EU AI Act Compliance & Assurance Services for EU Market Entry

EU AI Act Compliance & Assurance Services

Businesses that develop, supply, or use artificial intelligence in the European Union need to understand the EU AI Act before entering the market. The rules apply to certain organisations inside the EU and, in some cases, businesses based outside the EU. This means an overseas company cannot assume that its location removes it from the requirements.

The EU AI Act takes a risk-based approach. The requirements depend on the type of AI system, its intended purpose and the role of the organisation supplying or using it. A business therefore needs to establish whether the Act applies, identify the risk category of its system and understand which requirements must be met before entering the EU market. Finsoul Ireland provides EU AI Act Compliance & Assurance Services to help businesses review their position, understand their obligations and prepare the evidence needed to support compliance.

Does the EU AI Act Apply to Your Business?

The first step is to establish whether the EU AI Act applies to your business and AI system. The regulation can apply to businesses based outside the EU when they place an AI system or general-purpose AI model on the EU market. It can also apply in certain situations where the output produced by an AI system is used within the EU. This means a company does not avoid the regulation simply because it is based in the UK, US, or another country outside the EU. A business should consider:

  • Where the business is established
  • Where the AI system will be supplied
  • Where the system will be used
  • Who developed the AI system
  • Who supplies it to EU customers
  • How the system is intended to operate
  • Whether the business is acting as a provider, deployer, importer or distributor
  • Whether the system falls within a specific category under the Regulation

This assessment should take place before launch. Finding a compliance issue after entering the market can create delays and additional work.

Understanding AI Risk Categories Before EU Market Entry

The EU AI Act classifies AI systems according to the risks they can create. Understanding the correct category is important because the obligations are not the same for every system. Some AI practices are prohibited because of the risks they create. Businesses should check their intended use before launching an AI product in the EU. High-risk AI systems have more detailed requirements. These can include certain systems used in employment, education, essential services, law enforcement, migration, and other areas covered by the Regulation. The classification depends on the system and its intended purpose.

Other AI systems may have transparency requirements. For example, people may need to be told when they are interacting with AI. Certain AI-generated or manipulated content may also need to be identified. General-purpose AI models have separate requirements. These can include technical documentation, copyright policies, and information for businesses using the model. A simple artificial intelligence concept used to describe a product does not determine its legal classification. The business needs to assess how the system actually works and what it is designed to do.

What EU AI Act Compliance Requires for Market Entry

Once a business knows that the EU AI Act applies, it needs to identify the requirements relevant to its system. EU AI Act Compliance & Assurance Services can help businesses review these requirements and identify any gaps before the product enters the EU market. For high-risk AI systems, the requirements can cover areas such as:

  • Risk management
  • Data governance
  • Data quality
  • Technical documentation
  • Record-keeping
  • Human oversight
  • Accuracy
  • Robustness
  • Cybersecurity
  • Transparency
  • Quality management
  • Post-market monitoring

The requirements for other AI systems may be less extensive. A business may instead need to focus on transparency or other obligations linked to its role and the type of system it supplies. A compliance assessment should look at the actual AI system rather than relying on general statements about safety or security. 

High-Risk AI System Compliance

High-risk AI systems require more detailed preparation before they can be placed on the EU market or put into service. Providers of applicable high-risk systems must meet specific requirements covering areas such as risk management, data governance, technical documentation, record-keeping, human oversight, accuracy, robustness and cybersecurity. Risk management should consider the risks linked to the AI system throughout its relevant lifecycle. Businesses also need suitable processes for identifying and dealing with risks.

Data is another important area. Where training, validation, or testing data are relevant, businesses need to consider the quality and governance of that data. Human oversight should also be clear. People responsible for overseeing the system need enough information to understand its operation and take appropriate action when required. Testing and monitoring should support claims about system performance. Businesses should be able to show how they have assessed the system rather than relying only on general product descriptions. Cybersecurity is also important for high-risk systems. Security measures should reflect the actual risks associated with the AI system and its intended use.

