The EU AI regulation applies in phases.Do you have a management system for AI?
Using AI in your products or services? Requirements depend on the AI system's use and your role. AmpliFlow gives you the structure for risk management, documentation and follow-up, with ISO 42001 as the framework.

Four risk levels - different requirements
The EU AI Act classifies AI systems by potential harm. Higher risk means stricter requirements. High-risk classification follows Article 6 and depends on the system's intended use and the conditions in Annex I or III, with the exceptions set out in the regulation.
Social scoring, real-time biometrics in public spaces, manipulative AI. These systems are banned outright.
Biometrics, critical infrastructure, education, employment, law enforcement. Requires management systems, risk assessment and human oversight.
Chatbots and AI interacting with people. Users must know they are talking to AI.
Spam filters, AI in games and similar. No specific requirements, voluntary codes of conduct.
The AI management standard that gives you a head start
ISO/IEC 42001 is the international standard for AI Management Systems (AIMS). It gives you the framework to govern AI development and use responsibly - and demonstrates that you take the EU AI Act seriously.
AmpliFlow supports ISO 42001 with the same proven management system structure as for ISO 27001 and ISO 9001. Joakim at AmpliFlow participated in the ISO working group that developed the standard.
Risk management system
Identify and assess risks throughout the AI system lifecycle. Document measures and residual risks.
Data governance
Ensure training data is relevant, representative and free from bias. Document data provenance.
Transparency and information
Provide users with clear information about the AI system's capabilities, limitations and intended use.
Human oversight
Design systems so humans can monitor and intervene when needed. Document oversight processes.
Phased application
The high-risk AI dates below apply to Chapter III, Sections 1-3, except Article 6(5).
The duty to support AI literacy already applies to providers and organisations that use AI. They must take measures for staff and others who operate or use AI systems on their behalf.
Specific transitional rules apply to existing systems under Article 111. Not all systems therefore share the same deadline.
Ban on AI systems with unacceptable risk
Rules for General Purpose AI (GPAI) models
General application, with separate dates for certain provisions
Requirements for high-risk AI under Article 6(2) and Annex III
Requirements for high-risk AI under Article 6(1) and Annex I (product safety legislation)
How to build your AI management system
Existing management system tools - the same structure you already know from ISO 27001 and ISO 9001.
Risk Assessment
Classify AI systems according to the regulation's risk levels. Document risk analyses with proven methodology and link them to actions.
Pages (wiki)
Collect AI policies, technical documentation and user instructions in AmpliFlow's wiki feature. Accessible to everyone who needs the information.
Process Management
Map the AI development lifecycle and AI-affected processes. Link AI tools to your process steps for full visibility.
Audit Management
Plan and conduct conformity assessments. Document audit findings and follow up on non-conformities systematically.
Goals & Monitoring
Set goals for AI performance and track results. Monitor that AI systems work as intended over time.
Legal Requirements Register
Add the EU AI Act to your manual legal requirements register. Set target dates and link requirements to processes and controls.
What you can expect
Concrete benefits from structured AI governance.
AI governance
Complete overview of your AI systems, risks and actions in a single management system.
risk assessments
Systematic risk classification according to EU AI Act risk levels with traceable documentation.
AI lifecycle
Documented development, deployment and monitoring throughout the entire lifecycle.
compliance
Scheduled actions to meet requirements before each milestone takes effect.
Questions about the EU AI Act
What is the EU AI Act?
What counts as a high-risk AI system?
What are the penalties for non-compliance?
How does ISO 42001 help with EU AI Act compliance?
Does the EU AI Act apply to companies outside the EU?
How does AmpliFlow support EU AI Act work?
Ready to prepare for the EU AI Act?
Book a call and we'll show you how AmpliFlow can help you structure AI governance and build your management system with ISO 42001 as the foundation.