A working walkthrough of the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689) — the four-tier risk taxonomy (Art. 5 Prohibited / Art. 6 + Annex III High-Risk / Art. 50 Limited-Risk / Minimal-Risk), the eight high-risk obligations under Articles 9–15 (risk management + data governance + technical documentation + record-keeping + transparency + human oversight + accuracy / robustness / cybersecurity), the Articles 51–55 GPAI obligations (model evaluation + 10^25 FLOPs systemic-risk threshold + 15-day serious-incident reporting to the AI Office), the conformity assessment mechanics (Annex IV self-assessment / Annex VII Notified Body / Art. 48 Presumed Conformity / Art. 72 post-market monitoring), the Article 99 penalty tiers (€35M / €15M / €7.5M), and a 2026 readiness roadmap for SaaS, GTM AI, and GPAI providers deploying AI systems to EU users.
The EU AI Act (Regulation (EU) 2024/1689) is the world’s first horizontal AI regulation. Entered into force August 1, 2024; published in the Official Journal of the European Union July 12, 2024; structured across 13 Chapters and 113 Articles covering prohibited practices, high-risk systems, transparency, GPAI models, enforcement, governance, and Member State competent authorities. Phased applicability with enforcement trigger dates that have shifted under the May 7, 2026 AI Omnibus provisional deal.
The EU AI Act applies to any provider placing an AI system on the EU market, any deployer putting an AI system into service in the EU, any provider or deployer of an AI system whose output is used in the EU, and any importer / distributor of AI systems placed on the EU market — regardless of whether the provider or deployer is established in the EU or outside it (Art. 2). The extraterritorial reach is the central reason US companies with EU customers, employees, or users must classify their AI systems. SaaS platforms with EU subscribers, HR tools with EU job applicants, healthcare AI serving EU patients, fintech with EU counterparties, and any foundation model exposing APIs to EU developers all land inside scope.
Phased applicability (Article 113): February 2, 2025 — Prohibited practices under Article 5 + AI literacy obligation under Article 4 enforcement began. August 2, 2025 — GPAI model obligations under Chapter V (Articles 51–55) enforcement began, including the systemic-risk classification at the 10^25 FLOPs training-compute threshold. August 2, 2026 — Originally Annex III high-risk-system enforcement + Article 50 transparency obligations; the Article 50 transparency obligations remain unchanged at August 2, 2026 (chatbot disclosure, deepfake labeling, AI-generated content marking, emotion-recognition notification). December 2, 2027 — Annex III high-risk-system enforcement, DEFERRED 16 months by the Council/Parliament AI Omnibus provisional deal reached May 7, 2026. August 2, 2028 — High-risk AI embedded in Annex I product-safety products (medical devices, machinery, toys, etc.), deferred 24 months by the AI Omnibus. New NCII / nudifiers ban: effective December 2, 2026 under the AI Omnibus. Watermarking and content marking moved to December 2, 2026. National sandbox deadline extended to August 2027 with a new EU-level sandbox (SME / start-up priority). SME benefits extended to newly defined “small mid-cap” companies. Source: Council Press Release 2026-05-07.
Governance structure: enforcement is split between the Commission AI Office (a centralized body inside DG CONNECT responsible for GPAI model enforcement and Art. 113 coordination), and the Member State competent authorities (NCAs / DPAs designated per Art. 70). The five largest NCAs by volume are Germany (Bundesnetzagentur + BMBF, NCA designated), France (ARCOM + CNIL, NCA designated), Netherlands (Rijksdienst voor Digitale Infrastructuur RDI), Spain (Agencia Española de Supervisión de Inteligencia Artificial AESIA — the first standalone EU AI regulator, operational since January 2024), and Ireland (Competition and Consumer Protection Commission CCPC — primary NCA for many US tech companies with EU HQ in Ireland). The NCA designation carries the Article 99 penalty-allocation authority within each Member State; cross-border enforcement coordination flows through the AI Office and the European AI Board established under Article 7.
The EU AI Act organizes AI systems into four risk tiers tied to the use case and the data subject affected. Tiers are mutually exclusive: a system is either Prohibited (Art. 5), High-Risk (Art. 6 + Annex III), Limited-Risk (Art. 50 transparency), or Minimal-Risk. ComplianceStack maps every AI deployment to its applicable tier via the Article 6 + Annex III classification decision.
