Regulations

AI Act: AI System Register and FRIA

Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.

TL;DR

The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in stages depending on the risk level of the AI system. It places a set of obligations on deployers of high-risk systems including, for certain bodies, a fundamental rights impact assessment (FRIA, Article 27). Most AI systems used in companies come from vendors, so compliance runs through the contractual relationship.

What does the AI Act change for a company using AI?

The AI Act is Regulation (EU) 2024/1689 governing artificial intelligence in the Union, in force since 1 August 2024 and applicable in stages. For most organisations the role at stake is that of deployer: they buy AI systems rather than build them.

Which risk categories, with what consequences?

AI system categories under the AI Act
CategoryExamples cited by the regulationConsequence for the deployer
Prohibited practicesSocial scoring, exploitation of vulnerabilitiesUse banned
High riskEmployment and recruitment, access to essential services, critical infrastructureEnhanced obligations, FRIA for certain bodies
Limited riskSystems interacting with people, generated contentTransparency obligations
Minimal riskOther usesNo specific obligation

How to prepare compliance on the vendor side

Three actions depend on no deadline and can be taken now:

  1. Inventory the AI systems actually in use, including AI features added by your existing SaaS — the main source of blind spots.
  2. Attach each system to its provider and to the documentation obtained: stated classification, instructions for use, logging commitments.
  3. Fold the question into the security questionnaire sent to third parties, rather than opening a parallel process.

As with NIS2, DORA, ISO 27001 and GDPR, the AI Act module will join your existing compliance dashboards — no new tool to deploy. See also the GDPR page.

FAQ

The AI Act is Regulation (EU) 2024/1689, the first horizontal framework governing artificial intelligence in the Union. It classifies systems by risk level — prohibited practices, high risk, limited risk subject to transparency, minimal risk — and places distinct obligations on providers and on deployers of those systems.

Sources

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence — EUR-Lex, 2024-07-12
  2. AI Act — European Commission page — European Commission

Ready for the regulations that apply to you

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account