Compliance
EU AI Act
Risk classification, logging, and human oversight duties for AI systems in the EU. PRISM evidence shows what the system did and who approved each change.
At a glance
Who this covers, and who enforces it
Providers and deployers of AI systems placed on the market or put into service in the EU, with obligations scaled to a risk tier: unacceptable, high, limited, or minimal.
- Instrument
- Regulation (EU) 2024/1689 — binding law
- Enforced by
- EU AI Office + national market-surveillance authorities
- Timeline
- In force 1 Aug 2024; obligations phase in through 2027
- Max penalty
- €35M or 7% of global turnover
- Risk model
- Four tiers: unacceptable, high, limited, minimal
Requirements
What it asks for
- 1Classify each system by risk tier and register high-risk systems
- 2Maintain technical documentation and automatic logging
- 3Provide for human oversight of high-risk system decisions
- 4Run post-market monitoring and report serious incidents
Evidence mapping
What PRISM records against each requirement
Every plan records this evidence as your AI runs. Compliance Reports, which turn it into a reviewed, framework-mapped report, are delivered as a service, on request.
- Risk classification
- Model Inventory tags each system’s risk tier and intended use.
- Technical documentation & logging
- Traces and Sessions record every input/output pair PRISM observes, automatically.
- Human oversight
- Evaluators and Guardrails log review and override actions against a named reviewer.
- Post-market monitoring & incidents
- Scores & Alerts plus the Audit Log show ongoing monitoring and every change over time.
Primary source
Read the actual text
Everything on this page is drawn from European Commission — Shaping Europe's Digital Future. The capture is live, not a paraphrase — go straight to the source and check us.

Evidence, not certification
This page describes EU AI Act’s publicly available requirements and how PRISM’s evidence layer supports them. It is not legal advice, and it does not constitute certification, regulatory approval, or a guarantee of compliance. EU AI Act compliance remains your organization’s responsibility, in consultation with qualified counsel.
Keep reading
- All frameworksThe full evidence-layer overview and all twelve frameworks.
- NIST AI RMFThe govern, map, measure, manage cycle. Traces, evaluations, and reviews become the measure and manage record.
- ISO/IEC 42001The auditable AI management system standard. Operational evidence for the clauses an internal auditor asks to see.
Ask us about your framework
Tell us how EU AI Act applies to your systems and we'll show you the evidence path.