The world's first horizontal AI law works like CE marking: risk classes, conformity assessment, technical documentation, market surveillance. If you know product certification, the AI Act is familiar territory — which is precisely IOTR's angle on it.
At a glance
Approach
Prohibited practices · high-risk systems · transparency cases · minimal risk
High-risk duties
Risk management, data governance, logging, robustness, human oversight, QMS
Two high-risk routes
Listed use cases (hiring, credit, infrastructure…) and AI as safety component in regulated products
GPAI
Documentation, copyright policy; systemic-risk models face evaluations and reporting — since Aug 2025
Assessment
Internal control for most Annex III; notified bodies for biometrics and embedded routes
Penalties
For prohibited practices; lower tiers for other breaches
What it is
Strip away the discourse and the AI Act is a product regulation: providers of high-risk AI systems run a risk management system, govern their training data, document the system, log its operation, ensure accuracy, robustness and cybersecurity (Article 15), keep humans meaningfully in the loop, pass conformity assessment and affix a CE mark. Deployers get lighter duties; importers and distributors inherit the usual chain obligations. Anyone who has built a CRA or machinery-directive file recognises the architecture immediately.
High-risk status arrives by two roads: Annex III use cases — biometrics, critical infrastructure management, employment, credit, essential services, law enforcement — and AI as a safety component of products already under EU harmonisation law, where AI Act conformity folds into the existing product’s assessment. GPAI models carry their own regime, in force since August 2025, with systemic-risk models facing model evaluations and incident reporting under the Commission’s AI Office.
The honest mid-2026 picture: the high-risk obligations reach their main application milestone in August 2026, while the scaffolding is still going up — harmonised standards from CEN/CENELEC JTC21 are not finished, notified-body capacity is embryonic, and the Commission’s digital omnibus discussions have put timeline adjustments for parts of the high-risk regime on the table. Uncertainty about dates, however, changes nothing about direction: the evidence disciplines the Act demands take years to build, and they are the same disciplines the rest of your certification portfolio already requires.
Key dates
Banned practices (social scoring, certain biometrics) enforceable.
Model documentation duties; AI Office oversight of systemic-risk models.
Regulation (EU) 2026/1744 defers most of the high-risk regime and amends the conformity machinery.
Governance, notified bodies, harmonised standards and Article 50 transparency obligations apply.
Chapter III Sections 1-3 apply to standalone high-risk systems. Also the deadline for machine-readable marking on generative systems placed on the market before 2 August 2026.
AI as a safety component of products already under EU harmonisation legislation.
What it means for you
Which systems are high-risk, by which route, who is provider vs. deployer — plus the borderline cases documented. Classification drives everything, and regulators will ask for the reasoning.
Logging, data lineage, evaluation results, robustness testing — produced continuously by the ML lifecycle, not reconstructed for audits. Retrofitting traceability onto a deployed model is the expensive path.
Accuracy, robustness and cybersecurity of AI systems overlap CRA Annex I and ISO 27001 territory. One risk framework covering both saves an entire parallel compliance function.
Timeline relief may come for parts of the high-risk regime. Capabilities take longer to build than deadlines take to move; the direction of travel has not changed once since 2021.
Where it lands
IoT & Embedded →
Models embedded in devices stack AI Act duties onto CRA and RED conformity — one technical file should carry all three.
IACS / Industrial →
Machine-learning in control and safety functions routes high-risk AI through machinery and product legislation — with notified bodies involved.
Cloud →
AI platforms and hosting inherit logging, access-control and robustness expectations — layered on the cloud assurance stack.
Digital Identity & Trust →
Identity verification and biometric systems sit in the Act’s most sensitive categories — where notified-body assessment applies.
The standards that answer it
Plus the emerging AI-specific set: ISO/IEC 42001 (AI management systems), ISO/IEC 23894 (AI risk) and the CEN/CENELEC JTC21 harmonised standards in development.
Expert notes
The organisations moving fastest on the AI Act are not the ones with AI ethics boards — they are the ones with CE-marking muscle memory. Technical documentation, QMS integration, conformity assessment logistics, post-market monitoring: the Act reuses the machinery of European product law, and the skills transfer directly. The genuinely new work is narrower than it looks: data governance evidence, model evaluation methodology, and human-oversight design that survives scrutiny.
Our position: staff AI Act compliance from your certification and quality functions, augmented by ML engineering — not the other way around. The regulation speaks conformity, not data science.
Accuracy, robustness and cybersecurity for high-risk AI — including resistance to data poisoning, adversarial examples and model extraction — lands on the same desk as CRA Annex I and your ISO 27001 scope. Running separate AI-security and product-security risk assessments produces contradictions; a shared threat model with AI-specific extensions produces one defensible story. The standards landscape is converging the same way: JTC21’s work leans on existing security standards wherever it can.
Our position: extend your existing security risk framework with AI failure modes rather than adopting a parallel AI-risk universe. One framework, two regulatory outputs — the pattern that works everywhere else in this portfolio works here too.
Classification, evidence architecture, Article 15 integration, notified-body strategy — thirty minutes to a plan that doesn’t wait for Brussels.
We’ll send you access by email.