Resources

Regulatory compliance

This pillar positions your AI uses against the EU AI Act and the GDPR: what is prohibited, what is high-risk, the obligations already in force and those coming next, and what you must be able to prove. It does not replace the advice of a lawyer.

General recommendations: the assessment selects those that match your situation and ranks them by priority.

AI Act mapping of your uses

The AI Act does not apply in the same way to every use: some are prohibited, a closed list (Annex III) is “high-risk”, systems that interact with people carry transparency obligations, and the rest is unrestricted. Everything starts with classifying each line of the register of uses. In the vast majority of SMEs, no use is high-risk; you still need to have checked it and be able to show it.

What we recommend

Obligations already in force

Three obligations already apply to every organisation that uses AI: not using prohibited practices (since February 2025), ensuring AI literacy among staff (Article 4, February 2025) and informing people who interact with an AI or receive generated content (Article 50, August 2026). Training and transparency are assessed in the Security pillar; this topic checks prohibited practices and the labelling of content.

What we recommend

High-risk deployer obligations

If you use a high-risk system (for example a CV screening or credit scoring tool), Article 26 imposes a set of concrete obligations on you as a deployer: follow the provider's instructions, assign human oversight to competent people, ensure input data is relevant, monitor operation, keep logs, and inform employees and affected people. Deadline: 2 December 2027. Some organisations must also carry out a fundamental rights impact assessment (Article 27).

What we recommend

GDPR and AI

The GDPR applies in full as soon as an AI tool processes personal data: lawful basis and purpose, information to individuals, contract with the provider, impact assessment for high-risk processing, and safeguards around fully automated decisions. The CNIL has published practical guides that answer most questions.

What we recommend

Sector-specific obligations

In regulated sectors, other rules add to the AI Act and the GDPR: certified health data hosting and medical devices in healthcare, DORA and supervisory expectations in finance, algorithmic transparency and administrative law in the public sector, and NIS 2 for essential and important entities. This topic checks that you have identified them.

What we recommend

Documentation and evidence

A customer, an auditor, the data protection authority or the AI Act supervisory authority will not ask whether you are compliant, but for proof. This topic checks that the evidence exists, can be found and is up to date. It is also the foundation for a possible ISO/IEC 42001 certification, which is becoming a selling point in tenders.

What we recommend

Frameworks

Disclaimer

The information in this pillar is provided for guidance only and does not constitute legal advice. How a use is classified under the AI Act and the GDPR must be confirmed by a lawyer or your DPO.

Where does your organisation stand?

The assessment evaluates these points for your organisation and ranks the actions by priority. Free, about 15 minutes, no account needed.

The other pillars