The Article 6 high-risk classification splits into two pathways. Annex III high-risk is the broad use-case list (biometric ID, critical infrastructure, education, employment, essential services, law enforcement, migration, administration of justice, democratic processes) and was the original August 2, 2026 enforcement date — deferred to December 2, 2027 under the May 7, 2026 AI Omnibus. Annex I product-safety high-risk is the product-safety-track list (medical devices under 93/42/EEC, machinery, toys, radio / telecom equipment, in-vitro diagnostics, motor vehicles, civil aviation, etc.) and was originally a separate earlier enforcement date — deferred to August 2, 2028 under the AI Omnibus. The deferred dates mean US companies deploying AI to EU users have a documented 14-month window (August 2, 2026 → December 2, 2027) for the Annex IV conformance work; companies with Annex I product-safety scope have a 24-month window.
Article 50 transparency obligations apply to (a) AI systems directly interacting with natural persons — such as chatbots, virtual assistants, and any conversational AI — users must know they are interacting with an AI; (b) AI systems generating synthetic audio / image / video / text — content must be machine-readable and detectable as AI-generated per the watermarking requirements moved to December 2, 2026; (c) emotion-recognition systems; (d) biometric-categorization systems inferring sensitive attributes; (e) deepfake generation or manipulation — deployers must disclose deepfake content. The Commission Code of Practice on AI-generated content, consultation open from May 2026 (closes October 2, 2026), sets the practical implementation expectations; the second draft of March 5, 2026 simplified obligations and removed the AI-generated vs AI-assisted taxonomy.
The ComplianceStack EU AI Act risk classifier walks every screened AI system through three questions in order: (1) Does the system or use case match any of the eight Article 5 prohibited practices? (2) Does the system or use case match any of the eight Annex III use-case areas, OR is it a safety component of an Annex I product? (3) Does the system or use case match any of the four Article 50 transparency triggers? If yes to (1) → Prohibited — do not deploy. If no to (1) but yes to (2) → High-Risk — run the Annex IV self-assessment or Annex VII Notified Body. If no to (1) and (2) but yes to (3) → Limited-Risk — implement Article 50 transparency. If no to all three → Minimal-Risk — voluntary Code of Conduct under Article 95.
The high-risk obligations under Articles 9–15 are the substantive control set for any AI system classified under Article 6 + Annex III. The GPAI obligations under Articles 51–55 apply to foundation-model providers above the 10^25 FLOPs threshold. Together they form the documentable evidence pack the Annex IV technical documentation must contain.
Article 9 requires a documented, iterative risk-management system that runs from the initial design phase through the post-market monitoring phase. The system must identify and analyze known and reasonably foreseeable risks to health, safety, fundamental rights, the environment, democracy, and the rule of law; estimate and evaluate those risks; evaluate other risks arising from the use of the AI system; and adopt appropriate risk-management measures. The risk-management cycle is iterative: risks re-evaluated every significant system modification. ComplianceStack pairs Article 9 with the ComplianceStack AI Risk Register tool that maps deployment risks against use-case / data / model-inference / output categories.
Article 10 requires that training, validation, and testing data sets meet quality criteria including relevance, representativeness, and (to the best extent possible) absence of errors and biases; that data sets are obtained lawfully; that they have appropriate statistical properties for the intended purpose; that data preparation processing operations (annotation, labeling, cleaning, enrichment, aggregation) are documented; and that datasets are examined for possible biases that could lead to discrimination. Where sensitive personal data is used, Article 10 subjects overlap with GDPR Art. 9 special-category processing.
Article 11 sets the technical-documentation requirement, with the Annex IV required content list: (1) general description of the AI system including intended purpose, person(s) deploying, version, environment, etc.; (2) detailed description of system elements and design choices; (3) detailed description of capabilities and limitations; (4) intended purposes; (5) risk-management measures per Article 9; (6) data and data-governance per Article 10; (7) performance metrics, foreseeable unintended outcomes, sources; (8) validation and testing procedures; (9) cybersecurity measures; (10) post-market monitoring plan; (11) declarations of conformity; (12) instructions for use. ComplianceStack pairs Article 11 with the ComplianceStack Annex IV Technical Documentation Builder that scaffolds every required section.
