Here you will find a concise overview of the EU AI Act{:target="_blank" rel="noopener"} as a practical guide to responsible AI governance and compliance with embedded links to the official EU AI Act text where appropriate.
As of March 2025, the EU AI Act's prohibited practice obligations are already enforceable, and 2 August 2026 marks the deadline for full compliance with high-risk AI system obligations for most organisations (Regulation (EU) 2024/1689{:target="_blank" rel="noopener"}).
Get your organization ready for the upcoming AI regulations around the globe that will guide the ethical development and deployment of these cutting-edge technologies. Equip your team with best practices to build solid AI governance structures, carry out thorough risk evaluations, maintain effective human oversight, and promote clarity while reducing exposure to legal challenges and fines.
To read the neatly arranged EU AI Act in full, visit our EU AI Act Resources, explore our EU AI Act guidebook for step-by-step compliance guidance, or find a personalized breakdown of the sections that apply to your organization with Whisperly's AI Act Compliance Checker.
In this guide:
- EU AI Act Summary in 5 Points
- What is the EU AI Act?
- The EU AI Act's Role in International AI Governance
- What does the EU AI Act Regulate?
- EU AI Act Timeline: Key Dates
- Key Stakeholders Under the EU AI Act
- EU AI Act penalties
- EU AI Act Compliance Oversight
- How can organizations comply with the EU AI Act?
- How can Whisperly support your AI governance?
EU AI Act Summary in 5 Points
TL;DRThe EU AI Act is a sweeping regulation with global reach. It classifies AI systems by risk level, assigns distinct obligations to every actor in the value chain, and phases enforcement between February 2025 and August 2027 (though the Digital Omnibus proposes adjustments to some deadlines; see our EU AI Act timeline for the latest schedule). Fines reach up to 35 million euros or 7% of global turnover for the most serious violations.
1. Global Regulatory Reach
The EU AI Act is the world's most comprehensive AI legislation with global impact, applying to all AI systems and general-purpose AI models (GPAIs) available in or affecting the EU market, regardless of provider location, similar to GDPR.
2. Risk-Based Framework
AI systems are categorized into four risk levels: unacceptable, high, limited, and minimal, with stringent obligations mostly for high-risk AI, including mandatory conformity assessment procedures, detailed documentation, transparency, human oversight, and cybersecurity.
3. Clear Obligations by Role
Providers, importers, distributors, deployers, and authorized representatives each have distinct responsibilities, such as system validation, documentation, market registration, operational oversight, and mandatory incident reporting.
4. EU AI Act Timeline
The EU AI Act entered into force on 1 August 2024, initiating a structured compliance timeline:
- Prohibitions against unacceptable-risk AI systems and general rules become enforceable from 2 February 2025;
- Governance measures, notifications, confidentiality, and GPAI obligations, along with most penalties, follow on 2 August 2025.
- Full enforcement covering all general compliance measures commences on 2 August 2026,
- culminating with mandatory compliance for high-risk AI systems (including pre-market assessments and system registrations) and existing GPAI models by 2 August 2027.
5. Significant Penalties for Non-compliance
Violations may incur fines up to 35 million euros or 7% of global turnover for prohibited practices and 15 million euros or 3% for high-risk system breaches, reinforcing the importance of rigorous compliance.
What is the EU AI Act?
TL;DRThe EU AI Act is a directly applicable regulation, not a directive, giving it uniform legal force across all 27 member states. It binds any organisation that places an AI system on the EU market or whose AI outputs affect people within the Union, regardless of corporate headquarters.
The European Union's Artificial Intelligence Act is the most ambitious and comprehensive regulatory framework for artificial intelligence in the world. The EU AI Act is a regulation, meaning it has uniform legal force across all EU member states without requiring national legislation to implement it, and establishes rules and obligations directly binding on organizations developing, deploying, or using AI systems within or impacting the EU market. This approach creates standardized AI governance and enforcement of AI standards across the entire European Union, providing clarity and legal certainty for businesses while safeguarding citizens' fundamental rights and interests through uniform, transparent, and enforceable rules.
