AI governance frameworks: Compare
A learning aid, not legal advice.
| Dimension | EU AI Act (Regulation (EU) 2024/1689) binding law |
|---|---|
| Nature | Depth 3 of 3. A regulation that applies directly in every Member State, backed by administrative fines. Reg. (EU) 2024/1689, Art. 99 |
| Where and to whom it applies | Depth 3 of 3. Reaches providers placing AI on the EU market wherever they are established, deployers in the EU, and importers and distributors. Art. 2 (Scope) |
| Roles addressed | Depth 3 of 3. Defines provider, deployer, importer and distributor, and gives each its own list of duties (for example Art. 16 for providers and Art. 26 for deployers of high-risk systems). Art. 3 (Definitions); Art. 16; Art. 26 |
| Risk approach | Depth 3 of 3. Tiers: prohibited practices, high-risk systems (Annex I products and Annex III uses), transparency duties for certain systems, and separate rules for general-purpose AI models. Art. 5; Art. 6 and Annex III; Art. 50; Art. 53 |
| Inventory and documentation | Depth 3 of 3. High-risk providers draw up technical documentation before market placement, keep automatic logs, and register Annex III systems in the EU database; public-body deployers register their use. Art. 11 and Annex IV; Art. 12; Art. 49; Art. 71 |
| Risk or impact assessment | Depth 3 of 3. Providers run a risk management system across the life cycle; public bodies and certain private deployers carry out a fundamental rights impact assessment before use and notify the authority. Art. 9; Art. 27(1) to (3) |
| Human oversight | Depth 3 of 3. High-risk systems are designed so people can understand, override or stop them; deployers assign oversight to competent people with authority. Art. 14(1) to (4); Art. 26(2) |
| Transparency and notices | Depth 3 of 3. Instructions for use to deployers; telling people they deal with AI; machine-readable marking of synthetic content; deepfake disclosure; a right to an explanation of certain decisions. Art. 13; Art. 50(1) to (4); Art. 86 |
| Data governance | Depth 3 of 3. Training, validation and testing data for high-risk systems must follow data governance practices and be relevant and sufficiently representative; special-category data may be used for bias correction under safeguards. Art. 10(2) to (5) |
| Testing, robustness and security | Depth 3 of 3. High-risk systems must reach appropriate accuracy, robustness and cybersecurity, including measures against data and model poisoning and adversarial examples; testing is part of risk management. Art. 15(1) to (5); Art. 9 |
| Monitoring and incident reporting | Depth 3 of 3. Providers run post-market monitoring and report serious incidents within 15 days, 10 days where a person died, 2 days for widespread infringement or critical infrastructure; deployers inform the provider immediately. Art. 72; Art. 73(2) to (4); Art. 26(5) |
| Assurance and enforcement | Depth 3 of 3. Conformity assessment before market placement for high-risk systems; market surveillance authorities; fines up to EUR 35 million or 7% of turnover for prohibited practices, EUR 15 million or 3% for other duties. Art. 43; Art. 99(3) to (5) |
| Effort to implement | Depth 3 of 3. Heavy for providers of high-risk systems (documentation, quality management, testing, conformity assessment); lighter for deployers of minimal-risk systems, who still carry AI literacy and transparency duties. Art. 4; Art. 16; Art. 17; Art. 26 |
| Key dates | Depth 3 of 3. In force 2024-08-01; prohibitions and AI literacy 2025-02-02; general-purpose AI rules 2025-08-02; general application, incl. Art. 50, 2026-08-02; new prohibitions 2026-12-02; Annex III high-risk 2027-12-02; Annex I 2028-08-02. Art. 113 and Art. 111(2) and (4) of Reg. (EU) 2024/1689, as amended by Reg. (EU) 2026/1744 |
A learning aid, not legal advice. Where AI SENTINEL is mentioned, it supports or maps to the dimension; it does not certify anything. Dates are those the official texts state on the date shown.