chapter seven

7 Regulation and Compliance

 

This chapter covers

  • Preparing for your discussions with Legal, although it does not provide legal advice.
  • An overview of high-risk systems under the EU AI Act
  • Legal roles (provider, deployer, or GPAI provider) and how they can change
  • Mapping best practices from Chapters 3 through 6 to specific regulatory obligations
  • What evidence you need before your system goes live

Does our RAG pipeline count as an AI system? We fine-tuned a vendor model on our data and deployed it internally, but our vendor says they handle compliance. Can we rely on that? Is my AI-driven personalized marketing system a high risk one? What about my internal agent that talks to my colleagues on a Slack channel and can run sensitive SQL queries?

When the European Commission published its AI Act proposal in April 2021, the accompanying Impact Assessment estimated that only 5-15% of AI systems would qualify as high-risk[1]. However, a 2023 study of 106 enterprise systems found that 18% of the systems could be categorized as high-risk, while 40% could not be clearly classified into a risk tier at all, meaning they could eventually end up in the high-risk category[2]. The Act’s first prohibitions took effect in February 2025[3]. GPAI provider obligations followed in August[4]. Many teams developing AI systems still aren’t sure what legal obligations they have for their AI system.

7.1 The Regulatory Landscape

7.2 Classifying Your System

7.2.1 Is It an AI System at All?

7.2.2 Prohibited practices

7.2.3 High Risk Classification

7.2.4 General Purpose AI (GPAI) Models

7.2.5 Transparency and AI Literacy Obligations

7.3 Roles and Duties

7.3.1 Provider, deployer, and other roles

7.3.2 When a deployer becomes a provider

7.3.3 What high-risk providers must do

7.3.4 What high-risk deployers must do

7.3.5 What your model provider owes you

7.3.6 Finding yourself on the map

7.4 What you already have and what’s still missing

7.4.1 Are your existing frameworks enough?

7.4.2 The evidence pack for providers

7.4.3 The evidence pack for deployers

7.5 Living Compliance

7.5.1 Post-market monitoring

7.5.2 Incident reporting

7.5.3 Regulatory sandboxes and SME provisions

7.6 ClaimAssist across the risk thresholds

7.7 Summary