Skip to content

EU AI Act

Complying with the EU AI Act

The EU AI Act requires providers and deployers of AI to classify, manage risk and document, with obligations phasing in between 2025 and 2027.

Book an introductory call
  • AI governance
  • Governance, risk & compliance

When the AI Act applies to you

The AI Act’s obligations phase in over time: prohibited practices since February 2025, obligations for providers of general-purpose AI models since August 2025, and most high-risk AI requirements from August 2026.

Many organisations don’t yet know which role (provider or deployer) they hold, or what that concretely means.

  • Your organisation develops, procures or uses AI applications

  • It’s unclear whether an application falls under a prohibited or high-risk category

  • A customer or regulator asks about your AI Act compliance

What a missed classification costs

AI Act fines can reach €35 million or 7% of global annual turnover, depending on the violation.

Non-compliance affects not just finances, but also management’s accountability for how AI is deployed.

What the law asks of your AI applications

The AI Act requires classification of every AI application, appropriate risk management, and documentation that shows you’re in control.

  • Classification of AI applications by risk level

  • Appropriate measures for high-risk applications: risk management, documentation, human oversight

  • Transparency towards users where required

  • Additional obligations for providers of general-purpose AI models

  • A FRIA for certain deployers of high-risk AI

From role assessment to embedded compliance

Vedeum translates the legal text into a concrete plan for your organisation: see also our approach on the AI governance page.

  1. Role and applicability

    We determine which role your organisation holds and which obligations follow from it.

  2. Classification

    We classify your AI applications under the law’s risk categories.

  3. Risk management

    We set up risk management, documentation and oversight, matched to the risk level.

  4. Embedding

    We help embed compliance into policy and periodic review.

Book a no-obligation introductory call

Tell us where your organisation stands. We will think through the first steps with you.

Book an introductory call