RL Written by Robert LabardeeFounder and CEO

EU AI Act compliance guide

The EU AI Act is the European Union's risk-based law governing artificial intelligence, sorting AI systems into prohibited, high-risk, limited-risk, and minimal-risk tiers and assigning obligations accordingly. Lightbridge Labs is an independent AI-governance advisor that helps providers and deployers, including non-EU organizations serving the EU market, prepare for these obligations.

The EU AI Act is the European Union's risk-based law for artificial intelligence.

The EU AI Act is a horizontal regulation: it governs artificial intelligence across sectors rather than carving out one industry at a time. Its central idea is that obligation should follow risk. Instead of treating all AI the same, the Act classifies an AI system by the risk its use poses and scales the rules to that classification. Its stated goal is to make AI placed on the EU market safe and trustworthy, protecting fundamental rights, health, and safety while still allowing innovation.

The Act entered into force in 2024 and applies its requirements in phases over the following years. It also sets a separate layer of obligations for general-purpose AI models, the foundation models that many applications build on. This page is a plain-language orientation, not legal advice, and the Act is detailed and evolving, so treat it as a map and verify the specifics against the official EUR-Lex text and your own counsel.

The EU AI Act sorts AI systems into four risk tiers.

The risk-based structure is the heart of the EU AI Act. Every system in scope sits in one of four tiers, and the tier determines how heavy the obligations are. Classifying each system correctly is the first practical step, because the same technology can land in different tiers depending on how it is used.

Prohibited (unacceptable risk)

A narrow set of practices the Act bans outright, such as certain social-scoring systems, manipulative techniques that exploit vulnerabilities, and specific untargeted biometric uses. If a system falls here, the answer is not configuration: the use case is not permitted in the EU market.

High-risk

Systems used in sensitive domains such as critical infrastructure, employment, education, essential services, and certain biometric and safety contexts. These carry the heaviest obligations: risk management, data governance, documentation, human oversight, and a conformity assessment before they reach the market.

Limited-risk (transparency)

Systems where the main duty is disclosure. People should know when they are interacting with an AI system, when content is AI-generated or manipulated, and when emotion-recognition or similar techniques are in use. The obligation is transparency rather than a full conformity regime.

Minimal-risk

The large majority of AI applications, such as spam filters and many productivity tools, that fall outside the higher tiers. The Act imposes few specific obligations here, though voluntary codes of conduct and good governance practice still apply.

The EU AI Act applies to providers and deployers, including non-EU organizations serving the EU market.

The Act assigns duties by role. A provider develops an AI system or a general-purpose AI model and places it on the EU market or puts it into service under its own name. A deployer uses an AI system under its authority in a professional setting. Importers and distributors carry their own duties as well. The roles are not cosmetic: a provider of a high-risk system shoulders the heaviest obligations, while a deployer has separate duties around oversight, monitoring, and using a system as intended. One organization is often both, depending on the system.

The reach extends beyond the EU's borders. The Act applies to providers that place an AI system or general-purpose AI model on the EU market wherever the provider is established, and it can apply to providers and deployers outside the EU when the output their AI produces is used within the EU. A US or other non-EU organization that sells AI into Europe, embeds AI in a product offered to EU users, or whose AI output reaches the EU can therefore be in scope. The way to settle scope is a documented assessment with counsel, captured inside an AI governance practice, rather than an assumption.

High-risk obligations under the EU AI Act center on risk management, oversight, and conformity.

High-risk systems carry the substantive weight of the EU AI Act. The obligations below are the recurring themes of that regime, summarized rather than reproduced in full. The precise requirements depend on a system's classification and role, so map your own systems against the official text instead of a generic list.

Risk management and data governance

Providers of high-risk systems run a documented risk-management process across the lifecycle and govern the data used to train, validate, and test models for relevance, representativeness, and error handling. These are continuous obligations, not a one-time gate.

Transparency and human oversight

High-risk systems must be designed so deployers understand how they work and so a human can effectively oversee them, including the ability to intervene or stop the system. Limited-risk systems carry disclosure duties so people know AI is involved.

