The EU AI Act establishes requirements and obligations for providers of high-risk systems. We summarized them in 10 points that companies in high-risk sectors should be aware of.
The EU enacted the EU AI Act in 2024 to ensure trustworthy and ethical AI across Europe. It introduces a range of requirements and obligations for companies providing or using AI, especially in so-called “high-risk areas”. Find out if your AI system qualifies as high-risk and what that means for you below.
The EU AI Act was introduced on the 21st of April 2021 by the European Commission, adopted by the EU co-legislators and the Member States in 2024, and entered into force on the 1st of August 2024. It aims to regulate AI across the EU to make it trustworthy and ethical. The Act introduces a risk-based approach, specifying four different levels of risk: unacceptable risk, high risk, limited risk, and minimal risk. It also regulates general purpose AI models (GPAI) extensively. The compliance obligations for companies vary according to these categories, with companies in the high-risk category having the highest obligations to fulfill.
The EU AI Act was amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026. The high-risk obligations now apply from 2 December 2027 for systems classified via Annex III, and from 2 August 2028 for systems classified via Annex I.
The EU defines high-risk AI systems as those that have the potential to cause significant harm to the health, safety or fundamental rights of people. Examples of high-risk AI systems include those used in critical infrastructure, transportation, and healthcare. The Act also includes AI systems that are used to make decisions that have legal or similarly significant effects, such as credit scoring or hiring decisions.
However, there are some exceptions that could apply. Under Article 6, a system in an Annex III area is not high-risk where it performs only a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns without replacing or influencing human assessment, or performs a preparatory task – provided it does not pose a significant risk of harm and does not profile natural persons. Article 6 also separately excludes systems used solely for non-safety purposes such as optimization, efficiency, or quality control from qualifying as safety components.
Consult this article to find out whether your system classifies as high-risk. Or see Annex I and III of the EU AI Act which provide an extensive list of AI systems that classify as high-risk.
Companies that fail to comply with the EU AI Act and its extensive measures for high-risk AI systems may face significant penalties. The Act introduces fines of up to 7% of the company’s annual global annual turnover or €35 million, whichever is higher, for violations of the prohibited systems. All other violations can receive fines of up to €15 million or 3% of the global turnover. Companies may also face reputational damage and legal action from affected individuals.
Chapter 3 of the EU AI Act establishes requirements and obligations for providers of high-risk systems. We summarized them below to give a better overview of what applies for companies in the high-risk sectors. The EU AI Act has been criticized for the missing specification of how to implement those requirements, which shifts the focus to guiding standards and guidelines that have to be developed.
The Digital Omnibus on AI partly answered the criticism that the Act attaches a single set of generic requirements to all high-risk systems: technical documentation may now be simplified for SMEs, start-ups and small mid-cap enterprises (SMCs), the simplified quality management route was extended from microenterprises to all SMEs.

1. Set up a Quality Management System that includes the following:
2. Check whether you must conduct a fundamental rights impact assessment. This is a deployer obligation (often providers are deployers under the AI Act too) and it applies to a limited group: bodies governed by public law, private entities providing public services, and deployers of credit-scoring or life and health insurance systems. The assessment must describe the deployment processes, the period and frequency of use, the categories of persons affected, the specific risks of harm to them, the human oversight measures, and the governance measures. It may cross-reference or incorporate parts of a data protection impact assessment.
3. Provide contact information for users / other stakeholders.
4. Keep logs over the duration of the system’s life cycle to enable traceability and monitoring. The logs must include the time period of system usage, input data, and people involved in verifying results. Logs may need different specifications depending on your application.
5. Implement transparency measures like providing user instructions for the system, information about characteristics, capabilities, and limitations of system performance, as well as output interpretation tools and a description of mechanisms included within the system.
6. Keep relevant documentation for ten years. That includes:
7. Register your AI system and undergo a conformity assessment to obtain the declaration of conformity and according CE marking. This is also necessary for non-European providers placing AI on the EU market, which also implies full compliance with all other requirements. Ensure necessary mitigation actions in case of non-conformity and inform the relevant authority.
8. Demonstrate conformity upon request in an audit. This includes detailed technical documentation and the latest logs of the AI system’s performance.
9. Implement human oversight during AI system use to understand capacities and limitations, to interpret outputs correctly, or to intervene in the system.
10. Implement cybersecurity measures to prevent attacks, ensure system robustness, and prevent failures. Uphold model accuracy and ensure that AI systems that continue to learn are designed to avoid biased outputs that could influence future operations.
If you are looking for an actionable AI governance framework that is aligned with the EU AI Act's obligations, take a look at our AI governance platform here.
Complying with the EU AI Act can sound daunting, especially for high-risk companies.
We suggest starting to set up governance processes already today. Organizations utilizing high-risk applications will need to comply with the EU AI Act starting from December 2027. Risk management, logging, and comprehensive documentation make sure that everything you develop today can still be used once the regulation is enforced and when you modify your systems later on.
Minimize technical, reputational, and societal risks of high-risk AI systems and increase understanding within your organization and among your customers.
Find out how to take the first steps in AI governance in this article. We are happy to get in touch about helping you set up the right tools and processes to meet your EU AI Act compliance requirements and automate compliance busywork along the way. Contact us here.