Regulation · EU Regulatory Framework

AI Act — product regulation arrives for algorithms

The world's first horizontal AI law works like CE marking: risk classes, conformity assessment, technical documentation, market surveillance. If you know product certification, the AI Act is familiar territory — which is precisely IOTR's angle on it.

At a glance

Approach

Risk-tiered

Prohibited practices · high-risk systems · transparency cases · minimal risk

High-risk duties

Full conformity machinery

Risk management, data governance, logging, robustness, human oversight, QMS

Two high-risk routes

Annex III + embedded AI

Listed use cases (hiring, credit, infrastructure…) and AI as safety component in regulated products

GPAI

Model-level duties

Documentation, copyright policy; systemic-risk models face evaluations and reporting — since Aug 2025

Assessment

Mostly self, sometimes notified

Internal control for most Annex III; notified bodies for biometrics and embedded routes

Penalties

Up to €35M / 7%

For prohibited practices; lower tiers for other breaches

What it is

New Approach mechanics under unfinished scaffolding

Strip away the discourse and the AI Act is a product regulation: providers of high-risk AI systems run a risk management system, govern their training data, document the system, log its operation, ensure accuracy, robustness and cybersecurity (Article 15), keep humans meaningfully in the loop, pass conformity assessment and affix a CE mark. Deployers get lighter duties; importers and distributors inherit the usual chain obligations. Anyone who has built a CRA or machinery-directive file recognises the architecture immediately.

High-risk status arrives by two roads: Annex III use cases — biometrics, critical infrastructure management, employment, credit, essential services, law enforcement — and AI as a safety component of products already under EU harmonisation law, where AI Act conformity folds into the existing product’s assessment. GPAI models carry their own regime, in force since August 2025, with systemic-risk models facing model evaluations and incident reporting under the Commission’s AI Office.

The honest mid-2026 picture: the high-risk obligations reach their main application milestone in August 2026, while the scaffolding is still going up — harmonised standards from CEN/CENELEC JTC21 are not finished, notified-body capacity is embryonic, and the Commission’s digital omnibus discussions have put timeline adjustments for parts of the high-risk regime on the table. Uncertainty about dates, however, changes nothing about direction: the evidence disciplines the Act demands take years to build, and they are the same disciplines the rest of your certification portfolio already requires.

Key dates

The AI Act clock, as of July 2026

2 Feb 2025 DONE

Prohibitions apply

Banned practices (social scoring, certain biometrics) enforceable

2 Aug 2025 DONE

GPAI regime live

Model documentation duties; AI Office oversight of systemic-risk models

2 Aug 2026 DONE

Main application milestone

Core high-risk framework scheduled to apply — amid live omnibus debate on adjustments

2027

Embedded-AI route & standards

High-risk via product legislation follows; harmonised standards mature through 2027

What it means for you

Four moves that don't depend on Brussels' calendar

Classify the portfolio, in writing

Which systems are high-risk, by which route, who is provider vs. deployer — plus the borderline cases documented. Classification drives everything, and regulators will ask for the reasoning.

Build the evidence engine, not a binder

Logging, data lineage, evaluation results, robustness testing — produced continuously by the ML lifecycle, not reconstructed for audits. Retrofitting traceability onto a deployed model is the expensive path.

Merge Article 15 with your security programme

Accuracy, robustness and cybersecurity of AI systems overlap CRA Annex I and ISO 27001 territory. One risk framework covering both saves an entire parallel compliance function.

Watch the omnibus — but don't bet on it

Timeline relief may come for parts of the high-risk regime. Capabilities take longer to build than deadlines take to move; the direction of travel has not changed once since 2021.

Expert notes

What we tell clients before they commit

Treat it as product certification, because it is

The organisations moving fastest on the AI Act are not the ones with AI ethics boards — they are the ones with CE-marking muscle memory. Technical documentation, QMS integration, conformity assessment logistics, post-market monitoring: the Act reuses the machinery of European product law, and the skills transfer directly. The genuinely new work is narrower than it looks: data governance evidence, model evaluation methodology, and human-oversight design that survives scrutiny.

Our position: staff AI Act compliance from your certification and quality functions, augmented by ML engineering — not the other way around. The regulation speaks conformity, not data science.

Accuracy, robustness and cybersecurity for high-risk AI — including resistance to data poisoning, adversarial examples and model extraction — lands on the same desk as CRA Annex I and your ISO 27001 scope. Running separate AI-security and product-security risk assessments produces contradictions; a shared threat model with AI-specific extensions produces one defensible story. The standards landscape is converging the same way: JTC21’s work leans on existing security standards wherever it can.

Our position: extend your existing security risk framework with AI failure modes rather than adopting a parallel AI-risk universe. One framework, two regulatory outputs — the pattern that works everywhere else in this portfolio works here too.

AI conformity, run by certification people

Classification, evidence architecture, Article 15 integration, notified-body strategy — thirty minutes to a plan that doesn’t wait for Brussels.

Contact us

Request this document

We’ll send you access by email.