Regulation (EU) 2024/1689

Comply with the EU AI Act with confidence

Understand what the AI Act requires in your specific case and get ready with a European GRC expert — without starting from scratch or relying on spreadsheets.

  • AI system inventory and risk-level classification
  • Conformity, technical documentation and continuous monitoring
  • AI Act, ISO 42001, GDPR and NIS2 on a single platform
Request a demo

Talk to our team

We'll show you how to get ready for the AI Act. No commitment.

This field is for validation purposes and should be left unchanged.
Cláusulas legales*

The regulation

All your AI Act compliance on a single platform

Prepare for Regulation (EU) 2024/1689 with GlobalSuite®, the platform that helps you inventory your AI systems, classify them by risk level and manage conformity end to end. The AI Act applies to providers and deployers of AI operating in the EU — and to organisations outside it when the output is used within the Union. GlobalSuite® turns a complex legal text into a clear, actionable plan.

Don't start from scratch. Reuse the controls you already manage — ISO 27001, GDPR, NIS2 — and map them to the AI Act articles, building on ISO/IEC 42001 as a certifiable AI management system. Expert software and consultancy from a European vendor aligned with the EU AI Office, so you can demonstrate compliance with confidence and stay in control continuously, not just at a single point in time.

The AI law, in plain terms

What applies, and when

The AI Act applies in phases. These are the milestones that set your obligations.

Aug 2024
Entry into force
Regulation (EU) 2024/1689 enters into force and the clock starts.
Feb 2025
Prohibitions
Unacceptable-risk AI systems are banned.
Aug 2025
GPAI models
Obligations for general-purpose AI models.

The AI Act's four risk levels

Level 1

Unacceptable

Prohibited practices: manipulation, social scoring, intrusive biometrics.

Level 2

High

Subject to conformity, technical documentation and continuous monitoring.

Level 3

Limited

Transparency obligations towards users.

Level 4

Minimal

No specific obligations; good practices recommended.

The platform

Govern all your AI from one powerful, flexible platform

From inventory to post-market monitoring, in a single workflow. No spreadsheets, no scattered emails.

Company/MS Darrell StewardDS
InventoryAI systems
AI system inventory24 systems registered
Add AI panel
CodeAI systemAreaLevel
AI-01
Credit scoring model
Provider · credit decisions
RiskHigh
AI-02
CV screening
Provider · recruitment
HRHigh
AI-03
Customer service chatbot
Deployer · support
CXLimited
AI-04
Email anti-spam filter
Internal · productivity
ITMinimal
AI-05
Remote biometric identification
Pilot · prohibited practice
SecurityUnacceptable
AnalysisRisk analysisHigh-risk AI systems
Risk-level classification
Add Rating AI panel
CodeRiskRatingLevel
Ag-01
Discriminatory bias in scoring
Assess the model's fairness (Art. 10)
82.00High
Ag-02
Lack of human oversight
Ensure effective human oversight (Art. 14)
65.00Medium
Ag-03
Ungoverned training data
Dataset traceability and quality
90.00High
Ag-04
Insufficient explainability
Transparency towards the user
40.00Low
Ag-05
Unauthorised biometric use
Prohibited practice (Art. 5)
100.00Unacceptable
ComplianceEU AI ActGap analysis
78%
EU AI Act complianceAI-assisted gap analysis · 42 requirements assessed
30
Requirements covered
8
Partial coverage
4
Gaps detected
ArticleRequirementAI status
Art. 9Risk management systemCovered
Art. 10Data governance and qualityPartial coverage
Art. 11Technical documentation (Annex IV)Evidence missing
Art. 14Human oversightCovered
Art. 15Accuracy, robustness and cybersecurityNot covered
AnalysisContinuous monitoringEvidence
Continuous monitoring and evidencePost-market monitoring · latest cycle
Export
EvidenceStatusUpdated
Scoring model log recordsUp to datetoday
Human oversight surveyCompleted2 d
Post-market reviewPending5 d
Signed technical documentation (v3)Current1 wk

And everything you need around it

Multi-framework mapping

Reuse your ISO 42001, ISO 27001, GDPR and NIS2 controls and map them to the AI Act articles that apply to you, without duplicating work.

