Skip to Content

AI Act: European AI regulation

The AI Act is the first comprehensive legal framework governing artificial intelligence in the European Union. Its principle: to adjust obligations according to the risk level of each AI system. Here is what your organization needs to anticipate.

BCIT Formation logo
BCIT Formation is rated Excellent
4,7 · Trustpilot
🎓 +1000 learners trained

Risk-based regulation

Rather than imposing the same rules on all AI systems, the AI Act adopts a tiered approach: the greater the risks a system poses to people's rights, safety, or health, the stricter the obligations. A simple content recommendation tool and a CV screening system are not treated in the same way.

The regulation applies to both providers and deployers of AI systems whenever they operate on the European market. Its implementation is phased in over time, leaving a window to prepare methodically, ideally by relying on the standard ISO 42001.

The four risk levels

Unacceptable risk

Certain uses are prohibited (generalized social scoring, behavioral manipulation, etc.) because they conflict with fundamental values.

High risk

AI used in sensitive areas (HR, credit, healthcare, safety, etc.): enhanced obligations for risk management, documentation, human oversight, and traceability.

Limited risk

Systems such as conversational agents: a transparency obligation (the user must know they are interacting with an AI system).

Minimal risk

The vast majority of uses (anti-spam filters, suggestions, etc.): few or no specific obligations, with good practices encouraged.

Who is concerned?

Any organization that designs, integrates, or uses an AI system for the European market is potentially concerned (including when the AI comes from a third-party provider). The first step is to map its AI systems and classify them by risk level. This is precisely what an AI management system structures according to ISO 42001, in line with an audit such as theAI & LLM security audit.

Anticipate rather than react

The AI Act cannot be addressed on the eve of the deadline. The right approach is to inventory AI systems, classify them, identify those that are high risk, then build the expected documentation and governance: risk analysis, human oversight, data quality, traceability, incident management. An approach that naturally aligns with an SMSI ISO 27001 and a logic of governance, risk & compliance (GRC).

Prepare for the AI Act, step by step

1

Map your AI systems

Inventory the AI systems designed, integrated, or used, their purposes, and their providers.

2

Classify by risk level

Determine, for each system, its category under the AI Act and the associated obligations.

3

Structure governance

Define roles, human oversight, and processes, ideally through an SMIA ISO 42001.

4

Document & trace

Build the compliance file: data, tests, logs, risk and incident management.

5

Secure AI systems

Test model robustness through an AI & LLM security audit.

6

Maintain compliance

Track deadlines, reassess systems, and update documentation as things evolve.

Why get support from BCIT?

A clear reading of the framework

We translate the AI Act into concrete obligations for your real-world use cases, without unnecessary legal jargon.

An integrated approach

We consolidate the AI Act, ISO 42001 and ISO 27001 to avoid duplication.

From scoping to audit

From classification to theAI audit, we cover the entire compliance journey.

Let's get ahead of the AI Act 🚀

Let's take 15 minutes to map your AI uses and build a realistic AI Act compliance roadmap.