REGULATION · AI ACT
AI Act obligations, governed like the rest of your risk.
Prohibitions apply since February 2025, general-purpose AI duties since August 2025, transparency duties since 2 August 2026, and most high-risk obligations now land on 2 December 2027 after the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026). Mindlapse brings your AI systems into the same verified register as every other risk you steer: inventoried, assessed, evidenced.
WHAT IS THE AI ACT?
The EU’s risk-based framework for artificial intelligence.
The AI Act (Regulation (EU) 2024/1689) is the EU’s horizontal framework for artificial intelligence, in force since 1 August 2024 and applying in stages: prohibited practices and AI literacy since 2 February 2025, general-purpose AI and governance since 2 August 2025, transparency duties since 2 August 2026, most high-risk obligations from 2 December 2027 (deferred by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026)), and high-risk AI embedded in already-regulated products by 2 August 2028.
It is risk-based: a short list of prohibited practices; high-risk AI systems (Annex III areas such as employment, credit scoring or essential services) under the heaviest duties; transparency obligations for limited-risk systems; freedom for the rest. Obligations differ by role: providers who place systems on the market carry most of them, deployers who use them carry their own, from oversight to logging.
For high-risk systems the regulation demands a risk management system, data governance, technical documentation, event logging, human oversight, accuracy, robustness and cybersecurity, plus post-market monitoring. Fines reach 35 million euros or 7% of worldwide turnover for prohibited practices.
THE OBLIGATIONS
What the AI Act actually asks of you.
Know your AI (inventory & classification)
You cannot comply with obligations you have not located: every AI system in use or in build, classified by risk tier and by your role in it, provider or deployer.
Risk management system (Art. 9)
For high-risk AI: identify, evaluate and treat the risks of each system across its lifecycle, as a continuous, documented process, not a one-off assessment.
Human oversight & transparency (Arts. 13-14)
High-risk systems operate under effective human oversight with usable instructions; limited-risk systems tell people they are interacting with an AI.
Documentation & logging (Arts. 11-12)
Technical documentation demonstrating conformity, and automatically recorded logs that make the system’s operation traceable, retained and retrievable.
Robustness & cybersecurity (Art. 15)
Accuracy and resilience against errors and attacks (data or model poisoning, adversarial inputs) consistent with the system’s purpose, with post-market monitoring feeding back what reality teaches.
HOW MINDLAPSE HELPS
AI duties, inside the governance you already run.
The AI Act does not need a parallel compliance program: it needs your AI systems inside the inventory, register and control set your organization already steers.
AI systems in the value chain
The Business Value Chain maps which business functions run on which AI systems and which suppliers stand behind them, so scope is a maintained map, not an annual survey.
AI risk in the same register
Risk Intelligence holds AI risks with likelihood, impact and treatment decisions next to every other cyber risk, one register, one appetite, one escalation path.
Obligations as verified controls
Smart Compliance carries AI Act obligations into your control set with cross-framework mapping and monitors each control continuously, with sourced, dated verdicts.
AI vendors under due diligence
TPRM assesses AI providers like any critical supplier: context-aware questionnaires, contradiction detection, reassessment when models, terms or subprocessors change.
Oversight the board can see
The Cyber Cockpit reports AI posture in the same board-grade views as the rest of your risk: what is deployed, what is verified, which decisions are open.
AI ACT - FAQ
Frequently asked, directly answered.
Who does the AI Act apply to?
Providers who place AI systems on the EU market, deployers who use them in a professional capacity, plus importers and distributors, including providers outside the EU when the system’s output is used in the EU. Most companies are first of all deployers of AI built by others.
What are the deadlines?
In force since 1 August 2024. Prohibited practices and AI literacy apply since 2 February 2025; general-purpose AI obligations and the governance framework since 2 August 2025; Article 50 transparency duties since 2 August 2026; most high-risk obligations from 2 December 2027, deferred by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026); high-risk AI embedded in regulated products by 2 August 2028.
Are we a provider or a deployer?
It is decided per system, not per company. Buying and using a system makes you a deployer; substantially modifying one, fine-tuning it for a new purpose or putting your name on it can make you its provider, with the heavier duties that follow. This is exactly why the inventory comes first.
What changes for a CISO or risk team?
AI joins the governance you already run: an inventory to maintain, risks to assess and treat, controls to operate, oversight to organize and evidence to keep. The discipline is the one cyber teams know, applied to a new class of systems, which is precisely the machinery Mindlapse runs.
Is Mindlapse itself governed AI?
Yes, by construction: the ERNEST engine operates under explicit mechanisms (human-in-the-loop for consequential actions, guardrails, LLM-as-a-judge evaluation and a full AI audit trail) documented in our AI Manifesto and Trust Center. We hold ourselves to the discipline the page describes.
GLOSSARY
Terms to know
AI ACT, OPERATIONALIZED
Your AI, in the register where it belongs.
Bring your list of AI tools, even a rough one. We will show what a governed inventory looks like.