EU AI Act Compliance — Certifyi | Risk-Tier Classification & Controls
EU Regulation 2024/1689

EU AI Act readiness, tiered to your actual risk

The EU AI Act entered into force in August 2024 with obligations phasing in through 2027. Certifyi classifies each AI system you operate into its risk tier — unacceptable, high-risk, limited, or minimal — and builds only the documentation and controls that tier actually requires.

Why this is urgent

Enforcement is phased — but it started already

Prohibited-practice rules and AI literacy obligations were already in force by February 2025, with GPAI and high-risk obligations following through 2027.

01

Deadlines are already active

Prohibited AI practices and staff AI-literacy requirements took effect February 2025. High-risk system obligations follow on a rolling schedule through August 2027.

02

Fines reach €35M or 7% of revenue

Non-compliance for prohibited practices carries the highest penalty tier under the regulation — steeper than GDPR's maximum.

03

Risk-tier classification is not self-evident

Most teams don't know which tier their own AI features fall into, and misclassifying a system means missing controls a regulator will expect.

04

It applies even without an EU entity

The Act has extraterritorial reach — any company placing an AI system on the EU market or affecting EU users is in scope, regardless of where it is incorporated.

How Certifyi is different

Tiered documentation, not a blanket compliance project

You get exactly the controls your risk tier requires — nothing generic, nothing missing.

Risk-tier classification

Every AI system you operate assessed and classified against the Act's risk categories, with the reasoning documented for regulators and auditors.

High-risk system documentation

Technical documentation, risk management system, and human-oversight controls built to the Annex IV requirements for systems that need them.

Transparency & disclosure controls

User-facing disclosure templates for AI interaction, synthetic content labeling, and emotion-recognition notices where required.

Conformity assessment prep

Documentation packaged for internal or third-party conformity assessment ahead of your system's applicable deadline.

Your roadmap

The path to EU AI Act readiness

A proven 3-phase process, scoped to the deadlines that actually apply to your systems.

Week 0-2: System Inventory & Risk Classification

Catalog every AI system in scope and classify each against the Act's risk tiers, with documented reasoning.

Deliverable: Risk Classification Report

Week 2-8: Control & Documentation Build

Build only the technical documentation, transparency disclosures, and oversight controls your classified tier requires.

Deliverable: Tier-specific control set

Week 8-12: Conformity Prep & Monitoring

Package documentation for conformity assessment and stand up ongoing monitoring ahead of your deadline.

Deliverable: Conformity-ready documentation package
The business impact

What changes when your risk tiers are documented

Clarity on obligations, not blanket over-engineering.

4

Risk tiers classified

Every AI system mapped to unacceptable, high-risk, limited, or minimal risk — with reasoning documented.

€35M

Maximum exposure addressed

Documented prohibited-practice screening and high-risk controls address the Act's steepest penalty tier.

12 wks

To conformity-ready documentation

Structured, tier-specific work instead of an undifferentiated compliance sprint across every system you operate.

Common questions

EU AI Act, answered

The EU AI Act (Regulation 2024/1689) is the European Union's risk-based regulation for AI systems, entering into force in August 2024 with obligations phasing in through August 2027. It classifies AI systems into unacceptable, high-risk, limited, and minimal risk tiers, each with different requirements.

Yes. The Act has extraterritorial reach — it applies to any provider or deployer placing an AI system on the EU market or whose AI system's output affects people in the EU, regardless of where the company is incorporated.

High-risk systems require technical documentation, a risk management system, human oversight measures, and (for many systems) a conformity assessment before market placement. Certifyi builds this documentation package to the Act's Annex IV requirements.

Typically 8-12 weeks from system inventory to conformity-ready documentation, scoped to the specific tier and deadline that applies to each system you operate rather than a one-size-fits-all program.

Ready when you are

Get your EU AI Act scoping call

30 minutes to classify your AI systems and get a fixed-price quote.

Pay-at-signoff pricing · 50% upfront, 50% when your documentation is delivered

Scroll to Top