EU AI Act High-Risk AI Timeline

The timing of high-risk AI obligations depends on the category of the AI system. Certain high-risk systems covered by Annex III are subject to the relevant requirements from 2 August 2026, while certain AI systems linked to regulated products under Annex I have a later application date of 2 August 2027. Businesses should therefore confirm which category applies before determining their market-entry compliance obligations. 

EU AI Act Conformity Assessment and Assurance

Conformity assessment is an important part of EU AI Act compliance for applicable high-risk AI systems. It provides a process for checking whether the system meets the relevant requirements before it enters the EU market. The assessment route depends on the type of AI system and the rules that apply to it. The conformity assessment route depends on the type of high-risk AI system and the requirements applicable to it. 

Depending on the system and the applicable procedure, conformity may be assessed through the provider’s internal controls or may require the involvement of a notified body. EU AI Act Compliance & Assurance Services can support businesses by reviewing the information and evidence needed for the relevant assessment. This can include checking:

  • Whether the AI system has been correctly classified
  • Whether the applicable requirements have been identified
  • Whether technical documentation is complete
  • Whether risk controls are documented
  • Whether testing records are available
  • Whether human oversight arrangements are clear
  • Whether transparency requirements have been considered
  • Whether the correct conformity assessment route has been identified

Where required, the provider may also need to prepare a declaration of conformity and complete other steps before placing the system on the EU market. An assurance review should not simply confirm that documents exist. The documents should reflect the actual AI system, its purpose, and the way it is developed and used.

Documentation Needed for EU AI Act Compliance

Good documentation helps a business demonstrate how its AI system works and how it meets the applicable requirements. For high-risk AI systems, the EU AI Act includes detailed technical documentation requirements. Depending on the system, documentation may include:

  • Description of the AI system
  • Intended purpose
  • System design and development information
  • Risk assessments
  • Data governance information
  • Testing and validation results
  • Human oversight arrangements
  • Logging information
  • Cybersecurity measures
  • Instructions for use
  • Post-market monitoring arrangements
  • Declaration of conformity where applicable

Finsoul Ireland can review existing documentation and compare it with the requirements that apply to the specific AI system. Documentation should also be kept up to date. If the system changes, its intended purpose changes or new risks arise, the business may need to review its compliance documentation again.

EU AI Act Compliance for General-Purpose AI Models

General-purpose AI models have specific requirements under the EU AI Act. Providers may need to prepare technical documentation, provide information to downstream providers, have a copyright policy and publish a summary of the content used to train the model. Additional requirements apply to models that present systemic risk.

Non-EU providers may also need to appoint an authorised representative in the EU before placing their general-purpose AI model on the market. Businesses supplying these models should therefore assess their obligations before entering the EU market. They should also understand their position in the AI value chain and the responsibilities that follow from that role.

Using AI for compliance can help businesses organise information and identify potential issues, but automated tools should not replace a proper assessment of the legal requirements that apply to a particular AI system.

EU AI Act Transparency Requirements

Transparency is another area that businesses need to consider before entering the EU market. Certain AI systems must inform people when they are interacting with AI. Other requirements apply to AI-generated or manipulated content. The EU AI Act also introduces specific requirements for certain deepfakes and other synthetic content. Article 50 transparency obligations apply from 2 August 2026. 

Businesses should also consider the transitional arrangements that apply to certain AI systems and transparency obligations. Where relevant, companies should review whether systems already placed on the market before 2 August 2026 are subject to a later transition period.

 For example, a business should consider:

  • What information users receive
  • When users need to know they are interacting with AI
  • Whether AI-generated content needs to be identified
  • How synthetic content is marked
  • Whether the required information is clear and accessible

The business needs to put the relevant technical and user-facing measures in place.

Common EU AI Act Compliance Challenges for Market Entry

Businesses can face several problems when preparing an AI product for the EU market. One common issue is failing to establish whether the regulation applies before starting compliance work. Another is placing an AI system in the wrong risk category. Documentation can also become a problem. Businesses may have policies and technical records but find that the information does not properly reflect the AI system.

