From AI risk tier to operating control.
The AI Act — Regulation (EU) 2024/1689 — sorts AI by risk: practices banned outright, high-risk systems carrying the heaviest obligations, and lighter transparency duties beneath that. It applies in stages, and it binds two sides — providers, who build and place AI systems on the EU market, and deployers, who put those systems to work.
For an organization running AI it did not build, this is an operating problem, not a documentation problem. Deployer duties run while the system runs: knowing what you operate and at which tier, keeping the logs, assigning human oversight. An inventory assembled for a report is out of date the moment a team brings in a new model.
Who it applies to
Providers placing AI systems on the EU market or putting them into service in the EU, and deployers established in the EU — or whose systems' output is used in the EU. One system can carry duties for both the company that built it and the company running it; most organizations outside the AI industry meet the Act as deployers.
The clock
The stages have shifted: the 2026 Digital Omnibus moved high-risk application for standalone Annex III systems to 2 December 2027, and for AI embedded in regulated products (Annex I) to 2 August 2028. The earlier stages are already in force.
| When | What happens |
|---|---|
| 1 August 2024 | Regulation (EU) 2024/1689 entered into force |
| 2 February 2025 | Prohibited practices and the AI-literacy obligation apply |
| 2 August 2025 | General-purpose AI model obligations, governance and penalties apply |
| 2 August 2026 | The Act applies generally, including transparency obligations |
| 2 December 2026 | A further prohibition applies, covering non-consensual intimate imagery and synthetic child sexual abuse material |
| 2 December 2027 | High-risk obligations apply to standalone systems (Annex III) |
| 2 August 2028 | High-risk obligations apply to AI embedded in regulated products (Annex I) |
What it asks, in operating terms
Read as an operating requirement rather than a legal text, the AI Act reduces to a handful of standing asks — each answerable from a live inventory, not reconstructed when a customer or authority asks.
| What the AI Act asks | Where it is answered |
|---|---|
| Know which AI systems you operate, and at which risk tier | AI system inventory · continuous, tiered, mapped to obligations |
| Discharge deployer duties — oversight, information, logs | Control library · deployer duties mapped control by control |
| Keep AI literacy current for affected staff | Awareness records · by role, fed from connected systems |
| Show what a given system decided, on which model version | Inference records · model identity, version, per-decision log |
| Answer ISO 42001 and NIST AI RMF from the same inventory | Framework crosswalks · one inventory, every framework |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a deployer inventory is made of:
- Systems inventoried
- 23 · tiered by risk
- High-risk systems
- 4 · human oversight assigned
- Model logs
- identity · version · per-decision
- AI literacy
- current · by role
- Evidence
- sealed · sha256:6f0b…92e7
Where teams usually start
With a demo walked through by TruSecure — your AI inventory tiered in front of you, a deployer log opened to a single decision, the export an enterprise customer or authority will ask for. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
Art. 26 deployer duties are easier to discharge when someone actually operates the inference. Because TruSecure runs its own models on hardware it operates inside OVH’s French and German datacentres, model identity, version and per-decision logs are all available to you rather than sitting behind a third party’s API.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
The EU AI Act classifies AI systems into unacceptable, high, limited, and minimal risk tiers, with obligations scaling accordingly. TruSecure maintains a continuous AI system inventory mapped to these obligations and to ISO 42001 and NIST AI RMF simultaneously.