Article 12 requires automatic logging of events over the AI system’s lifetime to ensure traceability of the system’s functioning, with a minimum retention matching the intended purpose and applicable Union law. Logs must enable monitoring of the AI system’s operation, post-market monitoring per Article 72, and reconstruction of past events. ComplianceStack pairs Article 12 with the ComplianceStack AI Lifecycle Event Logger that records every deployment decision + inference input / output metadata into an immutable, auditable trail.
Article 13 requires high-risk AI systems to be designed to enable deployers to interpret the system’s output and use it appropriately. Instructions for use must be concise, complete, correct, and clear; include the identity and contact details of the provider; the system’s characteristics, capabilities, and limitations; the intended purposes; the level of accuracy, robustness, and cybersecurity metrics per Article 15; and known foreseeable circumstances that may lead to foreseeable unintended outcomes.
Article 14 requires that high-risk AI systems be designed to allow effective human oversight during the period of use, with appropriate measures to enable it. Human oversight must be effective — overseen by natural persons; interactive — allowing meaningful intervention; and understood by natural persons. The designer-side measures (built into the system) and the operator-side measures (instructed by the deployer) are spelled out in Annex IV. AI systems used for biometric identification or critical infrastructure carry mandatory minimum human-oversight configurations.
Article 15 requires that high-risk AI systems be designed with appropriate levels of accuracy, robustness (resilience to errors, faults, inconsistencies), and cybersecurity (resilience to adversarial attacks per Recital 96). The accuracy metrics must be declared in the instructions for use; robustness minimisation of unintended outcomes must operate under foreseeable misuse; cybersecurity measures must address unauthorized access, data poisoning, model inversion, and adversarial examples. ComplianceStack pairs Article 15 with the ComplianceStack AI Robustness & Adversarial Testing tool that runs red-team testing against deployed AI systems.
Articles 51–55 apply to providers of general-purpose AI models. Article 51 requires training-data summarization, intellectual-property-respect policy, and downstream-integration documentation support. Article 52 sets the Annex XI technical-documentation content list (model architecture + training process + evaluation results + safety testing + risk-mitigation). Article 53 obliges providers to cooperate with downstream AI-system providers (the integrator tier). Article 54 activates when the model is classified as “systemic risk” — triggered at the 10^25 FLOPs training-compute threshold — with model evaluation, adversarial testing, cybersecurity incident-reporting, and energy-efficiency tracking. Article 55 sets serious-incident reporting to the AI Office within 15 days of the provider becoming aware. The 10-year Annex XI documentation retention applies.
For high-risk AI systems, conformity assessment is the gate that turns design and engineering documentation into a deployable system matching the Member State NCA expectations. ComplianceStack breaks the conformity assessment into four paths, calibrated to the classification and the use case.
| Conformity path | Trigger | Who audits | Output |
|---|---|---|---|
| Annex IV internal control | Annex III high-risk (most use cases) | Provider self-assessment | Annex IV technical documentation + EU Declaration of Conformity |
| Annex VII Notified Body | Biometric ID + certain critical infrastructure AI | Notified Body (designated by Member State) | Notified Body certificate + Annex VII audit report |
| Article 48 Presumed Conformity | Harmonized CEN / CENELEC standards (when issued) | Provider self-attestation against published standard | EU Declaration of Conformity + citation of harmonized standard |
| Annex I product-safety pathway | AI component of a regulated product (medical device, machinery, etc.) | Existing product-safety Notified Body sectoral process | CE marking per existing sectoral process + AI overlay |
Annex IV self-assessment is the conformity path for the bulk of Annex III high-risk use cases. The provider performs the assessment internally against the eight Articles 9–15 obligations, packages the Annex IV required content list (general system description, design choices, capabilities and limitations, intended purposes, risk-management measures, data-governance, performance metrics, validation / testing, cybersecurity, post-market monitoring plan, declarations of conformity, instructions for use), generates an EU Declaration of Conformity under Annex V, runs the CE marking compliance step, and registers the system in the EU AI database before placing it on the market. ComplianceStack pairs Annex IV with the ComplianceStack Annex IV Builder that scaffolds every required Annex IV section.
