Skip to content
FrankX.AI
Research Hub/The EU AI Act & Global Regulatory Compliance Frameworks

The EU AI Act & Global Regulatory Compliance Frameworks

Risk tier classification, prohibited AI, high-risk systems, conformity assessments, and ISO/IEC 42001 standards

TL;DR

The EU AI Act represents the world's first comprehensive, legally binding horizontal AI regulation, establishing strict extraterritorial compliance obligations backed by fines up to €35M or 7% of global annual turnover. The law categorizes AI systems into four risk tiers (Unacceptable/Prohibited, High-Risk, Specific Transparency / GPAI with Systemic Risk, and Minimal Risk), mandating technical documentation, risk management, and human oversight.

Updated 2026-08-186 source references4 claims indexed

Research briefs like this, when the evidence is ready. Source links, limitations, and open questions.

Subscribe

€35M / 7%

Maximum statutory fine for violating prohibited AI practices under the EU AI Act

Official Journal of the European Union

4 Risk Tiers

Prohibited, High-Risk, GPAI / Transparency, Minimal Risk classification

EU AI Act Article 6 & Annex III

ISO/IEC 42001

Global certifiable standard for Artificial Intelligence Management Systems (AIMS)

ISO Standards Organization

GPAI Systemic

Models trained with >10²⁵ FLOPs subject to mandatory red-teaming and energy reporting

EU AI Office Guidelines
01

The 4 Risk Tiers of the EU AI Act

The EU AI Act follows a risk-based approach: the higher the potential harm to fundamental human rights, safety, and health, the stricter the legal requirements.

Unacceptable Risk (Prohibited)

Prohibited

Bans social scoring, cognitive behavioral manipulation, biometric categorization of protected traits, and untargeted facial scraping.

High-Risk Systems (Annex III)

HighRisk

Regulates AI in critical infrastructure, medical devices, hiring/HR resume screening, credit scoring, and law enforcement.

General-Purpose AI (GPAI) & Systemic Risk

GPAI

Requires foundation model developers to publish training data summaries, respect copyright, and conduct red-teaming if FLOPs > 10²⁵.

Minimal Risk (Free Deployment)

Minimal

Covers AI video games, spam filters, and inventory optimization with zero regulatory burden beyond standard consumer law.

02

Mandatory Compliance Obligations for High-Risk AI Systems

Deploying or building a high-risk AI system requires passing rigorous conformity assessments and maintaining a permanent audit trail.

Continuous Risk Management System

RiskMgmt

Identifies, evaluates, and mitigates risks to health, safety, and fundamental rights throughout the entire lifecycle.

Data Governance & Bias Mitigation

DataGov

Requires training, validation, and testing datasets to be relevant, representative, and audited for discriminatory bias.

Technical Documentation & Automated Logging

Logging

Maintains comprehensive system architecture records and automatic logging of all system operational events.

03

Global Regulatory Harmonization: NIST AI RMF & ISO 42001

Global enterprises must navigate overlapping frameworks: the EU AI Act, the US NIST AI Risk Management Framework (AI RMF), and certifiable ISO standards.

ISO/IEC 42001 Certification

ISO42001

The international standard providing a verifiable management framework for AI governance, policies, and internal controls.

NIST AI RMF (Govern, Map, Measure, Manage)

NIST

The leading US voluntary framework used by federal agencies and enterprise IT teams to manage AI risks.

Extraterritorial Jurisdiction

Jurisdiction

Like GDPR, the EU AI Act applies to any company worldwide if their AI system's output is used within the European Union.

Key Findings

1

The EU AI Act applies globally to any company whose AI system or generated output touches users inside the European Union.

2

High-risk AI systems (hiring algorithms, credit underwriting, healthcare) require mandatory conformity assessments, bias audits, and human oversight.

3

General-Purpose AI (GPAI) foundation models trained with more than 10²⁵ FLOPs face strict systemic risk evaluations and energy disclosures.

4

ISO/IEC 42001 has emerged as the premier international certification standard for proving enterprise AI governance compliance.

5

Prohibited AI practices (like social scoring or manipulative subliminal techniques) carry severe penalties up to €35M or 7% of global revenue.

Research Transparency

Limitations

  • Secondary implementation guidelines from the EU AI Office regarding exact GPAI threshold metrics are actively being published.
  • Small and medium enterprises (SMEs) must navigate complex legal compliance costs via regulatory sandboxes.

What We Don't Know

  • ?The exact enforcement interpretation regarding open-weight model redistribution versus closed API commercial deployment.
  • ?How international courts will harmonize conflicting AI liability rulings between the US, EU, and Asian jurisdictions.
Evidence Grade:Grade A(Backed by the official legal text of the European Union Artificial Intelligence Act (Regulation EU 2024/1689), ISO/IEC 42001:2023 standards, and NIST AI RMF 1.0.)

Frequently Asked Questions

The EU AI Act is the world's first comprehensive legal regulation for Artificial Intelligence. It sets strict rules based on how risky an AI system is, ensuring AI is safe, ethical, and protects fundamental human rights.

From research to practice

Learn these tools hands-on

The research maps the landscape. These portals curate the videos, docs, and experts to actually build with the platforms it covers.