Skip to main content
FRAMEWORK

From AI risk tier to operating control.

The AI Act — Regulation (EU) 2024/1689 — sorts AI by risk: practices banned outright, high-risk systems carrying the heaviest obligations, and lighter transparency duties beneath that. It applies in stages, and it binds two sides — providers, who build and place AI systems on the EU market, and deployers, who put those systems to work.

For an organization running AI it did not build, this is an operating problem, not a documentation problem. Deployer duties run while the system runs: knowing what you operate and at which tier, keeping the logs, assigning human oversight. An inventory assembled for a report is out of date the moment a team brings in a new model.

Who it applies to

Providers placing AI systems on the EU market or putting them into service in the EU, and deployers established in the EU — or whose systems' output is used in the EU. One system can carry duties for both the company that built it and the company running it; most organizations outside the AI industry meet the Act as deployers.

The clock

The stages have shifted: the 2026 Digital Omnibus moved high-risk application for standalone Annex III systems to 2 December 2027, and for AI embedded in regulated products (Annex I) to 2 August 2028. The earlier stages are already in force.

EU AI Act · staged application
WhenWhat happens
1 August 2024Regulation (EU) 2024/1689 entered into force
2 February 2025Prohibited practices and the AI-literacy obligation apply
2 August 2025General-purpose AI model obligations, governance and penalties apply
2 August 2026The Act applies generally, including transparency obligations
2 December 2026A further prohibition applies, covering non-consensual intimate imagery and synthetic child sexual abuse material
2 December 2027High-risk obligations apply to standalone systems (Annex III)
2 August 2028High-risk obligations apply to AI embedded in regulated products (Annex I)

What it asks, in operating terms

Read as an operating requirement rather than a legal text, the AI Act reduces to a handful of standing asks — each answerable from a live inventory, not reconstructed when a customer or authority asks.

EU AI Act requirements · how TruSecure answers them
What the AI Act asksWhere it is answered
Know which AI systems you operate, and at which risk tierAI system inventory · continuous, tiered, mapped to obligations
Discharge deployer duties — oversight, information, logsControl library · deployer duties mapped control by control
Keep AI literacy current for affected staffAwareness records · by role, fed from connected systems
Show what a given system decided, on which model versionInference records · model identity, version, per-decision log
Answer ISO 42001 and NIST AI RMF from the same inventoryFramework crosswalks · one inventory, every framework

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a deployer inventory is made of:

AI system inventory · deployer excerptSample data
Systems inventoried
23 · tiered by risk
High-risk systems
4 · human oversight assigned
Model logs
identity · version · per-decision
AI literacy
current · by role
Evidence
sealed · sha256:6f0b…92e7

Where teams usually start

With a demo walked through by TruSecure — your AI inventory tiered in front of you, a deployer log opened to a single decision, the export an enterprise customer or authority will ask for. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

Sovereignty

Art. 26 deployer duties are easier to discharge when someone actually operates the inference. Because TruSecure runs its own models on hardware it operates inside OVH’s French and German datacentres, model identity, version and per-decision logs are all available to you rather than sitting behind a third party’s API.

See the whole chain

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

The EU AI Act classifies AI systems into unacceptable, high, limited, and minimal risk tiers, with obligations scaling accordingly. TruSecure maintains a continuous AI system inventory mapped to these obligations and to ISO 42001 and NIST AI RMF simultaneously.