Logging, documentation, and conformity

High-risk systems require technical documentation, automatic event logging for traceability, accuracy, robustness, and cybersecurity controls, plus a conformity assessment and CE marking before market entry, followed by post-market monitoring once deployed.

Limited-risk systems are lighter: the duty is transparency, so people know when they are interacting with AI or viewing AI-generated content. The work of turning these obligations into testable controls is what Lightbridge Labs designs under its AI governance practice.

The EU AI Act phases in over several years rather than all at once.

The Act entered into force in 2024, but its obligations switch on in stages. As a general shape, the prohibitions on unacceptable-risk practices apply first, transparency and general-purpose AI obligations follow, and the bulk of the high-risk requirements phase in over the following years. As of mid-2026, the exact application dates are best confirmed against the official EUR-Lex text and any implementing guidance, because the timeline is detailed and still being operationalized.

Enforcement has teeth. The Act establishes a structure of administrative fines scaled to a company's global annual turnover, with the highest band reserved for prohibited-practice violations and lower bands for other breaches. The structure is settled; the precise figures are the kind of detail to verify against the text rather than quote from memory. The practical takeaway is that a phased rollout is a planning opportunity: organizations that inventory and classify their systems early can sequence the heavier high-risk work before its deadline arrives.

An ISO 42001 AI management system gives organizations a durable substrate for EU AI Act readiness.

Preparing for the EU AI Act starts with an inventory: catalog the AI systems in use, classify each against the risk tiers, and determine whether the organization acts as provider or deployer for each one. From there, the high-risk systems drive the program: documented risk management, data governance, human oversight, logging, and the path to conformity. The goal is to turn each obligation into a control someone owns and an auditor or regulator could test.

This is where an AI management system earns its place. ISO 42001 is the international standard for governing AI: it sets out how an organization decides what AI to run, manages its risks, assigns oversight, and retains evidence. ISO 42001 is not the same as EU AI Act compliance, and holding the certificate does not by itself satisfy the Act, whose conformity runs through its own assessment and harmonized standards. What ISO 42001 does is operationalize many of the practices the Act expects, which makes it a strong foundation for readiness rather than a one-time scramble.

Lightbridge Labs builds the governance framework and the Act-specific controls together. For the management-system design, see our ISO 42001 advisory and broader AI governance practice. For teams that need to operate these controls day to day, our responsible AI governance training covers the practices that keep an AI program defensible. Organizations consuming foundation models can pair this with our Claude security and compliance guide.

