Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Regulations

EU AI Act

The EU AI Act (Regulation (EU) 2024/1689) is the European regulation that governs the development and use of artificial intelligence systems by their level of risk. It prohibits a small set of practices, imposes strict obligations on high-risk systems (risk management, data governance, documentation, human oversight, accuracy and cybersecurity), sets transparency duties for systems that interact with people or generate content, and regulates general-purpose AI models. Transparency duties have applied since 2 August 2026; stand-alone high-risk obligations apply from 2 December 2027, following the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026).

The risk tiers

Unacceptable risk: practices such as social scoring by public authorities or manipulative techniques, prohibited outright. High risk: systems listed in Annex III (employment, credit, essential services, law enforcement, critical infrastructure among them) and AI embedded as a safety component in products already regulated under Annex I. Limited risk: transparency obligations, for instance telling a person they are interacting with an AI or labeling generated content. Minimal risk: no specific obligation. General-purpose models carry their own documentation and, for systemic ones, evaluation duties.

Provider or deployer, the duties differ

A provider places a system on the market and bears the design obligations: risk management system, data governance, technical documentation, logging, human oversight design, accuracy, robustness and cybersecurity, conformity assessment and registration. A deployer uses it under its authority and must use it as instructed, ensure human oversight, monitor it, keep the logs and, for some uses, assess the impact on fundamental rights. Most enterprises are deployers of several systems and providers of none, which shapes their inventory.

What a governance program does with it

The first artifact is an inventory of AI systems in use with their classification, because every downstream duty depends on it. The second is the link to the existing risk and control program: a high-risk system’s risk management, logging and oversight duties are controls with evidence, like any other, and its residual risk sits in the register. For embedded AI in regulated products, the obligations apply by 2 August 2028, which puts the deadline inside most product roadmaps today.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.