EU AI Act high-risk obligations: 2 December 2027 for stand-alone systems, 2 August 2028 where the AI is inside a regulated product.Check if EU AI Act applies to you →
AI Governance

AI Governance &
Risk Management

EU AI Act compliance. AI risk register. Model inventory. Board-level AI oversight documentation. NIST AI RMF alignment. ISO 42001 readiness. One platform for your entire AI governance programme.

Start your AI inventory →$2,900/yrTalk to a specialist
EU AI ActNIST AI RMFISO 42001Model riskSR 11-7GDPR Art. 22Bill C-27 AIDABoard AI oversight
2 Dec
2027
High-risk obligations for stand-alone systems; 2 August 2028 where the AI is inside a regulated product
Stand-alone
high-risk
HR, hiring, credit, education AI — full conformity assessment required
€35M
or 7%
maximum EU AI Act fine for prohibited AI practices
Feb 2025
active
prohibited AI practices already banned — manipulation, social scoring, real-time biometrics
EU AI Act — Regulation (EU) 2024/1689 as amended by (EU) 2026/1744

The high-risk dates
moved. The scope did not.

If your company uses AI for HR decisions, hiring, credit scoring, or education in the EU, you are in scope for the EU AI Act Annex III high-risk provisions. Regulation (EU) 2026/1744 — published 24 July 2026, in force 27 July 2026 — deferred those obligations to 2 December 2027 for stand-alone systems, and to 2 August 2028 where the AI is built into a product already covered by EU product-safety law. Nothing else moved: the Article 5 prohibitions have applied since February 2025, GPAI obligations since August 2025, and the Article 50 transparency duties keep their original schedule. Classification, technical documentation and registration are unchanged in substance — only the date by which they must be done.

AI system inventory and Annex III risk classification
Article 11 technical documentation generation
Conformity assessment workflow and evidence pack
EU AI database registration preparation
Transparency notice templates for affected individuals
Board AI oversight framework and governance documentation
EU AI Act Annex III — High-risk categories
Employment & HR
2 December 2027
CV screening, candidate ranking, performance management, task allocation
Credit & finance
2 December 2027
Credit scoring, loan approval, insurance risk assessment
Education
2 December 2027
Student assessment, admissions, monitoring during exams
Essential services
2 December 2027
Access to public benefits, emergency services dispatch
Law enforcement
2 December 2027
Polygraphs, risk assessment, evidence evaluation
Migration & border
2 December 2027
Risk assessment, document verification, applications
Platform capabilities

Your complete AI governance programme.

AI system inventory
Comprehensive register of all AI systems across your organisation. Purpose, data inputs, outputs, affected individuals, and deployment context — all documented and version-controlled.
Risk classification
Automated EU AI Act risk classification (prohibited, high-risk Annex III, limited risk, minimal risk) with justification documentation. Updated as regulation evolves.
Technical documentation
Article 11 technical documentation generation for high-risk AI systems. System description, training data, accuracy metrics, robustness testing, and human oversight measures.
NIST AI RMF alignment
Map, Measure, Manage, Govern — ThemisIQ structures your AI risk management programme around the NIST AI Risk Management Framework and tracks maturity over time.
Board AI governance
Board-level AI oversight documentation, AI ethics policy management, accountability framework, and executive AI risk reporting — designed for directors, not just technologists.
Conformity assessment
Step-by-step conformity assessment workflow for high-risk AI systems. Evidence collection, gap identification, remediation tracking, and EU database registration preparation.
Framework coverage

Every AI governance framework. One platform.

FrameworkJurisdictionApplies toKey requirementThemisIQ coverage
EU AI ActEU (global scope)Any AI affecting EU residentsRisk classification + conformity assessment for high-risk AI✓ Full
NIST AI RMFUSA (voluntary/mandatory)US federal agencies + voluntaryMap, Measure, Manage, Govern framework✓ Full
ISO 42001:2023GlobalOrganisations using or developing AIAI management system — policies, controls, continuous improvement✓ Full
GDPR Article 22EU/UKAutomated decision-making affecting individualsRight to explanation + human review for automated decisions✓ Partial
Bill C-27 AIDA (proposed)CanadaHigh-impact AI systemsImpact assessment + registration when enacted✓ Monitored
SR 11-7 (Fed Reserve)USA financial servicesBanks using models for decisionsModel risk management — validation and governance✓ Partial
EU AI Act timeline

What's already in force. What's coming.

Active
Prohibited AI
Feb 2, 2025
Manipulation, social scoring, real-time biometric surveillance in public spaces, and emotion recognition in workplaces banned. Non-compliance: fines up to €35M or 7% global revenue.
Active
GPAI obligations
May 2, 2025
General Purpose AI models (GPT-4-class and above) subject to transparency, copyright, and systemic risk provisions. GPAI providers must publish technical documentation.
Prepare now
High-risk AI (Annex III)
2 December 2027
Stand-alone high-risk systems under Article 6(2) — HR, hiring, credit, education, essential services AI. Full conformity assessment, Article 11 documentation, EU database registration required. Fines up to €15M or 3% global revenue.
Prepare now
High-risk AI (Annex I)
2 August 2028
AI embedded in regulated products under Article 6(1) — medical devices, machinery, vehicles. Same high-risk obligations, with CE marking integration into the existing product conformity route.

You cannot classify what you
have not inventoried.
Start with what you have.

The first step is knowing what AI systems you have and whether they're high-risk. ThemisIQ's AI inventory wizard walks you through every system in days — not months.

Start your AI inventory →$2,900/yrTalk to a specialist