The scope goes well beyond EU-headquartered entities. It employs the same "extraterritorial" reach popularized by the GDPR: regardless of where your organization has a corporate presence, if you place an AI system on the EU market or make it available for use within EU borders, you are bound by its requirements.
The EU AI Act's Role in International AI Governance: New Global Benchmark
TL;DREurope is not legislating in isolation. The EU AI Act is designed to serve as a reference model for AI regulation worldwide, much as the GDPR became the de facto global privacy standard. Its principles and frameworks give organisations the strategic compass they need.
By introducing the EU AI Act, Europe isn't just setting its own rules; it's aiming to ignite a global conversation on what responsible AI governance looks like. Designed as an example, this law not only creates a single European AI governance system but invites other countries to adopt its approach as they shape and align their own AI regulations. For more information on the development of the pioneering responsible AI development in Europe see here.
So what do we mean by "AI governance," anyway? Think of it as the strategic compass that guides an organization through every phase of AI's lifecycle, from development and deployment to ongoing oversight. It blends legal requirements, corporate policies, best-practice frameworks, and international standards into a cohesive toolkit, empowering everyone from engineers at the keyboard to executives in the boardroom to build, launch, and steer AI systems with both creativity and caution.
Two cornerstones hold up any sound AI governance regime: principles and frameworks.
Principles of AI Governance
Principles of AI governance are universally recognized standards intended to promote fairness, transparency, accountability, and respect for human rights in the development and use of artificial intelligence. Although the specific language used varies, prominent international guidelines consistently embody these fundamental ethical values and serve as widely accepted global benchmarks. Most notable examples are:
- OECD AI Principles
- The Fair Information Practice Principles (FIPPs)
- UNESCO's Recommendation on the Ethics of Artificial Intelligence
Frameworks for AI Governance
If principles set the destination, frameworks map out the route. They provide the step-by-step guidance organizations need to translate lofty values into concrete policies, processes, and controls. Although many frameworks share common goals, each is tailored to a particular context or industry:
- ISO 42001 (Artificial intelligence management systems)
- ISO/IEC 22989:2022 (AI concepts and terminology)
- NIST AI Risk Management Framework (U.S.)
For a deeper dive into how different jurisdictions are legislating AI, complete with status updates and key provisions, check out the IAPP's Global AI Legislation Tracker.
What does the EU AI Act Regulate?
TL;DRThe EU AI Act uses a four-tier, risk-based approach to classify AI systems: unacceptable, high, limited, and minimal risk. Obligations scale with the risk tier. Very few systems are fully exempt; even open-source models fall within scope once they power an EU-facing service.
Encompassing 180 recitals, 13 Annexes, and 113 articles, the EU AI Act adopts a risk-based framework to oversee every stage in the lifecycle of various AI systems. It adopts a four-tier, risk-based classification for AI systems:
a. Unacceptable risk: AI systems whose operation is deemed contrary to EU values and fundamental rights. These systems are prohibited.
b. High risk: AI systems that pose significant threats to health, safety or fundamental rights. This includes AI used as safety components in products covered by existing EU law (Annex I) and a defined list of critical use cases (Annex III{:target="_blank" rel="noopener"}).
c. Limited risk: AI systems that interact directly with humans or generate synthetic content such as chatbots, deepfake generators, or emotion recognition tools.
d. Minimal risk: The vast majority of AI applications such as spam filters, AI-enabled video games, basic recommendation engines, etc. considered to pose little to no risk.
Most obligations apply to high-risk AI systems, while limited-risk obligations mainly concern transparency. Minimal-risk AI systems are generally free from additional regulatory requirements, though providers are encouraged to follow voluntary codes of conduct and adhere to overarching EU principles on human oversight, non-discrimination, and data protection.
