EU AI Act compliance with RecordPoint
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive law governing artificial intelligence. It sets risk-based obligations for organizations that develop, deploy, or supply AI systems connected to the EU market, spanning data governance, record-keeping, transparency, and human oversight. With RecordPoint, you can govern the data and systems behind your AI, and stay ready to prove it.
Govern and evidence your AI systems


See and control every AI system in use
Give your high-risk AI only governed data

What is the EU AI Act?
The Act applies beyond the EU's borders. Any organization that places an AI system on the EU market, puts one into service in the EU, or whose system's output is used in the EU falls in scope, wherever it is based. Separate obligations apply to providers of general-purpose AI models.
Obligations apply in phases. Prohibited practices and AI literacy duties applied from February 2025, and general-purpose AI model rules and penalties from August 2025. Following the 2026 Digital Omnibus, the main high-risk obligations apply from December 2027, and AI embedded in regulated products from August 2028.
The four risk tiers:
Lorem ipsum
Compliance with the EU AI Act
Any organization that develops, deploys, or supplies high-risk AI connected to the EU market must meet the Act's core obligations. For high-risk systems, the main requirements are:
Risk management system (Article 9).
Establish and maintain a continuous, documented process to identify, evaluate, and mitigate risks across the AI system's lifecycle.
Data and data governance (Article 10).
Ensure training, validation, and testing data is relevant, sufficiently representative, examined for bias, and as free from errors and as complete as possible for the intended purpose.
Technical documentation (Article 11).
Keep documentation that shows how the system meets the Act's requirements, ready to provide to regulators.
Record-keeping and logging (Article 12).
Automatically log events over the system's lifetime so its behavior can be traced and reconstructed.
Transparency and information (Article 13).
Make the system transparent enough that deployers can understand its output and use it correctly.
Human oversight (Article 14).
Design systems so people can effectively oversee them, intervene, and stop them when needed.
Accuracy, robustness, and cybersecurity (Article 15).
Ensure the system performs consistently and resists errors, faults, and manipulation.
Quality management system (Article 17).
Operate a documented quality management system covering the obligations above.
Registration and post-market monitoring (Articles 16, 18, and 72).
Register high-risk systems, retain documentation, and monitor performance after the system is on the market.
Penalties for noncompliance
The EU AI Act carries some of the steepest penalties in technology regulation. The most serious breaches, involving prohibited AI practices, can reach 35 million euros or 7% of global annual turnover, whichever is higher. Breaches of high-risk or transparency obligations can reach 15 million euros or 3%, and supplying incorrect or misleading information to authorities up to 7.5 million euros or 1%. Caps are set proportionately, with lower ceilings for SMEs and start-ups.
Frequently asked questions
It applies to providers, deployers, importers, and distributors of AI systems connected to the EU market, including organizations based outside the EU whose AI systems or their outputs are used in the EU.
Systems used in areas the Act treats as high-risk, such as recruitment and worker management, credit scoring, education, biometric identification, essential public and private services, law enforcement, and critical infrastructure.
In phases. Prohibited practices have applied since February 2025 and general-purpose AI model rules since August 2025. Following the 2026 Digital Omnibus, obligations for stand-alone high-risk systems apply from December 2027 and for AI embedded in regulated products from August 2028.
RecordPoint governs the AI systems and the data foundation the Act depends on. It helps you inventory AI systems, govern their data, and produce audit-ready evidence, which supports your conformity obligations rather than completing them on its own.
Explore EU AI Act articles & case studies
Regulatory breakdowns, expert commentary, and real-world case studies: everything you need to decode complex EU AI Act requirements, build a defensible AI governance strategy, and learn from how regulated organizations are preparing.


