Secure AI Atlas mark Secure AI Atlas SECURITY & GOVERNANCE

Framework

EU AI Act — Regulation (EU) 2024/1689

The European Union's comprehensive regulatory framework for artificial intelligence, establishing a risk-based classification system with escalating obligations for providers and deployers of AI systems.

RegulationGovernanceComplianceStandard

The EU AI Act is the world’s first comprehensive AI regulation. It classifies AI systems into four risk tiers and imposes graduated obligations on providers, deployers, importers, and distributors. It entered into force in August 2024 with a phased compliance timeline extending through 2027.

Risk categories and obligations

TierDefinitionExamplesKey obligations
Unacceptable riskAI practices deemed incompatible with EU values and fundamental rightsSocial scoring, real-time biometric identification in public spaces, manipulative AIProhibited outright
High riskAI systems that pose significant risks to health, safety, or fundamental rightsAI in critical infrastructure, education, employment, law enforcement, migration, justiceConformity assessment, risk management, data governance, transparency, human oversight, accuracy, robustness
Limited riskAI systems with specific transparency obligationsChatbots, emotion recognition, deepfake generatorsTransparency: users must be informed they are interacting with AI or viewing AI-generated content
Minimal riskAll other AI systems not covered by the aboveAI-enabled video games, spam filtersNo mandatory obligations; voluntary codes of conduct encouraged

ATLAS connection

The EU AI Act’s high-risk obligations map directly to ATLAS controls: data governance requires classification before AI use, human oversight maps to human approval for high-impact actions, and transparency requirements connect to logging and monitoring controls. The regulatory obligation to maintain an inventory of AI systems reinforces the core ATLAS principle that governance begins with knowing what AI is in production.

Official website →

Official source: EU