The EU AI Act casts a wide, extraterritorial net, meaning very few AI systems are wholly exempt. Those that fall outside the scope are:
- AI systems in private, non-commercial use (for example, hobby projects kept entirely offline), though even here, built-in transparency rules for "limited risk" systems (think chatbots or deepfake tools) may still apply.
- Open-source models released without commercial intent are not deemed "placed on the market," but once they power a service offered in the EU, that service becomes subject to the AI Act in the EU. Also, the exception applies only if they are not prohibited or classified as high-risk AI systems.
There are also three very limited exceptions:
- Scientific research & development: AI systems (and their outputs) that are specifically developed and put into service solely for scientific research and development.
- Testing before market placement: Systems used exclusively to test an AI system before it is placed on the market.
- Military/defense applications: AI developed or used exclusively for military, defense, or national security purposes.
Otherwise, the EU AI Act applies to all EU organizations as well as to organizations outside the EU that develop, deploy, place on the market, or use AI systems whose outputs affect individuals within the Union.
EU AI Act Timeline: Key Dates You Can't Miss
TL;DREnforcement unfolds in four stages. Prohibited-practice bans took effect on 2 February 2025. GPAI and governance obligations follow on 2 August 2025. Full high-risk system compliance is due by 2 August 2026, with existing GPAI models granted until 2 August 2027.
When did the EU AI Act enter into force?
On 12 July 2024, the EU AI Act was published in the Official Journal of the European Union and entered into force on 1 August 2024.
Compliance deadlines then stagger over a period of six to thirty-six months, beginning on 2 August 2024. Until the 2nd of February 2025, there were no mandatory obligations, but voluntary compliance was encouraged.
Phase 1: 2 February 2025
- Prohibition of AI systems posing unacceptable risks (e.g. social scoring)
- General provisions, definitions, and scope become enforceable
Phase 2: 2 August 2025
- Codes of practice for GPAI models
- Governance measures, notification obligations, and confidentiality requirements
- All GPAI-related requirements for providers of general-purpose AI models, including transparency, documentation, and copyright obligations
- Penalties enforceable for breaches of prohibited practices and GPAI non-compliance
Phase 3: 2 August 2026
This is the critical deadline. Full enforcement of the EU AI Act applies, including:
- All obligations for providers and deployers of high-risk AI systems
- Conformity assessment requirements
- Registration of high-risk AI systems in the EU database
- Post-market monitoring
- All remaining penalty provisions
- Obligations for importers, distributors, and authorized representatives
Phase 4: 2 August 2027
- High-risk AI systems embedded in products covered by EU harmonisation legislation listed in Annex I, Section A of the AI Act{:target="_blank" rel="noopener"} must also comply by this date
- GPAI models already on the market before 2 August 2025 must reach full compliance
For a complete walkthrough of each milestone with practical compliance steps, see our EU AI Act guidebook.
Key Stakeholders Under the EU AI Act
TL;DRThe EU AI Act assigns differentiated obligations to six categories of actors: providers, deployers, importers, distributors, authorized representatives, and GPAI providers. Your obligations depend on which role you occupy in the value chain for each specific AI system.
The EU AI Act assigns distinct obligations based on your role in the AI ecosystem. Below is an overview of each role and the responsibilities associated with it.
a. Providers (developers)
A provider is any entity that develops an AI system or a general-purpose AI model and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge.
b. Deployers (users of AI systems)
A deployer is any natural or legal person, public authority, agency, or other body using an AI system under its authority, except where the AI system is used in the course of a personal, non-professional activity.
c. Importers
An importer is any entity established in the EU that makes available on the EU market an AI system from a provider located outside the EU.
d. Distributors
A distributor is any entity in the supply chain, other than the provider or importer, that makes an AI system available on the EU market.
e. Authorized Representatives
An authorized representative is an entity established in the EU, mandated by a non-EU provider to act on its behalf for regulatory purposes.
f. Product manufacturers
A product manufacturer is an entity that places a product on the market with an integrated AI system under its own name or trademark.
