EU AI Act Compliance Guide for GRC Teams

EU AI Act Compliance: How to Operationalise AI Governance with Symbiant GRC Software

Understand the EU AI Act timeline, risk tiers and key duties—and how connected GRC workflows can support AI governance, oversight and evidence.

Take control of your compliance and risk processes

Move beyond spreadsheets and disconnected systems with a flexible platform that centralises your data, tracks actions, and gives you clear visibility across your organisation.

The The EU Artificial Intelligence Act is the world’s first comprehensive legal framework for artificial intelligence and it’s moving AI governance from principle to practice. It establishes rules for organisations that develop, provide, import, distribute or use AI systems in or affecting the European Union, with obligations determined by the organisation’s role and the risk presented by the system.

For risk and compliance leaders, the challenge is not simply to understand the legislation. It is to turn its requirements into repeatable processes: identifying AI use, classifying systems, assigning accountable owners, maintaining evidence, overseeing suppliers, monitoring performance and incidents, and demonstrating that controls work.

The Act defines the duties. Good governance makes them operational.

Symbiant provides a connected Governance, Risk and Compliance (GRC) environment in which organisations can coordinate that work across risks, controls, policies, assessments, incidents, actions, documents and assurance. It does not replace legal advice, technical testing or conformity assessment. It helps make AI governance visible, owned, evidenced and auditable.

In brief:

What is the EU AI Act?

Regulation (EU) 2024/1689, commonly called the EU AI Act, is the European Union’s horizontal legal framework for artificial intelligence (AI). It seeks to support trustworthy AI while protecting health, safety and fundamental rights.

The Act is built around different levels of risk:

Risk categoryWhat it meansIllustrative examples
Unacceptable riskCertain practices are prohibited because their use is considered incompatible with EU values and fundamental rights.Specified forms of manipulative AI, social scoring and certain biometric practices, subject to the Act’s detailed definitions and exceptions.
High riskPermitted, but subject to extensive requirements for risk management, data governance, documentation, logging, oversight, accuracy, robustness, cybersecurity and post-market monitoring.Certain AI used in recruitment, employment, education, essential services, critical infrastructure, law enforcement, migration, justice and biometrics.
Transparency riskSpecific information or labelling duties apply so that people know when or how AI is involved.Certain chatbots, emotion-recognition or biometric-categorisation systems, deepfakes and AI-generated or manipulated content.
Minimal or no riskNo additional mandatory rules under the Act in most cases, although other laws and voluntary governance still apply.Many administrative, productivity and low-impact AI applications.


The European Commission’s overview of the risk-based approach provides a useful summary. The legal classification of a particular system, however, must be made against the current text of the Act and its intended purpose, not by relying on a generic label such as “HR AI” or “generative AI”.

Not every Annex III use is automatically high-risk

Annex III identifies sensitive use cases, including some employment-related AI. Article 6 also provides limited circumstances in which a listed system may not present a significant risk of harm and may therefore fall outside the high-risk classification. These include some narrow procedural, preparatory or pattern-detection tasks that do not replace or materially influence a human assessment. Systems that profile natural persons remain high-risk when used in an Annex III context.

Providers relying on an Article 6 exception must document their assessment. Organisations should therefore record the system’s intended purpose, affected people, decision context, degree of human influence and classification rationale, and revisit that rationale when the system or its use changes.

Does the EU AI Act apply to UK organisations?

It can. The Act has an extraterritorial reach. It may apply to organisations outside the EU where, for example, they place an AI system or general-purpose AI model on the EU market, or where the output produced by an AI system is used in the EU. A UK headquarters does not, by itself, put an organisation outside scope.

The relevant facts include where the system is offered and used, where its output is used, the organisation’s role in the AI value chain and any applicable exclusions. UK organisations should assess scope system by system and obtain legal advice where the position is uncertain.

The Act can also operate alongside the UK GDPR, EU GDPR, employment and equality law, sector-specific regulation, contractual duties and internal policies. Satisfying one framework does not automatically satisfy another.

The EU AI Act timeline

The implementation timetable has changed. The AI Omnibus entered into force on 27 July 2026 and amended the timing of the high-risk regime.