Annex VII Notified Body assessment is required for certain biometrics and critical-infrastructure AI systems — the most sensitive categories of the Annex III list. The provider engages a Member-State-designated Notified Body to perform the conformity assessment; the Notified Body issues an assessment report and (where compliant) a Notified Body certificate. The CE marking step follows. The Notified Body designation structure is still being operationalized in 2026; Member State NCAs have begun publishing the list of designated Notified Bodies in Q2 2026. ComplianceStack pairs the Annex VII path with a Notified Body Readiness Package that pre-checks the Annex IV documentation against Notified Body expectations before the formal engagement.
Article 48 sets the Presumed Conformity mechanism: AI systems conforming to harmonized CEN / CENELEC standards adopted per Regulation (EU) No 1025/2012 are presumed to conform to the Articles 9–15 obligations the standards seek to cover. As of 2026, the CEN/CENELEC JTC 21 technical committee has started publishing drafts of the harmonized standards — the first published standards are expected in late 2026 / early 2027. Until then, providers must perform the Annex IV internal assessment themselves; once standards are published, providers can replace selected Annex IV sections with citations to the harmonized standard. ComplianceStack tracks the harmonized-standard publication list and updates Annex IV mappings as new standards land.
Article 72 requires every high-risk AI provider to establish and document a post-market monitoring system proportionate to the nature of the AI system. The post-market monitoring plan is part of the Annex IV technical documentation; the active monitoring actively analyzes feedback from deployers + reports on AI system performance + documents any serious incident or malfunction. Article 73 requires that providers of high-risk AI systems report any serious incident to the market surveillance authorities of the Member States where the incident occurred within 15 days of becoming aware of the incident (or earlier for critical-infrastructure incidents causing a breach of EU fundamental rights). The Article 73 notice must include the Member States affected, the AI system characteristics, the circumstances of the incident, and the corrective measures taken or planned.
Article 99 sets the penalty tier system, applied by Member State NCAs proportionate to the nature, gravity, and duration of the infringement. ComplianceStack ranks every EU AI Act exposure against the three tiers plus the GPAI-specific upper cap under Article 101.
| Tier | Trigger (Article 99) | Maximum penalty |
|---|---|---|
| Tier 1 — Art. 99(3) | Article 5 prohibited practices | €35M or 7% of global annual turnover (whichever is higher) |
| Tier 2 — Art. 99(4) | High-risk Articles 9–15 non-compliance | €15M or 3% of global annual turnover (whichever is higher) |
| Tier 3 — Art. 99(5) | Misinformation to authorities + ancillary infringements | €7.5M or 1% of global annual turnover (whichever is higher) |
| Article 101 GPAI cap | Article 51–55 GPAI model provider non-compliance | Up to 3% of global turnover OR €15M (whichever higher) |
Member State NCA designations (Article 70 NCA listings, source: ArtificialIntelligenceAct.eu / Member State designations as of May 14, 2026):
The Commission AI Office is the centralized enforcement body for GPAI models — it can request information from GPAI providers under Article 91, conduct evaluations under Article 92, and apply the Article 101 GPAI penalty cap. Cross-border enforcement coordination flows through the European AI Board established under Article 7.
ComplianceStack packages the EU AI Act readiness program as an 8-obligation, 90-day gap checklist mapped to every Article 9–15 high-risk obligation plus the Article 51–55 GPAI obligations. The 90-day program is the readiness runway between the August 2, 2026 Article 50 transparency deadline and the December 2, 2027 deferred Annex III high-risk enforcement date.
ComplianceStack tracks three sector-specific 2026 EU AI Act readiness roadmaps. The roadmaps share an Articles 9–15 baseline but diverge on which obli gations apply, the conformity-assessment path, and the Member State NCA engagement.
The recommended pathway is Annex IV self-assessment with Annex VII Notified Body engagement reserved for biometric ID or critical-infrastructure scope. The 90-day program covers the full eight-Articles 9–15 obligation matrix (risk management + data governance + technical documentation + record-keeping + transparency + human oversight + accuracy / robustness + cybersecurity); the Annex IV technical-documentation scaffolding; the Annex V EU Declaration of Conformity; the CE marking; and the EU AI database registration. Article 99 Tier 2 penalty exposure: €15M or 3% of global annual turnover, whichever is higher. ComplianceStack pairs the SaaS pattern with the Annex IV Builder + the Article 99 exposure estimator.
