Skip to content
2024/1689EU AI Act

One law. Four risk tiers.
Know where you stand.

Sort every AI system into its risk tier, keep the proof each tier demands, and stay current as things change.

Four risk tiers
Unacceptablebanned outright
High-riskthe full duty set
Limited risktell people it is AI
Minimal riskno extra obligation
01Requirements

What the Act asks you to produce.

The Act puts every AI system in a risk tier, and the tier decides your homework. For a high-risk system, each of these is something you must be able to hand over.

Art. 9

Risk management system

A risk process that runs for the system’s whole life — not a one-time check at launch.

Art. 10

Data governance

Training and test data that is relevant, representative and checked for errors.

Art. 11

Technical documentation

Full documentation written before launch and kept up to date, covering what Annex IV lists.

Art. 12

Record-keeping

The system logs its own activity automatically, and whoever runs it keeps those logs.

Art. 14

Human oversight

A real person who understands the system and can step in or shut it down.

Art. 49

Registration

Annex III high-risk systems registered in the EU database before they go live.

Application timeline

When each duty starts to bite.

The Act rolls out in stages. The 2026 Digital Omnibus pushed the high-risk stage back — everything already live stays live.

Aug 2024In force
Feb 2025Bans apply
Aug 2025General-purpose AI
Aug 2026Transparency duties
Dec 2027High-risk · Annex III
Aug 2028High-risk in regulated products

High-risk dates as amended by the 2026 Digital Omnibus.

Bans, general-purpose model duties and transparency rules apply now; high-risk duties start 2 December 2027 (Annex III) and 2 August 2028 (Annex I).

02In practice

From regulation to practice.

The Act tells you what compliance requires. Actually complying means connecting those requirements to real systems, real decisions and real evidence.

SystemsInventory

You can’t classify what you can’t see — it starts with knowing every AI system you run.

ClassificationReasoning

A risk tier holds up when the reasoning behind it is written down.

DocumentationEvidence

A document counts when it’s attached to the system it actually describes.

ChangeCurrent state

When a model changes, its classification and documents need to change with it.

03Strai8 for the EU AI Act

From the text of the Act to live AI governance.

Strai8 connects the Act’s obligations to the systems, classifications, controls and evidence across your AI environment.

Discovery

Find the AI already in use.

Find every AI system you run — across endpoints, apps, models and third-party services.

Risk classification

Place each system in the Act’s own tiers.

Sort each system into its tier, with the articles that explain why.

Technical documentation

Assemble Annex IV from the record.

Build Annex IV documentation straight from the system’s own record — no retyping into templates.

Evidence

Attach proof to the obligation.

Pin each piece of proof to the article it answers, versioned with the system.

Monitoring

Keep classifications current.

Get told when a change makes a classification or document out of date.

Accountability

Give every decision an owner.

Every decision carries a name, a date and the version it was made against.

04Questions

Questions teams ask about the EU AI Act.

EU AI Act

See your estate against the Act.

Thirty minutes on your own systems: which tier each one lands in, and what is missing.