Another challenge is treating compliance as a one-off exercise. AI systems can change over time. Changes to the system, its purpose, or its use may require the business to review its compliance position. Transparency is also easy to overlook, particularly when AI is built into an existing software product. Businesses should consider the full customer journey and how users interact with AI. Starting the assessment early gives businesses more time to identify these issues and address them before market entry.

How EU AI Act Compliance & Assurance Services Support Market Entry

For businesses preparing to enter the EU, EU AI Act Compliance & Assurance Services can cover several areas of the compliance process. These may include:

  • EU AI Act applicability assessment
  • AI system risk classification review
  • Compliance gap assessment
  • Risk and control review
  • Data governance review
  • Documentation assessment
  • Human oversight review
  • Transparency assessment
  • Conformity assessment preparation
  • Market-entry compliance review

Finsoul Ireland starts by understanding the business, its AI system and its intended use. This allows the assessment to focus on the requirements that actually apply to the organisation.

EU AI Act Market Entry Checklist

Before placing an applicable AI system on the EU market, businesses should ask:

  • Have we confirmed whether the EU AI Act applies?
  • Have we identified our role?
  • Have we classified the AI system correctly?
  • Have we identified the applicable requirements?
  • Have we assessed the relevant risks?
  • Is the required technical documentation complete?
  • Are testing and validation records available?
  • Are human oversight arrangements documented?
  • Have cybersecurity requirements been considered?
  • Have transparency requirements been addressed?
  • Is conformity assessment required?
  • Have we prepared the required declaration where applicable?
  • Have post-market obligations been considered?

This checklist provides a starting point. The exact requirements will depend on the AI system, its purpose, and the organisation’s role.

Our Approach to EU AI Act Compliance

EU AI Act compliance should be assessed against the specific AI system, its intended purpose and the role of the organisation in the AI value chain. Finsoul Ireland’s approach focuses on understanding the system first, identifying the requirements that apply, reviewing existing controls and documentation, and highlighting gaps that may need to be addressed before EU market entry.

The scope of the review is determined by the organisation’s activities, AI system classification and applicable regulatory requirements. Where a formal conformity assessment or other statutory process is required, the applicable regulatory route should be followed.

Preparing for EU AI Act Compliance?

If you are planning to introduce an AI system in the EU market, it is important to understand your obligations before launch. Reviewing your AI system, risk classification, and documentation early can help you identify compliance gaps and prepare for the requirements that apply to your business.

Want to understand what the EU AI Act means for your business? Contact Finsoul Ireland to discuss your requirements and next steps.

FAQs 

Does the EU AI Act apply to companies outside the EU?

Yes. The regulation can apply to certain providers established outside the EU when they place AI systems or general-purpose AI models on the EU market. It can also apply in specific circumstances where the output of an AI system is used in the EU.

Does every AI system require conformity assessment?

No. The requirement depends on the type and classification of the AI system. Applicable high-risk systems are subject to specific conformity assessment requirements.

Can auditing & assurance services help with EU AI Act compliance?

Yes. Auditing & assurance services can help businesses review their AI-related controls, documentation, risk assessments, and compliance evidence. The scope of the review will depend on the type of AI system, its risk classification, and the requirements that apply under the EU AI Act. However, general assurance work should not be confused with a formal conformity assessment where one is required.

What are the transparency requirements?

Certain AI systems must tell people when they are interacting with AI. Specific AI-generated or manipulated content may also need to be marked or labelled. Article 50 requirements apply from 2 August 2026.

When should businesses assess compliance?

Businesses should assess their position before entering the EU market. Early assessment gives them time to identify and address compliance gaps before supplying the AI system to EU customers.

 

Leave a Comment

Your email address will not be published. Required fields are marked *

Table of Contents

Book An Appointment

Scroll to Top