High-Risk AI Systems: Obligations
a. What are high-risk AI systems?
High-risk AI systems are defined by the EU AI Act in two categories:
Category 1: Safety components and regulated products (Annex I)
AI systems that serve as safety components of products already regulated under EU harmonisation legislation listed in Annex I, Section A of the AI Act or that are themselves such products. These include AI used in, among others, machinery, toys, lifts, medical devices, motor vehicles, and civil aviation.
Category 2: Critical use cases (Annex III)
AI systems that fall under one of eight critical areas listed in Annex III:
- 1.Biometric identification and categorisation
- 2.Management and operation of critical infrastructure
- 3.Education and vocational training
- 4.Employment, worker management, and access to self-employment
- 5.Access to essential private and public services
- 6.Law enforcement
- 7.Migration, asylum, and border control management
- 8.Administration of justice and democratic processes
b. The safety filter: when a high-risk classification may not apply
Not every system in these categories automatically triggers full high-risk obligations. An AI system may be exempt from being classified as high-risk if it meets at least one of the following conditions:
- The AI system is developed to execute a strictly limited, procedural task.
- The AI system is designed solely to enhance or verify the outcome of a previously completed human task.
- The AI system is built to identify patterns or deviations in human decision-making and is explicitly not intended to replace or substantially influence prior human review processes.
- The AI system performs exclusively preparatory tasks supporting assessments related to use cases specified in Annex III of the EU AI Act.
c. High-level overview of the obligations of providers of High-Risk systems
Here are some of the core obligations placed on providers of high-risk AI systems under the EU AI Act:
- Pre-market conformity assessment: Before placing a high-risk AI system on the EU market or putting it into service, you must demonstrate compliance with the Act's mandatory requirements via an appropriate conformity assessment (internal or third-party).
- Risk and quality management systems: You must establish and maintain documented frameworks for identifying, evaluating and mitigating risks throughout the AI system's lifecycle, and integrate these into a formal quality management system.
- Data governance: Training, validation and test datasets must be relevant, representative, free of bias and subject to ongoing quality control.
- Technical documentation & record-keeping: Keep detailed documentation of system design, development processes, data sources, performance metrics and decisions made during risk assessments, so that national authorities can verify compliance.
- Transparency & user information: Provide clear instructions for use, label outputs (e.g. "This result was generated by an AI system") and supply any information necessary for deployers to understand system capabilities and limitations.
- Human oversight: Design and implement measures (e.g. stop buttons, override mechanisms) allowing human operators to intervene in or deactivate the AI system when necessary.
- Accuracy, resilience & cybersecurity: Build systems to achieve a high level of accuracy and resilience against manipulation or attacks, and implement safeguards against unauthorized access, data corruption or other cybersecurity threats.
- Registration & post-market monitoring: Register each high-risk AI system (and, for public-sector uses, the deploying entity) in the EU database before deployment. Maintain ongoing surveillance of real-world performance, report serious incidents or breaches, and cooperate with market surveillance authorities.
d. High-level overview of the obligations of deployers of High-Risk AI systems
The obligations of deployers of high-risk systems complement and differ from providers' duties. While providers focus on design-phase requirements (e.g., risk-management systems, data governance, technical documentation, conformity assessments and post-market monitoring), deployers, by contrast, are responsible for operational compliance. This includes using the system correctly, supervising it in practice, and feeding back performance data and incidents to providers and regulators.
Here are some of the core obligations placed on deployers of high-risk AI systems under the EU AI Act:
- Use as instructed: Adhere strictly to all technical and organizational guidelines provided by the system's developer.
- Assign competent human oversight: Appoint qualified staff with the necessary training and authority to supervise the AI's functioning and step in when required.
- Validate input data: Any data you supply to the system must be appropriate, accurate, and reflective of its intended use case.
