EU AI ActPhased application

The EU AI regulation applies in phases.Do you have a management system for AI?

Using AI in your products or services? Requirements depend on the AI system's use and your role. AmpliFlow gives you the structure for risk management, documentation and follow-up, with ISO 42001 as the framework.

ISO standards and AI governance
Risk-based approach

Four risk levels - different requirements

The EU AI Act classifies AI systems by potential harm. Higher risk means stricter requirements. High-risk classification follows Article 6 and depends on the system's intended use and the conditions in Annex I or III, with the exceptions set out in the regulation.

Unacceptable riskProhibited

Social scoring, real-time biometrics in public spaces, manipulative AI. These systems are banned outright.

High riskStrict requirements

Biometrics, critical infrastructure, education, employment, law enforcement. Requires management systems, risk assessment and human oversight.

Limited riskTransparency

Chatbots and AI interacting with people. Users must know they are talking to AI.

Minimal riskVoluntary

Spam filters, AI in games and similar. No specific requirements, voluntary codes of conduct.

ISO 42001

The AI management standard that gives you a head start

ISO/IEC 42001 is the international standard for AI Management Systems (AIMS). It gives you the framework to govern AI development and use responsibly - and demonstrates that you take the EU AI Act seriously.

AmpliFlow supports ISO 42001 with the same proven management system structure as for ISO 27001 and ISO 9001. Joakim at AmpliFlow participated in the ISO working group that developed the standard.

The management system's tools for risk management, document control, process management and auditing work together to build a complete AI management system.

Risk management system

Identify and assess risks throughout the AI system lifecycle. Document measures and residual risks.

Data governance

Ensure training data is relevant, representative and free from bias. Document data provenance.

Transparency and information

Provide users with clear information about the AI system's capabilities, limitations and intended use.

Human oversight

Design systems so humans can monitor and intervene when needed. Document oversight processes.

Timeline

Phased application

The high-risk AI dates below apply to Chapter III, Sections 1-3, except Article 6(5).

The duty to support AI literacy already applies to providers and organisations that use AI. They must take measures for staff and others who operate or use AI systems on their behalf.

Specific transitional rules apply to existing systems under Article 111. Not all systems therefore share the same deadline.

Feb 2025

Ban on AI systems with unacceptable risk

Aug 2025

Rules for General Purpose AI (GPAI) models

2 August 2026

General application, with separate dates for certain provisions

2 December 2027

Requirements for high-risk AI under Article 6(2) and Annex III

2 August 2028

Requirements for high-risk AI under Article 6(1) and Annex I (product safety legislation)

AmpliFlow's tools

How to build your AI management system

Existing management system tools - the same structure you already know from ISO 27001 and ISO 9001.

Risk Assessment

Classify AI systems according to the regulation's risk levels. Document risk analyses with proven methodology and link them to actions.

Pages (wiki)

Collect AI policies, technical documentation and user instructions in AmpliFlow's wiki feature. Accessible to everyone who needs the information.

Process Management

Map the AI development lifecycle and AI-affected processes. Link AI tools to your process steps for full visibility.

Audit Management

Plan and conduct conformity assessments. Document audit findings and follow up on non-conformities systematically.

Goals & Monitoring

Set goals for AI performance and track results. Monitor that AI systems work as intended over time.

Legal Requirements Register

Add the EU AI Act to your manual legal requirements register. Set target dates and link requirements to processes and controls.

Results

What you can expect

Concrete benefits from structured AI governance.

Structured

AI governance

Complete overview of your AI systems, risks and actions in a single management system.

Documented

risk assessments

Systematic risk classification according to EU AI Act risk levels with traceable documentation.

Traceable

AI lifecycle

Documented development, deployment and monitoring throughout the entire lifecycle.

Planned

compliance

Scheduled actions to meet requirements before each milestone takes effect.

FAQ

Questions about the EU AI Act

What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive legislation for artificial intelligence. It entered into force on 1 August 2024 and applies to all organisations that develop, provide, or use AI systems within the EU. The regulation uses a risk-based approach where requirements depend on the AI system's risk level.
What counts as a high-risk AI system?
High-risk AI systems are defined in Annex III of the regulation and include biometric identification, AI in critical infrastructure, AI affecting education and employment, AI in law enforcement and migration, and AI used by judicial authorities. These systems must meet strict requirements for risk management, data governance, documentation, transparency, human oversight and cybersecurity.
What are the penalties for non-compliance?
The penalties are significant: up to EUR 35 million or 7% of global annual turnover for prohibited AI practices, up to EUR 15 million or 3% for other violations, and up to EUR 7.5 million or 1% for providing incorrect information to authorities. Whichever amount is higher applies.
How does ISO 42001 help with EU AI Act compliance?
ISO/IEC 42001 provides a framework for building an AI Management System (AIMS) that supports EU AI Act compliance. The standard covers risk assessment, governance, documentation and continual improvement - exactly what's needed to demonstrate responsible AI management.
Does the EU AI Act apply to companies outside the EU?
Yes. The EU AI Act applies to all organisations that provide or use AI systems whose output is used within the EU, regardless of where the organisation is based. If your AI system affects people within the EU, you are covered by the regulation.
How does AmpliFlow support EU AI Act work?
AmpliFlow has built-in ISO 42001 controls with AI assistance for generating content per control, automatic SoA, and task management per control. Beyond the control register: risk analysis for classifying AI systems, pages (wiki) for policies and technical documentation, process management for mapping AI-affected processes, legal requirements register for tracking the EU AI Act, and action management for following up on adaptations.
Get started

Ready to prepare for the EU AI Act?

Book a call and we'll show you how AmpliFlow can help you structure AI governance and build your management system with ISO 42001 as the foundation.