EU AI Act
Risk-based EU framework governing AI systems and general-purpose AI, with phased obligations for providers, deployers and other actors.
Risk-based EU framework governing AI systems and general-purpose AI, with phased obligations for providers, deployers and other actors.
Applies according to the AI Act's territorial, actor and system scope. Organisations should determine role, system classification and applicable transition dates for each use case.
Enforced through national competent authorities and the European Commission AI Office within their respective competences.
Penalty context: Administrative fines can apply for infringements; exact exposure depends on the violated provision and organisation context. Verify against the Act and current Commission guidance.
Risk-based EU framework governing AI systems and general-purpose AI, with phased obligations for providers, deployers and other actors.
The European Commission AI Office and national authorities begin enforcing applicable AI Act rules; Article 50 transparency obligations also apply from this date.
Design human oversight appropriate to the system's intended use, foreseeable misuse and consequence severity.
Actor: providers/deployers · Domain: human oversight
Evidence: Oversight procedures, intervention authority, training and logs.
Maintain technical and operational records needed to reconstruct material AI behaviour and decisions where applicable.
Actor: providers/deployers · Domain: traceability
Evidence: System logs, version history, event records and retention schedule.
Classify relevant AI systems against prohibited, high-risk, transparency and other applicable categories.
Actor: providers/deployers · Domain: risk classification
Evidence: Documented classification rationale and periodic reassessment.
Determine and document the organisation's role for each AI system and model before assigning controls.
Actor: providers/deployers/importers/distributors · Domain: governance
Evidence: Role register, system inventory, contracts and responsibility matrix.
Provide required disclosures when people interact with AI or encounter certain AI-generated/manipulated content.
Actor: providers/deployers · Domain: transparency
Evidence: Disclosure designs, machine-readable marking where applicable, content labelling evidence.
Cybatar's mapping is designed for AI governance and assurance work. Legal interpretation remains anchored to the current primary text and competent authority guidance.
Open European Commission source