- Monitor operation and report issues: Keep a close watch on the AI's performance; if you detect potential hazards or serious malfunctions, halt its use immediately and inform both the provider (or distributor/importer) and the designated market surveillance authority.
- Retain system logs: Maintain all automatically generated logs under your control for a minimum of six months (or longer if mandated by EU or national law).
- Inform employees and representatives: Prior to implementation in the workplace, notify affected staff members and their representatives in accordance with relevant labor-law procedures.
- Register when required: Confirm that any high-risk AI you deploy is recorded in the EU database; if it isn't, you must refrain from using it and alert the provider or distributor.
- Support data-protection impact assessments: Use the transparency information supplied by the provider to complete any required GDPR Data Protection Impact Assessment.
- Comply with specialized law-enforcement rules: For post-remote biometric identification, secure timely judicial or administrative authorization, log each use, and restrict processing solely to the purposes approved.
- Notify data subjects: When decisions affecting individuals are made or assisted by the AI, inform those individuals that a high-risk system is in use.
- Cooperate with authorities: Provide requested information or implement corrective measures at the behest of market surveillance or data protection authorities.
Providers of GPAI
Here is a concise overview of the main responsibilities of providers of general-purpose AI models under the EU AI Act:
- Comprehensive Documentation: Keep detailed records of your model's design, training processes, evaluation outcomes and safety checks, and make these available to any authorities upon request.
- Transparency to Integrators: Downstream developers must receive all necessary technical details, including architecture descriptions, performance metrics and known limitations, so they can deploy the model compliantly.
- Data and IP Compliance: Establish and enforce policies to respect copyright and data-protection rules for any third-party material used in model development or fine-tuning.
- Training-Data Disclosure: Publish a clear summary of the types and sources of data used to train your model, enabling users to assess potential biases or gaps.
- Change-Notification: Notify the designated oversight body whenever you make significant updates, such as altering the model's intended purpose or performing large-scale retraining, that could affect its risk profile.
- Regulatory Cooperation: Respond promptly to any inquiries from EU or national authorities, supplying additional information or adjustments as needed during supervision or investigations.
Fully open-source models with all parameters and usage details publicly available are generally exempt from these requirements unless they pose a systemic risk.
What are GPAIs with Systemic Risk?
Under the EU AI Act, General-Purpose AI (GPAI) systems are versatile AI models capable of a broad range of tasks without being specifically designed for one particular application (for example, foundation models like ChatGPT, GPT-4, or large multimodal AI models).
A GPAI with systemic risk refers to a subset of these general-purpose models that pose significant potential threats at a societal level, such as:
- Undermining democracy (through disinformation or manipulation)
- Violating fundamental rights (privacy, equality, non-discrimination)
- Affecting public health, safety, or the environment on a large scale
- Enabling harmful or malicious activities due to their broad capabilities and wide adoption
These are high-impact AI models whose misuse or malfunction could cause substantial societal harm or disruption.
Providers of GPAIs with systemic risks have obligations beyond those applicable to general-purpose AI models without such systemic risks.
EU AI Act penalties
TL;DRFines follow a three-tier structure modelled on GDPR but with steeper ceilings. Prohibited-practice violations attract up to 35 million euros or 7% of global turnover. High-risk breaches cap at 15 million euros or 3%. Providing false information to authorities can cost up to 7.5 million euros or 1.5%. SMEs pay the lower of the two thresholds.
Penalties for non-compliance with the EU AI Act take effect upon its entry into force on August 1, 2024, but are phased in over two years, with full enforcement by August 2026 (Article 99{:target="_blank" rel="noopener"}).
- Prohibited AI practices (e.g., social scoring): fines of up to 35 million euros or 7% of global annual turnover, whichever is higher.
- Breaches of general and high/limited-risk requirements (e.g., data quality, transparency, human oversight): up to 15 million euros or 3% of global turnover, whichever is higher.
- False or misleading information to competent authorities: up to 7.5 million euros or 1.5% of global turnover, whichever is higher.