Chatbots, AI-generated content, deepfake generation, and emotion-recognition systems in GTM / Sales contexts typically fall under Article 50 limited-risk rather than Annex III high-risk. The recommended pathway is the August 2, 2026 Article 50 transparency obligations: chatbot user disclosure (the user must know they’re interacting with an AI); AI-generated content labeling; deepfake disclosure; emotion-recognition notification. The Commission Code of Practice on AI-generated content, consultation open from May 2026 (closing October 2, 2026), sets the practical implementation expectations. ComplianceStack pairs the GTM pattern with the Article 50 Transparency Notice template + the Code of Practice orientation checklist. Typical 30-day readiness program.
Article 51–55 obligations: training-data summary (Art. 53); Annex XI technical documentation maintained for 10 years; downstream-integration support documentation; systemic-risk classification at the 10^25 FLOPs training-compute threshold (Art. 51); model evaluation, adversarial testing, cybersecurity incident-reporting, energy-efficiency tracking (Art. 54); 15-day serious-incident reporting to the AI Office (Art. 55). Article 101 GPAI penalty cap: up to 3% of global turnover OR €15M, whichever is higher. The 90-day program covers the full Article 51–55 obligation matrix; the Annex XI technical-documentation scaffolding; the 15-day reporting channel setup; the systemic-risk classification decision documentation. ComplianceStack pairs the GPAI pattern with the Annex XI Builder + the 10^25 FLOPs classification calculator + the Article 101 exposure estimator.
Three ComplianceStack tools pair directly with this pillar guide. The EU AI Act report is the lightweight tier-classification diagnostic (under 60 seconds, no signup); the EU AI Act audit is the in-depth Articles 9–15 readiness pass with conformity-path selection; and the 90-day roadmap deliverable converts the 8-obligation gap backlog into a sequenced plan. ComplianceStack pricing covers audit-ready deliverables from free gap-mapping to paid 90-day roadmap reports.
The ComplianceStack EU AI Act Risk Report at /eu-ai-act-report covers every AI system in your EU deployment scope against the Article 5 prohibited list and the Annex III high-risk list, classifies by tier, surfaces the most-cited Article 9–15 deficiency categories — missing risk-management under Art. 9, missing training-data bias examination under Art. 10, missing Annex IV technical documentation under Art. 11, missing automatic logging under Art. 12, missing human-oversight measures under Art. 14, missing adversarial-attack resilience under Art. 15 — with conformity-path recommendation (Annex IV / Annex VII / Art. 48 / sectoral) and a 90-day Art. 9–15 implementation timeline. Output is a PDF deliverable + an interactive checklist view in your account dashboard.
Get the $19 EU AI Act Risk Report →The ComplianceStack EU AI Act Audit at /eu-ai-act-audit runs the deep Articles 9–15 readiness pass across every high-risk AI system in scope. The audit pairs EU AI Act with adjacent frameworks — GDPR Article 22 automated-decision overlap, NIST AI RMF 1.0 GOVERN/MAP/MEASURE/MANAGE alignment, SOC 2 CC6 logical-access crossover, ISO/IEC 42001 Annex A controls. Output: a prioritized 8-obligation gap remediation backlog, conformity-path selection, Article 99 Tier 1/2/3 penalty exposure across the three tiers, Member State DPA designation matrix, 90-day readiness roadmap deliverable, and an EU Declaration of Conformity draft per Annex V.
Run the $199 EU AI Act Audit →The ComplianceStack 90-Day Roadmap at /90-day-roadmap converts the EU AI Act 8-obligation gap backlog into a sequenced implementation plan. Output: a 90-day delivery plan covering Article 9 risk-management system + Article 10 data-governance + Article 11 Annex IV technical documentation + Article 12 record-keeping + Article 13 transparency + Article 14 human oversight + Article 15 accuracy / robustness / cybersecurity + Article 72 post-market monitoring, with named owners, evidence-package expectations, the EU Declaration of Conformity draft per Annex V, and the CE marking + EU AI database registration checklist. ComplianceStack delivers this in 3–5 business days.
Build the 90-Day Roadmap →The ComplianceStack free compliance assessment at /free-compliance-assessment scores EU AI Act alongside GDPR + NIST AI RMF 1.0 + SOC 2 in a single multi-question instrument. Useful for any organization facing EU AI Act exposure alongside adjacent frameworks — GDPR for personal-data-processing AI, NIST AI RMF for the GOVERN/MAP/MEASURE/MANAGE alignment that’s the de facto US-market counterpart, SOC 2 for the enterprise-buyers logical-access cell. Output: every-framework risk score and a cross-framework remediation map.
