The EU AI Act marks the world’s first comprehensive legal framework for artificial intelligence. Adopted in 2024, establishes clear rules that apply to anyone providing, importing, distributing, or using AI systems in the EU market, regardless of where your company is located.
But compliance doesn’t stop there. Organizations working must also align with GDPR (for data protection), ISO 42001 (for AI management systems), and a web of sector-specific rules across finance, healthcare, and beyond. Understanding these regulations and how they interact is essential for effective AI governance.
Complying with the EU AI Act: A risk based framework
The AI Act takes a risk-based approach. There’s four risk categories, with requirements increasing based on potential harm. This approach means your compliance obligations depend entirely on what your AI system does and how it’s used:
Risk classification under the EU AI Act

- Unacceptable Risk: These AI systems are banned outright because they pose fundamental threats to human rights and safety.
Example: Social scoring systems or real-time remote biometric identification in public spaces for law enforcement. - High-Risk AI: These systems require strict compliance based on their potential impact on safety and fundamental rights.
Example: Systems used in critical areas like employment, education, law enforcement, and critical infrastructure. - Limited Risk (Transparency): These systems require transparency obligations like disclosure of AI interaction.
Example: AI systems like chatbots and deepfakes. - Minimal Risk: All other AI systems face no specific legal requirements but can voluntarily adopt codes of conduct.
Example: Most traditional business applications like recommendation engines, inventory optimization, and basic analytics tools.
Roles under the EU AI Act
The AI Act defines specific roles throughout the AI supply chain. Your obligations depend on your role, not your intentions. Keep in mind; you may wear multiple hats, acting as both provider and deployer.
Provider
You’re a provider if you develop an AI system or have one developed for you to place on the market under your name or trademark. This includes:
- Training (foundation) models from scratch.
- Substantially modifying open-source models for commercial use.
- Developing custom AI systems for your own organization
Provider responsibilities include: ensuring compliance, conducting conformity assessments, maintaining technical documentation, and registering high-risk systems in the EU database.
User
You’re a user if you use an AI system for personal, non-professional purposes. This role has minimal obligations under the Act.
Deployer
You’re a deployer if you use an AI system for its intended purpose in a professional context. Most organizations using AI systems are deployers. This includes:
- Using commercial AI services for business purposes.
- Implementing AI systems developed by third parties.
- Operating AI systems within your organization.
Deployer responsibilities include: using systems according to instructions, implementing human oversight, monitoring performance, and conducting impact assessments for high-risk systems.
Distributor
You’re a distributor if you make AI systems available on the market without being the provider or importer. This typically applies to:
- Resellers of AI software or services.
- System integrators packaging AI components.
- Consultants implementing AI solutions for clients.
Distributor responsibilities include: verifying CE marking and compliance documentation before market availability, monitoring systems for conformity issues, taking corrective actions such as withdrawal or recall when non-compliance is detected.
Make sure you know you’re role. If you’re buying AI services (like using OpenAI’s API), you’re usually a deployer, not a provider. If you’re training your own AI, or modifying ones, you are a provider with much heavier obligations. When in doubt, assume the more restrictive role. More often than not, you wear multiple hats.
Complying with the GDPR
Any AI system processing personal data must also comply with General Data Protection Regulation (GDPR). If you are processing personal data with your AI systems both the AI Act and the GDPR will apply. Key intersection points include:
Automated Decision-Making
AI systems that make decisions without human intervention that create legal or significant effects on individuals require:
- Explicit consent or legitimate interest basis.
- Right to human review of automated decisions.
- Information about decision logic and consequences.
Data Subject Rights
- Individuals maintain rights to access, rectify, delete, and port their data, even when used in AI systems.
- Organizations must design AI systems to support these rights.
Privacy by Design
- AI systems processing personal data must implement data protection measures from the design phase, including data minimization, purpose limitation, and security safeguards.
Legal Basis for Processing
- The GDPR requires you to have a legal basis for processing (e.g. consent or a legal obligation). Without a legal basis for processing your AI application is not legitimate, regardless whether you have followed the requirements under the AI Act.
Purpose Limitation
- Under the GDPR you collect data for specific purposes. The legitimate use of the personal data is limited to these purposes. If you repurpose personal data (e.g. for training AI models), make sure that you have a legal basis for doing so or that the new purpose is compatible with the original purpose.
Copyright and Intellectual Property
- Copyright and other intellectual property limit the ability to use copyrighted material for model training purposes. Furthermore, the use of generative AI may infringe on intellectual property rights if the output of the model is very closely resembeles the intellectual property of others. In your governance ensure that training data is vetted before use and that model output can be reviewed to determine any potential copyright infringements.
Complying with other AI regulations & standards
European regulations
Beyond the AI Act and GDPR, several EU regulations create additional obligations for AI systems:
- Digital Services Act (DSA): Content moderation algorithms, risk assessments for large platforms.
- Digital Markets Act (DMA): Interoperability requirements affecting AI services from gatekeepers.
- Digital Operational Resilience Act (DORA): ICT risk management including AI systems in financial services.
Global AI regulations
While the EU leads with comprehensive legislation, other regions are developing different approaches:
- UK: Sector-specific guidance through existing regulators (FCA, ICO), no new AI-specific laws.
- US: Executive Order 14110, NIST AI Risk Management Framework, sector-specific rules and a patchwork of state regulations (California, New York).
- China: Algorithmic Recommendation Provisions, Deep Synthesis Provisions, draft AI measures.
- Singapore: Model AI Governance Framework, Directive on Automated Decision-Making.
For European organizations operating globally, this creates complexity. The same customer service chatbot may need EU transparency disclosures, California bias audits, and UK financial services algorithmic reviews.
Meeting the ISO 42001 (AI Management Systems) standard
This international standard provides a framework for managing AI throughout its lifecycle. While voluntary, ISO 42001 offers practical guidance for implementing AI Act requirements through:
- Systematic risk management processes.
- Documentation and record-keeping standards.
- Continuous improvement methodologies.
- Integration with existing management systems.
Learn more about ISO 420001 and how organizations can meet the standard.
Building an AI Regulation compliance strategy
Effective AI regulation compliance requires understanding how these overlapping frameworks apply to your specific AI systems. The key steps include:
- System Inventory: Catalog all AI systems in your organization
- Risk Classification: Determine each system’s risk level under the AI Act
- Role Identification: Clarify whether you’re a provider, deployer, or distributor for each system
- Gap Analysis: Compare current practice against regulatory requirements
- Implementation Planning: Develop compliance roadmaps prioritized by risk and regulatory deadlines
The regulatory landscape for AI continues evolving. Staying compliant requires ongoing monitoring of new requirements, guidance documents, and enforcement actions from regulators across the EU.
Learn more: Get the AI Governance & Control Framework Whitepaper

This discussion is just one section of our broader framework. To explore the full picture, including practical strategies for implementing AI governance without slowing innovation, download the our latest whitepaper. It covers all essential topics across the AI lifecycle and offers a clear roadmap for compliance and risk management.
- Define ownership and responsibilities
- Establish oversight and controls
- Embed governance across the AI lifecycle