- SME proportionality: SMEs still face the same caps, but pay the lower monetary amount or percentage (e.g., if 3% of turnover is 150,000 euros, that is the fine rather than the 15 million euro cap).
- EU institutions and bodies: reduced penalties of up to 1.5 million euros for prohibited AI breaches and up to 750,000 euros for other compliance failures.
- General-Purpose AI (GPAI) providers: subject to fines of up to 15 million euros or 3% of turnover for non-compliance with their specific obligations.
This tiered system, modelled on GDPR but with steeper caps, underscores the EU's commitment to enforcing safe, transparent, and accountable AI by August 2026.
For a more detailed breakdown of penalty provisions, see our article on EU AI Act penalties.
Penalties are not the sole motivation for complying with the EU AI Act; adherence also offers substantial strategic and operational advantages. Compliance enhances corporate credibility by demonstrating a clear commitment to ethical practices, transparency, and responsible AI deployment.
It can also serve as a differentiator in the market, positioning the organization as a trustworthy and forward-thinking leader. Proactively incorporating transparency measures, human oversight, and comprehensive documentation from the outset helps to avoid costly system redesigns, legal liabilities, and reputational damage, resulting in long-term cost savings that exceed the potential financial penalties.
EU AI Act Compliance Oversight
TL;DRTwo types of bodies keep the system honest. Notified Bodies conduct pre-market conformity assessments, verify technical documentation, and issue CE-marking certificates. Market Surveillance Authorities monitor AI systems already in use, investigate incidents, and can order withdrawals or impose fines.
To confirm that high-risk AI systems meet strict standards and remain compliant once in the market, the EU AI Act appoints dedicated bodies for conformity assessment and ongoing surveillance.
Notified Body (Conformity Assessment Body)
A Notified Body is an independent organization officially designated by an EU Member State. Its role is to verify that high-risk AI systems comply with the EU AI Act's strict requirements. Before a high-risk system can display the CE marking and enter the market, the Notified Body reviews its technical documentation, audits the provider's risk management processes, tests the system against applicable standards and issues a conformity certificate. It also conducts regular checks and audits so that, once in use, the AI system continues to meet safety, transparency and accountability requirements.
Market Surveillance Authority
Each Member State appoints a Market Surveillance Authority to oversee AI systems already available or in use within its territory. These national regulators have the power to inspect products, request documentation and investigate serious incidents or cases of non-compliance. If an AI system is found to violate the Act, whether through unsafe operation, missing documentation or prohibited functions, the Market Surveillance Authority can require corrective measures such as recalling the system, withdrawing it from the market or imposing fines and penalties. Their work keeps all AI systems in the EU safe and lawful.
How can organizations comply with the EU AI Act?
TL;DRCompliance follows a nine-step lifecycle: establish governance, determine your role for each AI system, classify risk, implement mitigation strategies, align with data protection laws, maintain thorough documentation via an AI inventory, provide user transparency, embed human oversight, and monitor continuously after deployment.
Your specific obligations under the EU AI Act will depend on your organization's role in the AI value chain and the classification of the AI systems you manage. There is, however, a consistent set of best practices that organizations can adopt to support compliance across the entire AI system lifecycle. The following provides a high-level overview of the key steps that should be implemented to align with the Act's requirements and maintain responsible, legally compliant AI operations.
Step 1: Establish a Governance Framework
Before your organization develops or deploys AI systems, it should establish a comprehensive yet adaptable governance framework aligned with compliance obligations and responsible AI objectives.
Essential elements of this framework include:
- Clearly assigned employee roles and responsibilities for effective oversight and accountability.
- Drafting and publishing an AI policy based on recognized ethical standards to guide responsible AI decisions and deployments.
- Implementing procedures for continuous monitoring, evaluation, and reporting throughout each AI system's lifecycle.
- Embedding human oversight at all stages of AI design and operation.