Open the Multi-Framework Assessment →ComplianceStack pairs every EU AI Act Article 9–15 high-risk obligation with its NIST AI RMF 1.0 function counterpart, its ISO/IEC 42001:2023 Annex A control, its GDPR Article 22 (automated decision-making) overlap, its SOC 2 CC1–CC9 logical-access cell, plus the four primary-source families the roadmap item mandates binding every Article 9–15 row to NIST CSF 2.0 Function/Category/Subcategory, NIST SP 800-53 Rev 5 control family IDs, HIPAA Security Rule §164.302-318 safeguard IDs, and AICPA TSC CC1-CC9 (2022) criterion IDs with named primary-source citations and outbound pillar links. Use this crosswalk to map a finished EU AI Act evidence package to a NIST AI RMF Current-vs-Target Profile without re-papering controls and to demonstrate continued NIST AI RMF + ISO/IEC 42001 alignment to enterprise buyers who request both attestations.
| EU AI Act Article | NIST AI RMF 1.0 Function / Category / Subcategory | ISO/IEC 42001 Annex A | GDPR overlap | SOC 2 Trust Services Criterion (CC1–CC9) | NIST CSF 2.0 Function / Category / Subcategory | NIST SP 800-53 Rev 5 control family | HIPAA Security Rule 45 CFR §164.302-318 (when AI processes PHI) | Primary-source citation |
|---|---|---|---|---|---|---|---|---|
| Art. 9 — Risk-management system | GOVERN-1.1 / 1.2 / 2.1 / 2.2 + MANAGE-1.1 | A.5.1 AI policies + A.5.7 risk management | Art. 35 DPIA (high-risk automated processing) | CC1.1 + CC2.3 + CC3.1 + CC3.2 | GV.RM-01 / GV.RM-04 + ID.RA-01 / ID.RA-04 | RA-3 (Risk Assessment) + PM-9 (Risk Management Strategy) | §164.308(a)(1)(ii)(A) Risk Analysis + §164.308(a)(1)(ii)(B) Risk Management | Reg (EU) 2024/1689 Art. 9 / NIST AI RMF 1.0 (Jan 2023) / NIST CSF 2.0 (Feb 2024) / NIST SP 800-53 Rev 5 / 45 CFR §164.308(a)(1) |
| Art. 10 — Data governance | MAP-1.1 / 1.2 / 1.3 + MEASURE-2.1 / 2.2 / 2.3 | A.6.2 / A.6.3 data quality | Art. 5(1)(b) accuracy + Art. 22(1) profiling logic | CC2.1 + P1.1 + P2.1 + P3.5 (Privacy) | ID.AM-05 / ID.AM-07 + PR.DS-01 + PR.IP-06 | AC-16 (Security Attributes) + SI-7 (Software / Firmware Integrity) + SR-4 (Provenance) | §164.502 Uses / Disclosures of PHI + §164.514 de-identification standard + §164.308(a)(6) Security Incident Procedures | Reg (EU) 2024/1689 Art. 10 / GDPR Art. 5 + 22 / NIST SP 800-53 Rev 5 AC-16 SI-7 SR-4 / 45 CFR §164.502 / §164.514 |
| Art. 11 — Annex IV technical documentation | GOVERN-4.1 (documentation) | A.7.5 documented information | Art. 13 / 14 information obligations | CC2.1 / CC2.3 + CC4.1 | GV.OV-01 / GV.OV-03 + ID.IM-04 | PL-4 (Plan of Action and Milestones) + SA-15 (Development Process / Standards) | §164.316(b)(1) Documentation retention (6 years) + §164.316(b)(2) Availability of documentation | Reg (EU) 2024/1689 Art. 11 + Annex IV / NIST SP 800-53 Rev 5 PL-4 SA-15 / 45 CFR §164.316(b) |
| Art. 12 — Record-keeping / automatic logging | MANAGE-4.1 / 4.2 (logging) | A.8.4 monitoring + logging | Art. 30 records of processing activities | CC7.1 / CC7.2 + CC7.3 + CC7.5 | DE.CM-01 / DE.CM-03 / DE.CM-09 + PR.PT-01 | AU-2 (Audit Events) + AU-12 (Audit Record Generation) + AU-9 (Protection of Audit Info) | §164.312(b) Audit Controls + §164.316(b)(2)(i) Hardware / Software / Procedural mechanisms | Reg (EU) 2024/1689 Art. 12 / NIST SP 800-53 Rev 5 AU-2 AU-9 AU-12 / 45 CFR §164.312(b) |