EU AI Act compliance: frequently asked questions

What is the EU AI Act?
The EU AI Act is the European Union's horizontal law on artificial intelligence. It takes a risk-based approach: instead of regulating a technology in the abstract, it sorts AI systems by the risk a given use poses and scales obligations to that risk. The four tiers are prohibited or unacceptable-risk practices, high-risk systems, limited-risk systems subject to transparency duties, and minimal-risk systems. The Act also sets separate obligations for general-purpose AI models. It entered into force in 2024 and phases its requirements in over time. This is a simplified summary of an evolving regulation, so verify specifics against the official EUR-Lex text and your own counsel.
Who does the EU AI Act apply to?
The Act applies primarily to providers, the organizations that develop an AI system or general-purpose AI model and place it on the EU market or put it into service under their own name, and to deployers, the organizations that use an AI system under their authority in a professional context. Importers and distributors also carry duties. The roles matter because obligations differ: a provider of a high-risk system carries the heaviest set, while a deployer has its own duties around oversight, monitoring, and using the system as intended. Many organizations are both provider and deployer depending on the system.
What are the EU AI Act risk categories?
There are four risk tiers. Prohibited or unacceptable-risk practices are banned outright, including certain social-scoring and manipulative or specific biometric uses. High-risk systems, used in sensitive areas such as critical infrastructure, employment, education, and essential services, carry the heaviest obligations and a conformity assessment. Limited-risk systems face transparency duties, so people know when they are interacting with AI or seeing AI-generated content. Minimal-risk systems, the large majority of applications, face few specific obligations. General-purpose AI models are handled under a separate set of obligations layered on top of this structure.
Does the EU AI Act apply to US companies?
Yes, in defined circumstances. The Act has extraterritorial reach: it applies to providers that place an AI system or general-purpose AI model on the EU market regardless of where the provider is established, and it can apply to providers and deployers established outside the EU when the output produced by their AI system is used within the EU. A US company that sells AI into the EU, embeds AI in a product offered to EU users, or whose AI output reaches the EU can therefore fall in scope. The right way to confirm scope is a documented assessment with counsel, not an assumption either way.
What are the core obligations under the EU AI Act?
For high-risk systems, the core obligations include a documented risk-management process across the lifecycle, data governance for training, validation, and test data, technical documentation, automatic logging for traceability, transparency toward deployers, effective human oversight, and appropriate accuracy, robustness, and cybersecurity. Before a high-risk system reaches the market it must pass a conformity assessment and carry CE marking, and providers run post-market monitoring afterward. Limited-risk systems focus on transparency disclosures. The precise obligations depend on the system's classification and role, so map your own systems against the official text rather than a generic checklist.
When does the EU AI Act take effect?
The Act entered into force in 2024 and applies in phases rather than all at once. As a general shape, the prohibitions on unacceptable-risk practices apply first, transparency and general-purpose AI obligations follow, and the bulk of the high-risk requirements phase in over the following years. As of mid-2026 the exact application dates are best confirmed against the official EUR-Lex text and any implementing guidance, because the timeline is detailed and still being operationalized. The Act also establishes a structure of administrative fines scaled to global annual turnover, with the highest band reserved for prohibited-practice violations. Treat the specific dates and figures as items to verify, not as settled numbers to quote.
How does ISO 42001 relate to the EU AI Act?
ISO 42001 is the international standard for an AI management system: a governance framework for how an organization decides what AI to run, manages its risks, assigns oversight, and retains evidence. It is not the same thing as EU AI Act compliance, and holding an ISO 42001 certificate does not by itself satisfy the Act, whose conformity runs through its own assessment and harmonized standards. What ISO 42001 does is operationalize many of the practices the Act expects, including risk management, human oversight, documentation, and monitoring, which makes it a strong substrate for readiness. Lightbridge Labs builds the management system and the Act-specific controls together.
How does Lightbridge Labs help with EU AI Act readiness?
Lightbridge Labs is an independent AI-governance advisor. We help an organization inventory its AI systems, assess where each one falls in the Act's risk tiers, determine whether it acts as provider or deployer, and design the risk-management, oversight, documentation, and monitoring controls the obligations call for. We connect that work to an ISO 42001 AI management system so governance is durable rather than a one-time scramble. We are not a law firm and do not provide legal advice. Our certifications are in progress: Lightbridge Labs is pursuing ISO 42001 and operates to those controls while the audits proceed.

Important notices

General advisory: this page is general guidance from Lightbridge Labs as an independent AI-governance advisor. It is not a warranty and not a substitute for an assessment of your own systems and circumstances.

Not legal advice: this is a simplified summary of the EU AI Act, a complex and evolving regulation. It is not legal advice, and it does not capture every obligation, exception, or definition. Consult your own counsel and verify every specific against the official EUR-Lex text and any implementing guidance before relying on it. Specific dates, deadlines, and penalty figures in particular should be confirmed against the controlling text, because they are detailed and still being operationalized.

Freshness: regulatory text, guidance, and timelines change. This page reflects a general understanding as of mid-2026 and should be re-checked against current sources before action.

Trademarks: Claude and Anthropic are trademarks of Anthropic, PBC. Lightbridge is not affiliated with, endorsed by, or sponsored by Anthropic. References to standards such as ISO 42001 are for identification only.

From the EU AI Act text to a defensible AI program.

When the question shifts from what the EU AI Act says to how your organization proves it is ready, Lightbridge Labs inventories your systems, classifies the risk, and stands up the AI management system that governs them.