DateMilestoneWhat organisations should understand
1 August 2024The EU AI Act entered into force.The phased implementation period began.
2 February 2025The original prohibited practices and AI-literacy provisions began applying.Organisations needed to stop the prohibited uses then listed in Article 5 and support the development of appropriate AI literacy among relevant staff and others acting on their behalf.
2 August 2025Governance and general-purpose AI provisions began applying.Obligations for relevant GPAI providers and the EU governance architecture took effect.
2 August 2026Most remaining provisions applied.This included the general enforcement regime and Article 50 transparency obligations, subject to specific transitional provisions.
2 December 2026A new prohibited practice applies.The AI Omnibus added a prohibition covering specified AI systems that generate non-consensual sexually explicit or intimate content or child sexual abuse material.
2 December 2027Annex III high-risk rules apply.The high-risk regime applies to stand-alone use cases listed in Annex III, including specified employment and workforce-management systems.
2 August 2028Annex I high-risk rules apply.The high-risk regime applies to AI systems that are safety components of, or are themselves, products covered by specified EU product-safety legislation.


This is not a reason to delay. Building an inventory, resolving ownership, assessing suppliers, documenting controls and collecting evidence can take substantial time, particularly where AI is already embedded in business software or procured across different functions.

Provider or deployer? Why your role matters

Risk classification is only part of the analysis. Duties also depend on the role an organisation performs.

RoleIn practical termsTypical responsibilities
ProviderDevelops an AI system or GPAI model, or has one developed, and places it on the market or puts it into service under its own name or trade mark.For high-risk systems, responsibilities can include meeting system requirements, maintaining technical documentation and a quality-management system, conformity assessment, registration, post-market monitoring and corrective action.
DeployerUses an AI system under its authority for a professional purpose.For high-risk systems, responsibilities can include following instructions, assigning competent human oversight, monitoring use, keeping logs under its control, ensuring appropriate input data and meeting applicable information, worker-consultation or impact-assessment duties.
Importer or distributorPlaces a third-country system on the EU market or makes a system available in the supply chain.Must perform the checks and actions assigned to that role before making relevant systems available.

An organisation can have more than one role. A customer that substantially modifies a system, changes its intended purpose or places it under its own name may, in defined circumstances, take on provider responsibilities. The European Commission’s AI Act FAQ summarises the allocation of duties, but the facts and contracts should be examined for each use case.

What operational compliance looks like

The EU AI Act cannot be managed effectively as a legal memo stored in a shared drive. It requires an operating model that connects policy decisions with what teams actually do throughout the AI lifecycle.

For high-risk systems, the framework covers areas such as:

  • continuous risk management;

  • appropriate data and data-governance practices;

  • technical documentation and record-keeping;

  • information for deployers;

  • effective human oversight;

  • accuracy, robustness and cybersecurity;

  • quality management and conformity assessment for providers;

  • post-market monitoring, incident reporting and corrective action; and

  • specific deployer duties, including monitoring and maintaining automatically generated logs that are under the deployer’s control.

The exact obligations vary by role and use case. For example, a fundamental-rights impact assessment is required only for the deployers specified in Article 27, not for every organisation using a high-risk system. Workplace information and consultation duties, meanwhile, can apply where a deployer intends to use a high-risk system at work. The detailed deployer requirements are set out in Article 26.

A practical ownership model

The Act assigns legal duties to organisations and economic operators; it does not prescribe a single internal org chart. A workable governance model commonly distributes responsibility as follows:

FunctionPractical contribution
Board and senior leadershipSet the organisation’s risk appetite, approve governance priorities and receive meaningful reporting on material AI risks.
LegalInterpret scope and obligations, advise on contracts and regulatory exposure, and monitor legal change.
Risk and ComplianceMaintain the governance framework, coordinate inventory and classification, map obligations to controls, monitor compliance and escalate exceptions.
AI, Product, Data and IT ownersMaintain system and data documentation, implement lifecycle controls, test performance and manage changes.
Information SecurityAssess security threats, technical safeguards, access, resilience and incident response.
Procurement and Third-Party RiskConduct supplier due diligence, obtain necessary documentation and embed assurance, audit and notification rights in contracts.
HR and operational teamsEnsure permitted use in the real decision context and provide competent, properly authorised human oversight.
Data Protection OfficerPerform the independent advisory and monitoring functions required by data-protection law where personal data is involved.
Internal AuditProvide independent assurance over the design and effectiveness of governance and controls.


This is an illustrative operating model, not a statutory allocation. Named accountability, decision rights and escalation routes should reflect the organisation’s structure and regulated activities.

An eight-step EU AI Act readiness framework

1. Establish a reliable AI inventory

Identify AI developed internally, bought from vendors or embedded within existing platforms. Record the owner, provider, intended purpose, users, affected groups, locations, inputs, outputs, dependencies, data types and lifecycle status.

