Answer · updated

What does the EU AI Act require from a company deploying high-risk AI?

Three obligations do most of the work: a documented, lifecycle-long risk management system (Article 9); quality and governance criteria for training, validation and test data (Article 10); and demonstrated, maintained accuracy, robustness and cybersecurity (Article 15). The common thread is evidence a reviewer can check. This is not legal advice.

Regulation (EU) 2024/1689 — the AI Act — regulates AI systems according to the risk they pose, with the heaviest obligations on systems classed as high-risk: AI used in areas such as employment, credit, insurance, essential services and medical contexts. Three of its articles do most of the work for anyone preparing a high-risk system, and they are worth reading in the original.

The three articles that shape the engineering

Article 9 requires a risk management system: documented, maintained across the system's whole lifecycle, covering the identification, evaluation and treatment of risks. Not a one-off assessment — a living process with records.

Article 10 sets quality criteria for the data used to train, validate and test a high-risk system: governance over its collection and origin, examination for possible biases, and attention to gaps between the data and the population the system will serve. Data work, in other words, becomes a compliance artefact, not just an engineering convenience.

Article 15 requires that high-risk systems achieve appropriate accuracy, robustness and cybersecurity, and perform consistently on those measures throughout their lifecycle. Declared accuracy has to be demonstrated, and maintained, not asserted once at launch.

What this means in practice

The common thread is evidence. Each requirement implies records a reviewer can check: risk registers with treatments, dataset documentation with bias examinations, test results with the criteria they were judged against. Organisations that already test systematically — agreed pass marks, per-group results, versioned re-tests — find the distance to these obligations short. Organisations that rely on demos find it long.

On timing, one caution

The Act's application dates for high-risk obligations have been amended since the original text — the European Commission's Digital Omnibus on AI, in force since July 2026, moved key high-risk dates later. Do not rely on dates quoted in older articles, this one included: check the current consolidated text or the European Commission's AI Act pages for the timeline that applies to your system.

This page describes the regulation to help you plan engineering and evidence. It is not legal advice; classification of your system and your obligations under the Act are questions for your counsel.

Related questions

Which AI systems count as high-risk?

Broadly, systems used in areas the Act lists — employment, credit, insurance, essential services, medical contexts and others. Classification is fact-specific and is a question for counsel; the current text on EUR-Lex is the authority.

When do the high-risk obligations apply?

The dates have moved. The Digital Omnibus on AI, in force since July 2026, pushed key high-risk application dates later than the original text. Check the European Commission's AI Act pages rather than relying on older articles.

What evidence should a deployer start collecting now?

Risk registers with treatments and owners, dataset documentation including bias examination, agreed acceptance criteria, and versioned test results — each finding traceable to a test and each test to a requirement.

Related Qylis capability

AI Testing & Certification

Test AI solutions for accuracy, safety and conformity, and prepare them for external certification.

Discuss your requirement