Framework AI Governance & Privacy Frameworks
EU AI Act
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is the European Union's horizontal law on AI.
It sorts AI systems by risk: a short list of prohibited practices, a set of high-risk uses (Annex III standalone systems such as hiring, credit scoring, and critical infrastructure, plus Annex I systems embedded in products already covered by EU product safety law), transparency duties for chatbots and synthetic content, and a separate regime for general-purpose AI models.
The prohibitions have applied since February 2, 2025 and the general-purpose model obligations since August 2, 2025. The Digital Omnibus on AI, reported as entering into force on July 27, 2026, pushed the high-risk deadlines back: Annex III systems to December 2, 2027 and Annex I systems to August 2, 2028 (verify against the consolidated text).
The Article 50 transparency duties kept their August 2, 2026 date.
For a provider of a high-risk system the law is largely a documentation statute. It requires a written risk management system that runs across the lifecycle, data governance records for training and testing sets, technical documentation per Annex IV, automatic logging, instructions for use, a human oversight design, a quality management system, a declaration of conformity, and post-market monitoring with serious incident reporting.
Deployers must follow those instructions, keep logs, assign trained human oversight, and in some cases complete a fundamental rights impact assessment. Every organization, whatever its role, must ensure staff have adequate AI literacy.
Who has to comply
Providers that place AI systems or general-purpose models on the EU market, deployers established in the EU, and importers and distributors. Providers and deployers outside the EU are caught when the system's output is used in the EU. Obligations scale with the risk tier; most SMEs using off-the-shelf tools face only the AI literacy and transparency duties.
What the assessor asks to see
AI system inventory and risk classification rationale; risk management system documentation; data governance records (provenance, bias examination, relevance of training data); Annex IV technical documentation; logging design and retained logs; instructions for use; human oversight measures; quality management system; conformity assessment record and EU declaration of conformity; EU database registration; post-market monitoring plan and incident reports; AI literacy training records; for deployers, the fundamental rights impact assessment where required.
Where the requirement sits: Art 4 AI literacy; Art 26 deployer obligations; Art 9 risk management; Art 11 technical documentation; Art 17 QMS
Application timeline
Entry into force August 1, 2024. Prohibited practices and AI literacy from February 2, 2025. General-purpose AI model obligations and governance provisions from August 2, 2025.
Transparency obligations (Article 50) from August 2, 2026. High-risk Annex III systems deferred by the AI Omnibus to December 2, 2027 and Annex I systems to August 2, 2028; these amended dates were reported by legal commentary after the Omnibus entered into force on July 27, 2026 and should be verified against the Official Journal text.
What AllyMatter does here
AI-use policy and literacy-acknowledgment layer.
AllyMatter publishes this site.
Assessors
Who assesses EU AI Act
Depends on the system. Most Annex III high-risk providers self-assess through the internal control procedure in Annex VI. Third-party assessment by a notified body is required for certain biometric systems where harmonized standards are not fully applied, and for Annex I products it runs through the notified body already used under the sectoral product law.
General-purpose model providers are supervised directly by the AI Office. Accredited by National notifying authorities designate notified bodies, normally on the basis of accreditation by the national accreditation body under Regulation (EC) 765/2008. Designations are published in the Commission's NANDO database.
Public register of assessors: https://webgate.ec.europa.eu/single-market-compliance-space/#/notified-bodies
No firm has claimed a EU AI Act assessor listing yet. Claim yours →
Consultants
Who helps with EU AI Act
A fast-growing ecosystem of law firms, AI governance consultancies, and GRC platform vendors. Typical engagements start with an inventory and risk classification of AI systems, then build the risk management system, technical documentation, and quality management system for anything high-risk, and often map the work onto ISO/IEC 42001.
Engagements run from a few weeks for classification to many months for a high-risk provider.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a EU AI Act consultant listing yet. Claim yours →
Software
Tools for EU AI Act
Tools that name this framework in their own material.
Related reading
- High-level summary of the AI ActClause-by-clause plain-language walkthrough of the risk tiers and what providers and deployers must actually do for each.Future of Life Institute
- EU AI Act Omnibus Agreement: postponed high-risk deadlines and other key changesExplains the Digital Omnibus changes that moved the high-risk compliance dates, and what stayed on the original timetable.Gibson Dunn
- U.S. companies face the EU AI Act's compliance deadlineSets out when the Act reaches a non-EU company and which documentation and governance duties follow from that.Holland & Knight
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for EU AI Act
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of EU AI Act in AllyMatter
Approve the policies EU AI Act asks for, keep every version, and record a named acknowledgment from each person who has to read them.