Step 2: Determine Your Role concerning each AI system
Clarify whether you are:
- A provider of an AI system, a provider of a general-purpose AI (GPAI) system, or a provider of GPAI systems identified with systemic risks
- A deployer of an AI system
- Distributor, importer, or authorized representative.
Step 3: Classify Your AI System and undertake a Risk Assessment
Clearly define and document the intended purposes, contexts, and uses of each AI system your organization handles. Based on these defined use cases, classify each AI system according to the EU AI Act's categories:
- Prohibited Risk
- High-risk/Low risk/Minimal risk
- General-purpose (GPAI)
- GPAI with systemic risk
Once AI systems have been classified, organizations should conduct detailed risk assessments for each system and its intended use cases. Prohibited practices must be identified and eliminated from operation. As part of the assessment process, organizations should identify potential risks, including bias, discrimination, privacy violations, safety concerns, and environmental impact.
Review and apply any specific transparency obligations associated with each classification. Finally, clear and accessible information must be prepared to inform users and downstream stakeholders about the AI system's functions, limitations, and potential risks.
Step 4: Implement Risk Management Strategies
Organizations should develop and document concrete plans and measures to mitigate the risks identified during the assessment phase. These mitigation strategies must be tailored to the specific nature and context of each AI system.
For example, in the case of recruitment software with potential bias, appropriate measures may include implementing debiasing techniques, maintaining human oversight in decision-making, conducting regular audits, and establishing clear procedures for handling complaints.
Step 5: Data Protection Compliance
Align your AI practices with applicable data protection laws (e.g., GDPR) by implementing technical and organizational safeguards, clearly defining and documenting your legal basis for processing personal data, performing Data Protection Impact Assessments (DPIAs) where required, and establishing mechanisms for meaningful human review, especially in scenarios involving automated decision-making.
Step 6: Maintain Comprehensive Records
Organizations should create detailed technical documentation and maintain comprehensive records covering all aspects of their AI systems. A structured AI inventory serves as the foundation for this record-keeping. This includes information on system architecture, datasets used, results of risk assessments, implemented mitigation measures, and ongoing performance monitoring. Proper documentation supports transparency, accountability, and regulatory compliance, while also facilitating internal reviews and external audits.
Step 7: Provide User Transparency
Organizations must clearly communicate to users how their AI systems function, including the systems' capabilities and any associated risks. This involves providing user guidance and disclosures that are both easily understandable and readily accessible, so that individuals interacting with the AI are well-informed and able to use the technology responsibly and effectively.
Step 8: Establish Human Oversight
- Implement processes for appropriate human involvement, particularly for high-risk AI systems.
- Guarantee human capability to intervene, supervise, and explain critical decisions or actions taken by AI systems.
Step 9: Continuous Monitoring and Adjustments
- After deployment, continuously monitor and evaluate AI system performance.
- Adjust processes, update risk assessments, and refine mitigation measures regularly to maintain compliance.
How can Whisperly support your AI governance and compliance journey?
Whisperly AI Governance Solution
Managing AI governance and regulatory compliance is often complex. To support your organization in keeping pace with evolving AI laws such as the EU AI Act, Whisperly offers:
- AI Compliance Knowledge Center
- AI Registry with AI-related risks and best practices for risk mitigation
- Insights into dozens of AI models
- Synchronization with your Data Privacy governance
Whisperly AI Governance Consulting
For organizations in need of thorough guidance, our team of governance professionals offers tailored solutions to create and execute AI governance frameworks that reflect your unique context and industry requirements. Using our governance-as-a-service model, you'll receive strategic support so that your AI efforts are responsibly and effectively governed from the outset.
Book a demo to learn how Whisperly can help your organization navigate the EU AI Act with confidence.
Related reading: Explore the broader policy context in EU AI Act Regulation: Decoding the Debate, and see a sector deep dive in AI in Clinical Trials & Compliance with the EU AI Act.
Further Reading on Whisperly

Reviewed by: Tamara Zavisic, AI Governance Specialist