REGULATION

EU AI Act

Regulation (EU) 2024/1689. The world's first comprehensive AI law. Vigilens automates classification, maps controls to obligations, collects evidence continuously, and generates audit-ready governance packs inside your CI/CD pipeline.

Type Regulation
Jurisdiction European Union
Status In force (1 Aug 2024)
Vigilens coverage Full

What it requires

The EU AI Act establishes a risk-based framework for AI systems placed on the EU market or affecting EU residents. High-risk systems (Annex III) must satisfy obligations covering risk management, data governance, technical documentation, transparency, human oversight, accuracy, robustness, and cybersecurity before they can be deployed.

Key obligations for high-risk AI

  • Article 9: Risk management system maintained throughout the AI system lifecycle
  • Article 10: Data governance and management practices for training, validation, and testing data
  • Article 11: Technical documentation drawn up before the system is placed on the market
  • Article 12: Record-keeping enabling automatic logging of events
  • Article 13: Transparency and provision of information to deployers
  • Article 14: Human oversight measures designed into the system
  • Article 15: Accuracy, robustness, and cybersecurity requirements
  • Article 17: Quality management system covering all of the above
  • Article 26: Obligations on deployers of high-risk AI systems
  • Article 27: Fundamental rights impact assessment for certain deployers

Annex IV: Technical documentation

High-risk systems must maintain comprehensive technical documentation that demonstrates conformity with the requirements. This includes a general description of the AI system, detailed development process information, monitoring and functioning details, and a description of the risk management system.

How Vigilens automates it

Vigilens encodes the EU AI Act as executable rules, not checklist items. Every article and annex obligation becomes a control with an acceptance specification that defines exactly what evidence is needed and how it is evaluated.

  • Automatic risk classification via the free EU AI Act Classifier (Annex III mapping)
  • Controls auto-assigned based on classification result (high-risk, limited-risk, GPAI)
  • Evidence pulled continuously from GitHub, GitLab, Jira, Confluence, Datadog, MLflow
  • Deterministic verdicts computed from acceptance specs (no LLM decides pass/fail)
  • Governance pack generated with full article-level traceability

Key compliance dates

The EU AI Act phases in gradually under the Digital Omnibus on AI timeline:

2 Feb 2025Prohibited practices (Article 5) apply
2 Aug 2025GPAI model obligations apply
2 Dec 2027Annex III high-risk system obligations apply
2 Aug 2028Annex I high-risk system obligations apply

Related frameworks

EU AI Act compliance is strongest when combined with ISO 42001 (AI management system), ISO 27001 (information security), and GDPR (data protection). Vigilens maps controls across all four, de-duplicating shared obligations.

LIVE IN VIGILENS

Coverage

Full Annex III classification, Articles 9-15, 17, 26-27, 50, 62, 72, 79. Annex IV technical documentation template. FRIA support for deployers.

Articles covered

Art. 9, 10, 11, 12, 13, 14, 15, 17, 26, 27, 50, 62, 72, 79

Start automating EU AI Act compliance.

Classify your AI system, map controls, collect evidence, generate your governance pack.

Classify your AI → Start free