Atlas · skill

EU AI Act Compliance

EU AI Act compliance is the practice of identifying which obligations apply to an AI activity and producing evidence that the responsible organization meets them. It connects intended use, operator roles, risk classification and lifecycle controls to the applicable legal text rather than treating a technical checklist as compliance.

conceptRegulation & Compliance

What it is

The EU AI Act distinguishes AI systems, general-purpose AI models and several operator roles, with obligations depending on the relevant category and context. A provider and a deployer can have different responsibilities, and the same underlying model can participate in applications with different intended purposes. Classification therefore requires examining the actual use and the organization's role, not assigning a legal category from a model name. Compliance work links that assessment to documentation, oversight, evaluation and other applicable requirements. The current text, amendments, guidance and application provisions must be checked for the specific case; this skill is not a substitute for qualified legal interpretation.

What the work involves

A practitioner inventories AI uses and records purpose, users, affected people, providers and deployment arrangements. With legal and governance specialists, they map applicable provisions to concrete controls and evidence owners. Artifacts include a classification rationale, documentation register and change-review process. Engineering evidence can describe data handling, testing, oversight mechanisms and monitoring, but it must correspond to the actual system configuration. Changes in purpose, operator responsibilities or technical capability trigger reassessment. The team also checks other relevant law rather than assuming the AI Act displaces privacy, employment or product requirements.

Illustrative example

An organization adds an assistant to a hiring workflow. Before launch, it documents whether the assistant merely answers general questions or influences applicant evaluation. That purpose assessment changes the compliance analysis and the evidence requested from the provider. The team records human responsibilities, evaluates the actual workflow and routes the classification decision through its legal review. Purchasing a model service with safety features does not settle the application's obligations.

Limits and common mistakes

Neither a guardrail library, an ISO certificate nor a good benchmark proves AI Act compliance. Public summaries can omit exceptions, role-specific duties and amended provisions. The skill requires tracing a claim to the applicable legal requirement and to maintained system evidence. A generic risk label is particularly weak when intended use is unclear. Legal conclusions and timing should be confirmed against authoritative, current sources for the particular activity.

Prerequisites

  • NIST AI RMF provides a risk management framework that maps well to EU AI Act requirements — NIST is a useful conceptual foundation

Related skills

Sources and further reading

Last updated: 2026-10-10