EU AI Act
The EU AI Act (Regulation (EU) 2024/1689) is the European Union's comprehensive AI regulation, imposing risk-based obligations on providers and deployers of AI systems placed on the EU market or used in the EU.
How the EU AI Act Is Structured
The Act uses a risk-based approach, classifying AI systems into four categories with different obligations for each.
- Prohibited AI: Practices banned outright, including social scoring, real-time biometric identification in public spaces (with narrow exceptions), and manipulation causing significant harm.
- High-risk AI: Systems used in specified high-stakes areas that require conformity assessment, technical documentation, risk management, and other controls before market placement.
- Limited-risk AI: Systems subject to transparency obligations under Article 50, including disclosure of AI-generated content.
Separately, general-purpose AI models face their own obligations, with additional requirements for models with systemic risk.
Key Dates for the EU AI Act
The Act entered into force on August 1, 2024. Prohibited AI practice provisions applied from February 2, 2025. General-purpose AI obligations applied from August 2, 2025. High-risk AI obligations for systems in Annex III apply from August 2, 2026, with additional obligations phasing in through 2027.
Why the EU AI Act Matters Globally
The Act applies to any AI system placed on the EU market or whose output is used in the EU, regardless of where the provider or deployer is based. Enterprises operating globally are building compliance programs against the EU AI Act as a baseline, similar to how GDPR became a de facto global standard for data protection.
See EU AI Act compliance explained for CISOs and GRC leaders.
How Kovrr Approaches EU AI Act Compliance
Kovrr's EU AI Act Automated Compliance capability maps discovered AI assets to specific EU AI Act requirements, tracks conformity assessment status, and produces the technical documentation required under the regulation. See what data is required for EU AI Act compliance.
Related Terms
Full AI Visibility. Full Control. One Connected Platform.
Enterprise AI is expanding faster than most governance programs can track. Kovrr connects every AI signal across browser, endpoint, network, identity, and vendor systems into a single platform so security, governance, and risk teams work from the same evidence.


