Lesson 4 of 11 · Frameworks · 3 min read

EU AI Act compliance software: what it needs to do

In brief

The EU AI Act sorts AI systems by risk and sets obligations for providers and deployers. Compliance software helps by classifying systems, recording controls, logging behavior and producing documentation. No software makes a system compliant on its own.

By The Charter Desk, Agentic Governance Compare · Published 2026-09-07 · Vendor pages read 7 September 2026 · Editorial assessment

What is the EU AI Act?

The EU Artificial Intelligence Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024. It regulates AI systems placed on the EU market or used in the EU, with obligations that apply in stages. Check the official text and timeline for the dates that apply to your systems; this lesson describes structure, not deadlines.

How does the Act sort AI systems?

The Act takes a risk-based approach:

  • Prohibited practices: a short list of uses that are banned outright.
  • High-risk systems: systems used in listed areas, such as employment, credit, education and access to essential services, or as safety components of regulated products. Most of the detailed obligations apply here.
  • Transparency obligations: for example, people must be told when they are interacting with an AI system, and certain generated content must be labelled.
  • General-purpose AI models: separate obligations for the providers of the models themselves.

Who has obligations?

The Act distinguishes roles. A provider develops an AI system or has it developed and places it on the market under its name. A deployer uses an AI system under its authority. Importers and distributors have their own duties. A company that builds a customer-facing assistant on a third-party model is usually the provider of that assistant and a deployer of it at the same time.

What do high-risk obligations ask for?

For high-risk systems, providers need a risk management system, data governance, technical documentation, record-keeping through automatic logs, transparency information for deployers, human oversight, and appropriate accuracy, resilience and cybersecurity, followed by a conformity assessment and post-market monitoring. Deployers must use systems according to instructions, assign human oversight and keep the logs under their control.

Which of these can software support?

  • Classification: a register that records each system's risk level and role (provider or deployer).
  • Risk management and testing: documented tests before launch and after, including adversarial testing.
  • Logging: automatic records of inputs, outputs and decisions.
  • Human oversight: approval steps and the ability to stop or override.
  • Documentation: technical files and reports mapped to the Act's articles.
  • Post-market monitoring: ongoing tests and drift detection after launch.

Five of the six platforms on this site name the EU AI Act on the pages we read: Alice, Credo AI, Holistic AI, Pillar Security and Lasso. SPLX describes mapping to global and custom standards. Naming the Act is the start; ask each vendor to show which article each report section supports.