Discovery should extend beyond tools labelled “AI”. Procurement records, software inventories, privacy records, security reviews and departmental interviews can reveal AI-enabled functionality that a central team does not yet know about.

2. Determine scope and role

For each use case, determine whether the Act applies and whether the organisation is acting as provider, deployer, importer or distributor. Record changes of purpose, branding or substantial modification that could alter the role.

3. Classify the use and document the rationale

Screen for prohibited practices, high-risk use cases and transparency duties. Record the evidence and assumptions supporting the decision, including any reliance on an Article 6 exception. Classification should be approved by competent people and reviewed when the technology, data, users or intended purpose changes.

4. Translate obligations into controls

Map the applicable legal obligations to policies, processes and controls. Identify the control owner, evidence, testing method, frequency, dependencies and treatment of failures. Separate provider controls from deployer controls so that accountability remains clear.

5. Design meaningful human oversight

“Human in the loop” is not sufficient by itself. Oversight personnel need the competence, training, authority, information and practical ability to understand limitations, recognise anomalies, challenge outputs, disregard or override them where appropriate, and stop use when necessary.

6. Assemble the evidence chain

Maintain the documents and records relevant to the organisation’s role: classification decisions, policies, risk assessments, supplier evidence, approvals, instructions for use, training records, test results, logs under organisational control, incident records, monitoring reports and corrective actions.

7. Monitor systems, suppliers and change

Define indicators and thresholds for the risks that matter. Review performance, human interventions, complaints, incidents, overrides, data or model changes and supplier notifications. Escalate warning signals and re-assess the classification and control environment when material change occurs.

8. Test, remediate and report

Use control testing, compliance assessments and internal audit to evaluate whether the governance design works in practice. Assign remedial actions with owners and deadlines, verify completion and give leadership a reliable view of exposure, exceptions and readiness.

How Symbiant GRC Software helps operationalise EU AI Act readiness

Symbiant connects the governance activities that would otherwise sit across spreadsheets, emails, ticketing systems and disconnected repositories. Organisations can configure its modules around their own obligations, roles and risk methodology.

Governance needHow Symbiant can support it
AI inventory and classificationUse configurable Risk Registers and Questionnaires & Assessments to capture AI use cases, ownership, purpose, role, affected groups and classification evidence. Dynamic questions can route reviews according to risk and role.
Risk and control mappingLink identified AI risks to Controls & Policies, objectives, assessments, incidents, indicators and actions. Record owners, testing schedules, evidence and control status in a connected framework.
Supplier and value-chain assuranceUse Due Diligence workflows to assess vendors, collect supporting evidence, score risks, record issues and track remediation. Link supplier findings to enterprise risks and controls.
Policies, decisions and evidenceUse Document Manager as a controlled source for policies and governance records, with approvals, change requests and links to related records. Use Audit Working Papers to assemble assurance evidence.
Human oversight and accountabilityAssign named owners, reviewers, approval steps and actions. Symbiant’s optional AI Assistant is designed to support professional judgement: people review, decide and remain accountable.
Monitoring and early warningConfigure Key Risk Indicators with thresholds and trends relevant to each use case. Link indicators to risks and assessments so that warning signals can trigger review. The underlying technical performance data must be supplied by the relevant system or process.
Incident and issue managementRecord concerns and incidents in Incident Reporter, connect them to the affected risks and controls, and assign follow-up actions with an auditable history.
RemediationUse Action Tracker to assign actions, owners and deadlines; monitor progress; retain evidence; and verify completion across risk, compliance and audit activity.
Assurance and reportingUse assessments, control testing and Audit Working Papers to test governance and provide management with connected reporting on risks, exceptions, overdue actions and assurance findings.
Privacy impact assessmentWhere AI processing also requires a data-protection impact assessment, the DPIA module can link the assessment to risks, controls, incidents and records of processing. A DPIA and an AI Act fundamental-rights impact assessment are related but not interchangeable.

Symbiant does not determine an AI system’s legal classification, generate a provider’s technical file by itself, perform conformity assessment or certify EU AI Act compliance. It gives responsible teams a structured system in which to manage the decisions, controls, evidence, monitoring and remediation that support readiness and demonstrability.

Human-guided AI within Symbiant

Accountability matters in the software used to manage accountability. Symbiant’s optional AI Assistant can help professionals analyse structured GRC information, suggest risks or controls, identify possible duplication and support analysis. Its purpose is to assist—not replace—the person responsible for the decision.