| Art. 13 — Transparency to deployers | GOVERN-2.3 (transparency) | A.5.8 communication | Art. 13 / 14 transparency obligations | CC2.2 + CC2.3 + CC9.1 (Confidentiality / Privacy) | GV.OC-03 / GV.OC-05 + PR.AT-01 | AT-2 (Security Awareness Training) + PL-4 (Plan of Action) + SI-12 (Information Output Handling) | §164.520 Notice of Privacy Practices + §164.308(a)(5)(ii)(A) Security reminders + §164.404 Individual Notice | Reg (EU) 2024/1689 Art. 13 / GDPR Art. 13 + 14 / NIST SP 800-53 Rev 5 AT-2 SI-12 / 45 CFR §164.520 / §164.404 |
| Art. 14 — Human oversight | GOVERN-3.1 + MANAGE-1.1 / 1.2 / 1.3 | A.5.10 / A.5.11 human oversight | Art. 22(3) right to human intervention | CC1.4 + CC4.2 + CC5.1 (Control Activities) | GV.OV-01 / GV.SC-04 + PR.AT-02 | PS-1 / PS-5 (Personnel Security) + SA-11 (Developer Testing) + AT-3 (Role-Based Training) | §164.316(b)(2)(ii) Workforce training documentation + §164.530(b) Privacy training + §164.308(a)(3)(ii)(C) Termination procedures | Reg (EU) 2024/1689 Art. 14 / NIST SP 800-53 Rev 5 PS-1 PS-5 SA-11 AT-3 / 45 CFR §164.316(b)(2)(ii) / §164.530(b) |
| Art. 15 — Accuracy / robustness / cybersecurity | MEASURE-1.1 / 1.2 + MANAGE-2.1 | A.8.7 / A.8.8 reliability + cybersecurity | Art. 32 security of processing | CC6.6 + CC7.1 + CC7.3 + CC7.4 + A1.2 (Availability) | PR.AC-01 / PR.AC-04 + PR.DS-01 / PR.DS-02 + DE.CM-01 + RS.MI-01 | SC-5 (Denial of Service Protection) + SC-28 (Protection of Information at Rest) + SI-3 (Malicious Code Protection) + IR-4 (Incident Handling) | §164.312(a)(2)(iv) Encryption &decryption + §164.312(e)(2)(ii) Transmission encryption + §164.402(2) Encryption safe-harbor presumption | Reg (EU) 2024/1689 Art. 15 + Recital 96 / NIST SP 800-53 Rev 5 SC-5 SC-28 SI-3 IR-4 / 45 CFR §164.312(a)(2)(iv) / §164.402(2) |
| Art. 51–55 — GPAI obligations | GOVERN-1.1 + MAP-1.1 + MEASURE-1.1 + MANAGE-4.1 | A.5.1 / A.6.2 / A.7.5 / A.8.4 | Art. 22 + Art. 24 data protection by design | CC1.1 + CC2.1 + CC7.1 + P1.1 + P8.1 (Privacy) | GV.SC-01 / GV.SC-09 + ID.SC-04 + RS.CO-04 | SR-1 / SR-3 / SR-6 (Supply Chain) + MA-2 (Controlled Maintenance) + IR-6 (Incident Reporting) | §164.314 BAA organizational requirements + §164.318 Reporting (annual + 60-day breach) + §164.410 Business Associate Notification | Reg (EU) 2024/1689 Art. 51–55 + Annex XI / NIST SP 800-53 Rev 5 SR-1 SR-3 SR-6 MA-2 IR-6 / 45 CFR §164.314 / §164.318 / §164.410 |
Pair this crosswalk with the six pillar references below. Each row can be lifted wholesale into an EU AI Act Article 9–15 evidence cell, an Annex IV technical-documentation section, a NIST AI RMF 1.0 Target Profile cell, an ISO/IEC 42001 Annex A control evidence row, a GDPR Article 22 automated-decision-making cell, or a SOC 2 CC6 logical-access cell — plus the four primary-source families the roadmap item mandates: NIST CSF 2.0 Function/Category/Subcategory binding, NIST SP 800-53 Rev 5 control families (AC/AT/AU/CM/IA/IR/MA/MP/PE/PL/PS/RA/SA/SC/SI/SR), HIPAA Security Rule 45 CFR §164.302-318, and AICPA TSC CC1-CC9 (2022).
