Compliance/EU AI Act
EU regulation · AI risk

EU AI Act

The EU AI Act (Regulation 2024/1689) sets obligations according to the risk level of AI systems and is being phased in from 2025. High-risk systems carry the heaviest requirements, including robustness and cybersecurity.

Who it applies to

Providers and deployers of AI systems used in the EU
Organizations developing high-risk AI systems, or still establishing their classification
Organizations integrating AI into regulated products
What it requires

The obligations, clearly explained.

01
Risk classification
Determining whether each system falls into the prohibited, high-risk, limited, or minimal risk tier.
02
Risk and data governance
Risk management, data governance, and technical documentation for high-risk systems.
03
Human oversight
Effective human oversight and transparency toward users.
04
Robustness and security
Accuracy, robustness, and cybersecurity appropriate to the system's purpose and risk.
How Raptoric helps

We do the engineering work, not just the documentation.

AI system inventory and classification
We record the organization's AI systems and classify them against the regulation's requirements.
AI system testing
We test models, agents, and the surrounding processes against the robustness and security requirements.
Guardrail design
We design and validate the controls that keep AI system behavior within defined boundaries.
Governance documentation
We produce documentation aligned with the EU AI Act and the NIST AI RMF.
We deliver the testing, controls, and documentation. We do not act as a notified body or as legal counsel.
FAQ

Questions, answered

Does the EU AI Act apply to us?
If you develop, deploy, or distribute AI systems in the EU, very likely yes. Obligations scale with the risk tier, and high-risk systems carry the heaviest requirements.
What does the regulation require technically?
Risk management, data governance, logging of system activity, and robustness and security appropriate to the risk tier. We translate those requirements into concrete engineering tasks.
When do the obligations take effect?
The regulation applies in stages: provisions on prohibited practices first, followed by the obligations for high-risk systems. Timely preparation reduces the cost and risk of later alignment.
How does this connect to AI security testing?
Directly. We test the system as a whole and align the testing and documentation with the regulation's obligations, so the results also serve as evidence of regulatory readiness.

Need to be ready for EU AI Act?

Our team will define the scope of work with you on a 30-minute call.
Book a scoping call or email contact@raptoric.com