EU AI Act
The EU's risk-tiered regulation of AI systems, imposing obligations that scale from transparency duties to extensive conformity requirements for high-risk uses.
The Act classifies AI systems by risk. Unacceptable-risk practices are prohibited outright. High-risk systems — including AI used in employment, credit, essential services and certain safety components — carry the substantive obligations: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, and conformity assessment. Limited-risk systems carry transparency duties. General-purpose AI models have their own regime, with additional requirements where they present systemic risk.
Obligations phase in across a staged timeline running from 2025 into 2027, with prohibitions and AI-literacy duties applying first and high-risk obligations later.
For internal audit the immediate question is scoping: which systems the organisation operates fall into which tier, and whether anybody has made that determination on the record. The common finding is not non-compliance but absence of classification — nobody has decided, so nobody owns the obligations.
The human-oversight requirements are also worth reading closely by anyone building agentic audit capability, because they describe, in regulatory language, something close to supervised autonomy.
Related