The ComplianceStack NIST CSF pillar at /pillar/nist-csf walks the NIST Cybersecurity Framework 2.0 GOVERN / IDENTIFY / PROTECT / DETECT / RESPOND / RECOVER Functions (Feb 2024 release) plus the NIST SP 800-53 Rev 5 control-family crosswalk (AC / AT / AU / CM / IA / IR / MA / MP / PE / PL / PS / RA / SA / SC / SI / SR) that rows in the §8a table resolve to — cell-by-cell binding every EU AI Act Article 9–15 obligation to its GV.RM / ID.RA / PR.AC / PR.DS / DE.CM / RS.MI counterpart. The CORE-Tier profile decision is also covered.
Open the NIST CSF 2.0 Pillar Guide →The ComplianceStack HIPAA pillar at /pillar/hipaa-security-privacy walks the 45 CFR §164.302-318 Security Rule safeguard set that maps onto the EU AI Act Article 10 (data governance → §164.514 de-identification), Article 12 (logging → §164.312(b) Audit Controls), Article 13 (transparency → §164.520 Notice + §164.404 Individual Notice), Article 14 (human oversight → §164.530(b) training), and Article 15 (encryption → §164.312(a)(2)(iv) + §164.402(2) safe-harbor). Any AI system processing ePHI inherits the §164.308(a)(1)(ii)(A) risk-analysis obligation.
Open the HIPAA Pillar Guide →The ComplianceStack CMMC pillar at /pillar/cmmc walks the 32 CFR Part 170 + NIST SP 800-171 Rev 2 110-control framework with the AC / AT / AU / CM / IA / IR / MA / MP / PE / PL / PS / RA / SA / SC / SI family mapping that binds the EU AI Act Article 14 (human oversight → AT-3 / PS-5 / SA-11) and Article 15 (accuracy / robustness / cybersecurity → SC-5 / SC-28 / SI-3 / IR-4) cells when the AI system processes any controlled unclassified information or contractor CUI. DFARS 7012 72-hour incident-reporting obligation is also covered.
Open the CMMC 2.0 Pillar Guide →The ComplianceStack PCI-DSS pillar at /pillar/pci-dss walks the Payment Card Industry Data Security Standard 4.0 Requirements 1–12 (with v3.2.1 retirement deadlines, the brand penalty matrix, and the merchant-level SAQ map). Any AI model ingesting cardholder data inherits the Req 3 (stored data), Req 4 (transmission encryption), Req 10 (logging → EU AI Act Art. 12), and the Req 6 (secure software development → Art. 11 / Art. 15) obligations — so the §8a accuracy / cybersecurity cell resolves to PCI-DSS Req 6.2.4 & Req 10 in the same deliverable.
Open the PCI-DSS 4.0 Pillar Guide →The ComplianceStack GDPR pillar at /pillar/gdpr walks the GDPR Articles 5/6/13/15-22/30/32/33/44-49/83 obligation set that overlaps with EU AI Act Article 10 (data governance) + Article 13 (transparency) + Article 14 (human oversight / Art. 22(3) right to human intervention) + Article 15 (security of processing / Art. 32). The cross-border data transfer mechanism (EU-US DPF, SCCs) is also covered.
Open the GDPR Pillar Guide →The ComplianceStack SOC 2 pillar at /pillar/soc2 walks the AICPA Trust Services Criteria CC1–CC9 (2022 revision) + the CC6 logical-access family + the CC7 system-operations family that map to EU AI Act Article 15 (accuracy / robustness / cybersecurity) and Article 12 (record-keeping / automatic logging). The TSC Category overlap (Security + Availability + Processing Integrity + Confidentiality + Privacy) is also covered.
Open the SOC 2 Pillar Guide →