EU AI Act Compliance
& AI Governance

The EU AI Act is now in force. Is your AI compliant? Digital Colliers provides end-to-end AI governance support, from risk assessment to ongoing monitoring.

What Is the EU AI Act?

The EU AI Act is the world’s first comprehensive artificial intelligence regulation. It establishes a risk-based legal framework for AI systems across the European Union. The regulation applies to any company deploying AI that affects EU citizens, including non-EU companies. As AI regulation in Europe evolves, organisations must understand their obligations and act now to ensure compliance.

Key Compliance Deadlines

A staged rollout from prohibitions to full enforcement. Plan your compliance roadmap around the dates that matter for your AI systems.

  1. Feb 2025 Phase 01 · In effect

    Prohibited AI practices banned: social scoring, manipulative AI and real-time biometric surveillance.

  2. Aug 2025 Phase 02 · GPAI rules

    GPAI rules take effect: transparency, documentation and copyright compliance for general-purpose AI providers.

  3. Aug 2026 Phase 03 · High-risk

    High-risk AI obligations begin: conformity assessments, risk management and human oversight requirements.

  4. Aug 2027 Phase 04 · Full enforcement

    Full enforcement: all remaining provisions apply, including penalties for non-compliance.

The Four Risk Categories

The EU AI Act applies a risk-based approach. Where your system sits in this hierarchy determines what, if anything, you need to do.

  • Tier 01

    Unacceptable Risk

    Examples

    Social scoring, manipulative AI, real-time biometric surveillance in public spaces.

    Requirements

    Banned: these AI practices are prohibited under the EU AI Act.

    Prohibited
  • Tier 02

    High Risk

    Examples

    HR recruitment, credit scoring, education assessment, law enforcement, healthcare diagnostics, critical infrastructure.

    Requirements

    Strict obligations: conformity assessments, risk management systems, human oversight, data governance and technical documentation.

    Strict obligations
  • Tier 03

    Limited Risk

    Examples

    Chatbots, emotion recognition systems, deepfake generators.

    Requirements

    Transparency obligations: users must be informed they are interacting with AI.

    Transparency
  • Tier 04

    Minimal Risk

    Examples

    AI-powered spam filters, AI in video games, inventory management systems.

    Requirements

    No specific obligations: voluntary codes of conduct encouraged.

    Voluntary

How We Help You Achieve Compliance

Digital Colliers provides end-to-end EU AI Act compliance support. From initial risk assessment to ongoing governance, we help you navigate every requirement.

  • AI System Inventory & Classification

    Audit all AI systems across your organisation and classify them against EU AI Act risk categories. Identify which systems require conformity assessments and prioritise compliance efforts.

  • Risk Assessment & Gap Analysis

    Structured AI risk assessment against EU AI Act requirements. Identify gaps in documentation, human oversight and data governance. Receive a clear remediation roadmap.

  • AI Governance Framework Setup

    Build your internal AI governance framework: policies, roles, approval workflows and monitoring processes. Establish clear accountability for AI compliance across your organisation.

  • Technical Documentation

    Prepare comprehensive technical documentation for high-risk AI systems: risk management plans, data quality protocols, testing procedures and human oversight documentation.

  • Conformity Assessment Support

    Guide you through the conformity assessment process: self-assessment for most systems, third-party assessment for biometric and critical-infrastructure AI.

  • Ongoing Monitoring & Audit

    Continuous monitoring, periodic audits and regulatory change tracking. AI systems must remain compliant as they evolve, and we help you maintain compliance over time.

Who Needs to Comply?

The EU AI Act does not just regulate vendors. If your AI touches EU citizens, you are in scope, no matter where you sit on the supply chain.

AI Providers

Companies that develop and place AI systems on the market. Providers bear the primary compliance burden, including conformity assessments and technical documentation.

AI Deployers

Companies that use AI systems in their operations. Deployers must ensure proper human oversight, monitor system performance and maintain usage logs.

Importers & Distributors

Companies that bring AI systems into the EU market. They must verify that providers have completed conformity assessments and that systems carry proper CE marking.

Non-EU Companies

Any company whose AI system affects EU citizens, regardless of where the company is based. The EU AI Act has extraterritorial scope, similar to GDPR.

Industries Most Affected

01 · Financial Services

Financial Services

Credit scoring, fraud detection and algorithmic trading all fall under high-risk classification. AI compliance for financial services is critical.

02 · Healthcare

Healthcare

AI-powered diagnostics, treatment recommendations and patient triage systems require rigorous conformity assessments and human oversight.

03 · Manufacturing

Manufacturing

Safety-critical AI in production lines, quality control and predictive maintenance falls under high-risk obligations when affecting worker safety.

04 · HR & Recruitment

HR & Recruitment

AI used in hiring, performance evaluation and workforce management is explicitly classified as high-risk under the EU AI Act.

Why Digital Colliers for AI Compliance?

Technical depth plus regulatory understanding: one team that can advise, document and implement.

Technical and Regulatory Expertise

We combine deep AI engineering knowledge with regulatory understanding. Our team does not just advise, we implement the technical controls and documentation required for compliance.

Book your assessment

European Team, DACH & Nordics Focus

Our consultants understand the European regulatory landscape, including the GDPR interplay with the AI Act. We serve clients across the DACH region, the Nordics and the UK.

A Dedicated Compliance Team

Scale your compliance work with specialists who understand both the technical and regulatory dimensions of AI governance.

Scale your compliance team

GDPR & EU AI Act, By Design

Every solution we ship sits inside European data and regulatory perimeters. Compliance is engineered in from day one, not bolted on at audit time.

Frequently Asked Questions

  • What is the EU AI Act?

    The EU AI Act is the world’s first comprehensive artificial intelligence regulation, established by the European Union. It creates a risk-based legal framework for AI systems, with obligations ranging from outright bans to transparency requirements.

  • When does the EU AI Act take effect?

    The Act entered into force in August 2024. Key dates: February 2025 (prohibited AI), August 2025 (GPAI rules), August 2026 (high-risk obligations) and August 2027 (full enforcement).

  • Does the EU AI Act apply to UK companies?

    Yes, if your AI system is used by or affects people in the EU. The Act has extraterritorial scope similar to GDPR: the location of the company does not matter, the location of impact does.

  • What are high-risk AI systems?

    Systems used in critical areas: HR recruitment, credit scoring, education, law enforcement, healthcare diagnostics and critical infrastructure. These require conformity assessments and ongoing monitoring.

  • What are the penalties for non-compliance?

    Up to €35 million or 7% of global annual turnover for prohibited AI violations, and up to €15 million or 3% for other breaches. SMEs face proportionally lower caps.

  • How long does a compliance assessment take?

    A typical AI system inventory and initial risk classification takes two to four weeks. Full compliance implementation, including a governance framework and documentation, takes two to six months depending on complexity.

  • Do I need a compliance officer for AI?

    The EU AI Act does not mandate a specific role, but companies deploying high-risk AI should designate clear accountability. Many organisations are creating AI Compliance Officer or AI Ethics Lead positions.

  • What is the difference between AI governance and AI compliance?

    AI governance is the internal framework of policies, processes and roles for responsible AI use. AI compliance is meeting specific legal requirements like the EU AI Act. Good governance makes compliance easier.

Book Your EU AI Act Compliance Assessment

Book a 30-minute call. We will map where your AI systems sit under the Act and outline a compliance plan you can take to your board.