One law. Four risk tiers.
Know where you stand.
Sort every AI system into its risk tier, keep the proof each tier demands, and stay current as things change.
What the Act asks you to produce.
The Act puts every AI system in a risk tier, and the tier decides your homework. For a high-risk system, each of these is something you must be able to hand over.
Risk management system
A risk process that runs for the system’s whole life — not a one-time check at launch.
Data governance
Training and test data that is relevant, representative and checked for errors.
Technical documentation
Full documentation written before launch and kept up to date, covering what Annex IV lists.
Record-keeping
The system logs its own activity automatically, and whoever runs it keeps those logs.
Human oversight
A real person who understands the system and can step in or shut it down.
Registration
Annex III high-risk systems registered in the EU database before they go live.
Application timeline
When each duty starts to bite.
The Act rolls out in stages. The 2026 Digital Omnibus pushed the high-risk stage back — everything already live stays live.
High-risk dates as amended by the 2026 Digital Omnibus.
Bans, general-purpose model duties and transparency rules apply now; high-risk duties start 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
From regulation to practice.
The Act tells you what compliance requires. Actually complying means connecting those requirements to real systems, real decisions and real evidence.
You can’t classify what you can’t see — it starts with knowing every AI system you run.
A risk tier holds up when the reasoning behind it is written down.
A document counts when it’s attached to the system it actually describes.
When a model changes, its classification and documents need to change with it.
From the text of the Act to live AI governance.
Strai8 connects the Act’s obligations to the systems, classifications, controls and evidence across your AI environment.
Discovery
Find the AI already in use.
Find every AI system you run — across endpoints, apps, models and third-party services.
Risk classification
Place each system in the Act’s own tiers.
Sort each system into its tier, with the articles that explain why.
Technical documentation
Assemble Annex IV from the record.
Build Annex IV documentation straight from the system’s own record — no retyping into templates.
Evidence
Attach proof to the obligation.
Pin each piece of proof to the article it answers, versioned with the system.
Monitoring
Keep classifications current.
Get told when a change makes a classification or document out of date.
Accountability
Give every decision an owner.
Every decision carries a name, a date and the version it was made against.
Questions teams ask about the EU AI Act.
See your estate against the Act.
Thirty minutes on your own systems: which tier each one lands in, and what is missing.