Technical documentation (Annex IV)

Generate and maintain the technical documentation and records required of high-risk AI systems.

AI risk management

Identify, assess and treat the risks of your AI systems with customisable methodologies and impact-likelihood matrices.

Built-in artificial intelligence

GlobalSuite Quantum uses AI to speed up risk classification, drafting and review. The smartest GRC. Now powered by AI.

API integrations

Sync data between your systems and GlobalSuite® through the API for an always up-to-date AI inventory.

Process automation

Automate repetitive compliance workflows and focus on the strategic decisions.

Everything on a single platform

Centralise AI Act compliance alongside the rest of your frameworks — ISO 42001, ISO 27001, GDPR, NIS2 — and leave spreadsheets and scattered emails behind.

Always ready to prove it

Every AI Act obligation is backed by tasks, owners and traceable evidence, ready to present in an audit or to the authorities.

European software and consultancy

More than 2,000 GRC projects delivered, plus specialists who follow the guidance of the EU AI Office and support you end to end — not just software.

You're not starting from scratch

The AI Act fits with what you already do

Reuse the frameworks you already run and manage compliance in one place.

Mandatory · EU

EU AI Act

Regulation (EU) 2024/1689. Inventory, risk classification, conformity and continuous monitoring.

You are here

GDPR

Personal data protection. The data governance foundation the AI Act builds on.

View solution

ISO/IEC 42001

A certifiable AI management system. The natural complement for demonstrating governance.

View solution

NIS2

Cybersecurity for essential sectors. Controls that map to the AI Act's.

View solution

Leading companies that trust GlobalSuite®

Banking & Finance Enterprise 1,000+ Risk

GlobalSuite® has enabled us to strengthen our business resilience by anticipating risks with a global view of all assets and controls.”

Banking & Finance Enterprise 1,000+ Integrated management

We achieved a global view of all our management systems on a single platform, simplifying corporate governance.”

Insurance Enterprise 1,000+ Risk

We have centralized all risk management on a single platform, eliminating Excel and improving operational efficiency.”

Cybersecurity Enterprise 1,000+ ISMS

We automated ISMS management, reducing the time spent on audits and gaining real-time visibility into compliance.”

To keep moving forward

Resources

Product sheet

AI Governance

Download the datasheet for our AI governance solution: capabilities, scope and how it gets you ready for the AI Act.

Download PDF
Download

White papers

In-depth guides and analysis on AI, GRC and European regulation.

View white papers
Webinar

Live sessions

Register for our webinars on the AI Act, ISO 42001 and AI governance, or watch the recordings whenever you like.

View webinars

Common questions

Frequently asked questions about the AI Act

When does the AI Act start to apply?
The Regulation entered into force in August 2024 and applies in phases: the prohibitions from February 2025, the obligations for GPAI models from August 2025 and the requirements for high-risk systems (Annex III) from December 2027, with August 2028 for AI embedded in regulated products (Annex I).
Who does it apply to?
Providers and deployers of AI systems operating in the EU, and also organisations outside the Union when the system's output is used within it.
What is a high-risk AI system?
Systems that can significantly affect people's safety or fundamental rights (for example, in employment, credit, education or critical infrastructure). They are subject to conformity, technical documentation and continuous monitoring.
What are the penalties?
Up to €35M or 7% of turnover for prohibited practices; up to €15M or 3% for breaching high-risk obligations; and up to €7.5M or 1% for supplying incorrect information to the authorities.
Who supervises the AI Act?
The European AI Office coordinates application across the Union, working alongside the national supervisory authority that each Member State designates.
Does the AI Act replace the GDPR?
No. They are complementary: the GDPR governs the processing of personal data and the AI Act governs AI systems. Many of the GDPR's data governance controls can be reused for the AI Act.
How can I get ready?
Start by inventorying your AI systems and classifying them by risk level. From there, GlobalSuite® guides you through conformity, documentation and continuous monitoring, reusing the controls you already manage.

Get ready for AI Act compliance today

Talk to our team and take the first step with a European GRC expert.

Request a demo