Regulations
AI Act: AI System Register and FRIA
Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.
TL;DR
The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in stages depending on the risk level of the AI system. It places a set of obligations on deployers of high-risk systems including, for certain bodies, a fundamental rights impact assessment (FRIA, Article 27). Most AI systems used in companies come from vendors, so compliance runs through the contractual relationship.
What does the AI Act change for a company using AI?
The AI Act is Regulation (EU) 2024/1689 governing artificial intelligence in the Union, in force since 1 August 2024 and applicable in stages. For most organisations the role at stake is that of deployer: they buy AI systems rather than build them.
Which risk categories, with what consequences?
| Category | Examples cited by the regulation | Consequence for the deployer |
|---|---|---|
| Prohibited practices | Social scoring, exploitation of vulnerabilities | Use banned |
| High risk | Employment and recruitment, access to essential services, critical infrastructure | Enhanced obligations, FRIA for certain bodies |
| Limited risk | Systems interacting with people, generated content | Transparency obligations |
| Minimal risk | Other uses | No specific obligation |
How to prepare compliance on the vendor side
Three actions depend on no deadline and can be taken now:
- Inventory the AI systems actually in use, including AI features added by your existing SaaS — the main source of blind spots.
- Attach each system to its provider and to the documentation obtained: stated classification, instructions for use, logging commitments.
- Fold the question into the security questionnaire sent to third parties, rather than opening a parallel process.
As with NIS2, DORA, ISO 27001 and GDPR, the AI Act module will join your existing compliance dashboards — no new tool to deploy. See also the GDPR page.
FAQ
The AI Act is Regulation (EU) 2024/1689, the first horizontal framework governing artificial intelligence in the Union. It classifies systems by risk level — prohibited practices, high risk, limited risk subject to transparency, minimal risk — and places distinct obligations on providers and on deployers of those systems.
Sources
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence — EUR-Lex, 2024-07-12
- AI Act — European Commission page — European Commission
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours