, European Commission, EUR-Lex and NIST sources
Last reviewed4 May 2026
Contactcontact@aicompliancecheckup.com