EU AI Act obligations depend on two variables: your role (provider, deployer, importer, distributor) and your system’s classification (unacceptable risk is banned; then high, limited and minimal risk). Most companies are deployers — they use AI systems supplied by third parties.
The EU AI Act (Regulation (EU) 2024/1689) defines four risk levels. Unacceptable risk (Article 5): prohibited practices. High risk (Article 6 and Annex III): reinforced obligations. Limited risk: transparency obligations. Minimal risk: no binding obligations.
For a deployer of a high-risk system, the main obligations are set out in Article 26: use the system in line with the provider’s instructions, ensure human oversight, monitor operation, report serious incidents, keep automatic logs, inform affected persons, and — in certain cases — carry out a Fundamental Rights Impact Assessment (FRIA, Article 27).
For a provider of a high-risk system, the obligations are heavier (Articles 9 to 21): a risk-management system, data governance, technical documentation, automatic record-keeping, transparency towards deployers, ex-ante conformity assessment, CE marking, registration in the EU database, a declaration of conformity, and post-market monitoring.
For limited-risk systems (chatbots, deepfakes, AI-generated content): a transparency obligation (Article 50) — users must know they are interacting with an AI or that content is AI-generated. The preparation priority before 2 August 2026: map your AI systems, classify each against Annex III, identify your role for each, and prioritise bringing high-risk systems into compliance.
Start from your role, not the technology: most organisations are deployers, and Article 26 is a far shorter list than the provider duties in Articles 9–21 — knowing which hat you wear scopes the whole programme.
This ISO/IEC 42001 Lead Auditor training prepares audit, risk, and compliance professionals to assess Artificial Intelligence Management Systems (AIMS) in a structured, defensible way. The course focuses on planning, conducting, and closing ISO/IEC 42001 audits in real organizational environments, addressing governance, ethical use of AI, risk management, and regulatory expectations shaping 2024–2025. Participants learn to interpret ISO/IEC 42001 requirements from an auditor’s perspective, evaluate objective evidence, and formulate audit conclusions that stand up to certification scrutiny and executive review.
View courseThis Lead AI Risk Manager training prepares professionals to design, operate, and defend an AI risk management program aligned with regulatory and governance expectations. The course focuses on practical risk identification, decision traceability, and defensible mitigation strategies across the AI.
View courseISO/IEC 27001 formation and certification is no longer a differentiator but a baseline expectation. This training prepares professionals to implement and manage an Information Security Management System that actually works in operational environments.
View courseAIMS scope defines which AI activities, systems, and organizational units are covered. Context analysis examines stakeholders, legal requirements, and organizational objectives to ensure the AIMS is fit for purpose.
A Statement of Applicability documents which controls are selected for the AIMS and why they apply, creating traceability between risks, requirements, and controls.
Leaders and managers who oversee program accountability and governance decisions.
Common gaps include incomplete risk assessments, generic policies not tailored to AI risks, insufficient training, and weak monitoring. Address them through stakeholder involvement, evidence-based controls, and continual review.
ISO 27001 gives you a head start on ISO 42001, not a free pass. Here is what carries over, what is new, and how to extend your ISMS to an AIMS, step by step.
Regulation (EU) 2024/1689 is the EU's first comprehensive risk-based horizontal AI law, applying in stages from 2025 to 2027 (with Article 6(1) deferred to 2027). Complete guide.
Browse all FAQs →
Full knowledge base
Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.