Skip to content

Compliance

EU AI Act

Risk classification, logging, and human oversight duties for AI systems in the EU. PRISM evidence shows what the system did and who approved each change.

At a glance

Who this covers, and who enforces it

Providers and deployers of AI systems placed on the market or put into service in the EU, with obligations scaled to a risk tier: unacceptable, high, limited, or minimal.

EU AI ActFramework
Instrument
Regulation (EU) 2024/1689 — binding law
Enforced by
EU AI Office + national market-surveillance authorities
Timeline
In force 1 Aug 2024; obligations phase in through 2027
Max penalty
€35M or 7% of global turnover
Risk model
Four tiers: unacceptable, high, limited, minimal

Requirements

What it asks for

  • 1Classify each system by risk tier and register high-risk systems
  • 2Maintain technical documentation and automatic logging
  • 3Provide for human oversight of high-risk system decisions
  • 4Run post-market monitoring and report serious incidents

Evidence mapping

What PRISM records against each requirement

Every plan records this evidence as your AI runs. Compliance Reports, which turn it into a reviewed, framework-mapped report, are delivered as a service, on request.

EU AI Act
Risk classification
Model Inventory tags each system’s risk tier and intended use.
Technical documentation & logging
Traces and Sessions record every input/output pair PRISM observes, automatically.
Human oversight
Evaluators and Guardrails log review and override actions against a named reviewer.
Post-market monitoring & incidents
Scores & Alerts plus the Audit Log show ongoing monitoring and every change over time.

Primary source

Read the actual text

Everything on this page is drawn from European Commission — Shaping Europe's Digital Future. The capture is live, not a paraphrase — go straight to the source and check us.

digital-strategy.ec.europa.eu
Capture of European Commission — Shaping Europe's Digital Future
Live capture, 24 Aug 2026Open the source ↗

Evidence, not certification

This page describes EU AI Act’s publicly available requirements and how PRISM’s evidence layer supports them. It is not legal advice, and it does not constitute certification, regulatory approval, or a guarantee of compliance. EU AI Act compliance remains your organization’s responsibility, in consultation with qualified counsel.

Ask us about your framework

Tell us how EU AI Act applies to your systems and we'll show you the evidence path.