OnwynStandards › EU AI Act (Regulation (EU) 2024/1689)

Regulation · 2024

EU AI Act (Regulation (EU) 2024/1689)

The EU AI Act is the first comprehensive AI law: it applies to essentially every company that puts an AI system on the EU market or uses one in the EU — including ordinary businesses that merely deploy AI tools bought from vendors. Obligations scale with risk: a short list of practices is banned outright, high-risk systems carry heavy provider and deployer duties, and certain systems trigger transparency rules regardless of risk. This pack takes the deployer's perspective first — the position most companies are actually in — with provider-side requirements summarized so buyers know what to demand from their AI vendors. Application is staggered from February 2025 onward, so parts of it already apply today.

32
Requirements
7
Areas
15
Recommended documents
1
Mapped frameworks
Start EU AI Act free Have us do it instead

What this standard asks for

Every requirement in EU AI Act (Regulation (EU) 2024/1689), grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

AI inventory & risk classification

3 requirements

  • Art. 3/25Determine your role per AI system
  • Art. 6 / Annex IIIClassify your AI inventory against the high-risk list
  • Art. 6(3)Document any claimed high-risk exemptions

Prohibited practices screening

4 requirements

  • Art. 5(1)(a)-(b)No manipulative or exploitative techniques
  • Art. 5(1)(c)No social scoring
  • Art. 5(1)(f)No emotion recognition in the workplace or education
  • Art. 5(1)(d)-(g)No banned biometric and predictive practices

High-risk deployer duties

8 requirements

  • Art. 26(1)Operate high-risk systems per the provider's instructions
  • Art. 26(2)Assign competent human oversight
  • Art. 26(4)Control the input data you feed high-risk systems
  • Art. 26(5)Monitor operation and escalate problems
  • Art. 26(6)Retain the system's automatically generated logs
  • Art. 26(7)Inform workers before workplace deployment
  • Art. 26(11)/86Tell people when high-risk AI decides about them
  • Art. 73Serious incident reporting readiness

Provider requirements (what to demand as a buyer)

9 requirements

  • Art. 9Demand evidence of the provider's risk management
  • Art. 10Demand evidence of training data governance
  • Art. 11Demand the technical documentation exists
  • Art. 12Verify logging capability before you buy
  • Art. 13Demand usable instructions and transparency
  • Art. 14Verify the system supports human oversight
  • Art. 15Demand accuracy, robustness and cybersecurity evidence
  • Art. 17Check the provider runs a quality management system
  • Art. 43/48Verify conformity assessment, CE marking and registration

Transparency obligations

3 requirements

  • Art. 50(1)Disclose AI interaction — chatbots and virtual agents
  • Art. 50(2)/(4)Mark synthetic content and label deepfakes
  • Art. 50(3)Notify people exposed to emotion recognition or biometric categorization

Fundamental rights impact assessment

2 requirements

  • Art. 27FRIA — determine whether it applies to you
  • Art. 27(1)FRIA — perform and maintain the assessment

Governance, literacy & readiness

3 requirements

  • Art. 4AI literacy across the workforce
  • Art. 113Applicability timeline and readiness plan
  • Art. 53-55GPAI awareness — know your general-purpose model duties and rights

The documents you will end up with

The recommended document set for EU AI Act (Regulation (EU) 2024/1689) — 15 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

AI System Inventory

The list of every AI system you build, buy or embed, with your role for each one and where it lands against the high-risk list.

AI Use Policy

The internal rules on what staff may and may not do with AI, which systems are approved, and who to ask before adding a new one.

Prohibited Practice Screening Record

Evidence that each system was checked against the banned uses — manipulation, social scoring, emotion recognition at work, and the biometric prohibitions — and the reasoning behind each conclusion.

AI Act Readiness Plan

Which obligations bite on which date for your systems, and what has to be in place before each one.

High-Risk Exemption Justification

Where you have decided an Annex III system is not high-risk after all, the written reasoning that decision rests on.

High-Risk Deployment Operating Procedure

How each high-risk system is actually run: using it the way the provider intended, controlling what data goes in, and watching what comes out.

Human Oversight Assignment

Who is named to oversee each high-risk system, what authority they have to override or stop it, and what training they were given.

AI Log Retention Standard

Which system-generated logs you keep, for how long, and how you would produce them if an authority asked.

Workplace AI Notification

The notice given to workers and their representatives before an AI system starts being used on them.

Individual Notification and Explanation Notice

What you tell a person when AI has decided something about them, and how they can get an explanation of that decision.

Serious Incident Reporting Procedure

How a malfunction or harm gets recognised as a serious incident, who is told, and against which deadline.

Fundamental Rights Impact Assessment

For the deployers it applies to: who the system affects, what could go wrong for their rights, and what oversight and remedies you have put in place.

Provider Evidence Checklist

What you demand from a vendor before signing: risk management, data governance, technical documentation, logging, instructions, oversight support, accuracy and robustness evidence, their quality system and their CE marking.

AI Transparency Disclosures

The wording users see when they are talking to AI, looking at AI-generated content, or being processed by emotion recognition or biometric categorisation.

General-Purpose AI Usage Note

Which foundation models you build on, what their providers have committed to, and what that leaves you responsible for.

Work that counts twice

EU AI Act (Regulation (EU) 2024/1689) overlaps with 1 other framework in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.

Start EU AI Act today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.