Read more about Symbiant’s human-guided AI capabilities and why human judgement and accountability still matter in agentic AI.

EU AI Act and ISO/IEC 42001

The EU AI Act and ISO/IEC 42001 are complementary, but they are not equivalent. The Act creates legal obligations; ISO/IEC 42001 specifies requirements for establishing, implementing, maintaining and continually improving an AI management system.

An AI management system can provide useful governance structure for policies, roles, risk treatment, performance evaluation and continual improvement. Certification to the standard does not, by itself, prove conformity with the EU AI Act. Organisations should map both frameworks to a shared control environment while retaining the evidence required by each.

What should organisations do now?

Use this checklist to start turning legal analysis into an operational programme:

  • appoint an executive sponsor and cross-functional programme owner;

  • create or validate an organisation-wide inventory of AI use;

  • identify the organisation’s role for each system;

  • screen use cases for prohibited, high-risk and transparency categories;

  • document classification decisions and review triggers;

  • map applicable obligations to named controls and owners;

  • review contracts and assurance evidence for third-party AI;

  • define competent human oversight and escalation authority;

  • support relevant AI literacy and retain records of the measures taken;

  • establish monitoring indicators, incident routes and change controls;

  • track gaps and remediation to verified completion; and

  • schedule independent assurance and regular management reporting.

The strongest programmes do not wait for every standard or template to be finalised. They begin with the facts they can establish now: what AI is used, why it is used, who is accountable, what could go wrong, which controls apply and what evidence exists.

Authoritative sources and further reading

This page provides general information and does not constitute legal advice. The application of the EU AI Act depends on the facts, the organisation’s role and the current law. Obtain qualified legal and technical advice for your circumstances.

Frequently Asked Questions

Is every AI system regulated as high-risk?

No. The classification depends on the intended purpose and the detailed conditions in the Act. Some practices are prohibited, specified systems are high-risk, some uses carry transparency duties and many systems are minimal or no risk under the AI Act. Other laws may still apply.

There should be a clearly accountable programme owner with senior sponsorship, but delivery is cross-functional. Legal interprets obligations; Risk and Compliance coordinate the framework; system and data owners implement lifecycle measures; Security manages technical safeguards; Procurement oversees vendors; operational teams provide human oversight; and Internal Audit provides independent assurance.

The current Article 4 requires providers and deployers to take measures that support the development of AI literacy among relevant staff and other people dealing with AI on their behalf. The appropriate measures should reflect their knowledge, experience, education, training and the context and affected people. The European Commission’s AI-literacy FAQ gives practical guidance. Separate competence and training requirements apply to people assigned to oversee high-risk systems.

No. Human oversight must be effective, and it is only one part of the control framework. The responsible person needs suitable competence, authority, information and time, as well as the ability to challenge or override output and stop the system where appropriate. Other duties may include risk management, data governance, documentation, logging, monitoring, security and transparency.

Penalties vary by infringement; the frequently quoted maximum does not apply to every breach. The Commission’s AI Act enforcement overview describes maximum fines of €35 million or 7% of worldwide annual turnover for prohibited practices, €15 million or 3% for breaches of other obligations, and €7.5 million or 1% for supplying incorrect, incomplete or misleading information, subject to the Act’s detailed rules and treatment of smaller organisations.

No software can guarantee compliance. Symbiant GRC Sofware can help operationalise an organisation’s governance framework by connecting risks, controls, assessments, evidence, incidents, indicators, suppliers, audits and remedial actions. Legal interpretation, technical validation, system documentation, conformity assessment and accountable decisions remain with the relevant organisation and specialists.

No. ISO/IEC 42001 can support a systematic approach to AI governance, but certification is not a substitute for satisfying the Act’s role-specific legal requirements. A mapped, integrated control framework can reduce duplication while preserving the evidence each regime requires.

See how Symbiant can support your AI-governance operating model

EU AI Act readiness is not a one-off classification exercise. It is an ongoing governance discipline spanning systems, suppliers, people, controls, evidence and change.

Symbiant helps bring those elements together in one configurable GRC platform, giving accountable teams a clearer view of AI risk, control effectiveness, incidents and outstanding action.

Stafford Railway Building Society uses Symbiant to enhance compliance and governance

Pricing Disclaimer

* Modules are charged at a standard monthly fee, not on a per-user basis. All users can access each module at any required level. Please note that costs exclude VAT, AI features, and additional modules you may wish to use. User seats are required.