modern auditing

Glossary

EU AI Act

Also known as: Artificial Intelligence Act, Regulation (EU) 2024/1689

The EU's risk-tiered regulation of AI systems, imposing obligations that scale from transparency duties to extensive conformity requirements for high-risk uses.

The Act classifies AI systems by risk. Unacceptable-risk practices are prohibited outright. High-risk systems — including AI used in employment, credit, essential services and certain safety components — carry the substantive obligations: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, and conformity assessment. Limited-risk systems carry transparency duties. General-purpose AI models have their own regime, with additional requirements where they present systemic risk.

Obligations phase in across a staged timeline running from 2025 into 2027, with prohibitions and AI-literacy duties applying first and high-risk obligations later.

For internal audit the immediate question is scoping: which systems the organisation operates fall into which tier, and whether anybody has made that determination on the record. The common finding is not non-compliance but absence of classification — nobody has decided, so nobody owns the obligations.

The human-oversight requirements are also worth reading closely by anyone building agentic audit capability, because they describe, in regulatory language, something close to supervised autonomy.


Related


Part of the Modern Auditing glossary. See also the maturity model and theartifact library.