> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# EU AI Act

> Comply with the world's first comprehensive AI regulation — risk classification, transparency, and governance.

The EU AI Act (Regulation 2024/1689) is the world's first comprehensive artificial intelligence regulation. It establishes a risk-based framework that classifies AI systems into risk tiers and imposes obligations proportional to the level of risk.

<Note>
  The EU AI Act reaches full application on **August 2, 2026**, with some provisions already in effect. High-risk AI system obligations are expected by late 2027. Penalties can reach **7% of global annual turnover**.
</Note>

## Who needs EU AI Act compliance?

<CardGroup cols={2}>
  <Card title="AI providers" icon="code">
    Organizations that develop or place AI systems on the EU market, regardless of where they are based.
  </Card>

  <Card title="AI deployers" icon="building">
    Organizations that use AI systems within the EU for business purposes.
  </Card>
</CardGroup>

## Risk classification tiers

| Tier             | Description              | Examples                                                                      |
| ---------------- | ------------------------ | ----------------------------------------------------------------------------- |
| **Unacceptable** | Banned AI practices      | Social scoring, manipulation, real-time biometric identification              |
| **High-risk**    | Strict requirements      | Credit scoring, employment decisions, healthcare diagnostics, law enforcement |
| **Limited risk** | Transparency obligations | Chatbots, emotion recognition, deepfake generators                            |
| **Minimal risk** | No specific requirements | Spam filters, AI-powered games                                                |

## Key requirements for high-risk AI

* **Risk management system** throughout the AI lifecycle
* **Data governance** for training, validation, and testing datasets
* **Technical documentation** and record-keeping
* **Transparency** — users must be informed they are interacting with AI
* **Human oversight** mechanisms
* **Accuracy, robustness, and cybersecurity** requirements
* **Registration** in the EU AI database

## How DSALTA helps

* **EU AI Act controls** mapped to risk tier requirements
* **AI system inventory** and classification
* **Risk assessment** tools for AI-specific risks
* **Documentation templates** for transparency and governance
* **Cross-framework mapping** — aligns with ISO 42001, NIST AI RMF, DORA, and NIS 2

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Does the EU AI Act apply to US companies?" icon="flag-usa">
    Yes, if your AI systems are placed on the EU market or used in the EU. The regulation has extraterritorial reach similar to GDPR.
  </Accordion>

  <Accordion title="What are the penalties?" icon="dollar-sign">
    Up to 7% of global annual turnover for prohibited AI practices, 3% for high-risk violations, and 1.5% for providing incorrect information.
  </Accordion>

  <Accordion title="How does it relate to NIST AI RMF?" icon="diagram-project">
    Both use risk-based approaches. Implementing NIST AI RMF provides a strong operational foundation for EU AI Act compliance.
  </Accordion>
</AccordionGroup>

## How DSALTA automates this

**203** of DSALTA's automated checks contribute evidence to this framework, drawn from **70** integrations. Browse them in the [Compliance Tests](/tests/overview) catalog. They are linked through the controls each check satisfies, so a single check usually contributes to several frameworks at once — the count is not a list of checks unique to this one.

## Related pages

* [ISO 42001](/frameworks/iso42001/overview)
* [NIST AI RMF](/frameworks/nist-ai-rmf/overview)
