EU AI Act for Technical Teams: Compliance & Implementation | SIXE
Compliance EU AI Act
REGULATION (EU) 2024/1689 · IN FORCE

EU AI Act for technical teams

Technical consulting for the EU AI Regulation at the level of code, pipelines, logs and infrastructure. That's where compliance is actually demonstrated.

Phased application through 2027. The bulk of technical weight falls on high-risk systems under Annex III — biometrics, HR, credit, education, essential services — with obligations applicable from August 2026.

01 · What it is

What is the EU AI Act.

The Regulation (EU) 2024/1689, known as the EU AI Act, is the first comprehensive law on artificial intelligence in the world. It entered into force on 1 August 2024 and applies in phases through 2027. It is directly applicable in all 27 member states: no national transposition required.

It classifies AI systems into four risk tiers — prohibited, high, limited and minimal — and assigns concrete obligations to each. Most of the technical weight falls on high-risk systems under Annex III: biometrics, HR, credit, education, critical infrastructure, law enforcement and essential services.

It obliges providers (those who develop and place AI on the market), professional users (companies using it in operations), and applies outside the EU too when the output of the system is used inside. The territorial scope is broad.

02 · Dates & who's obliged

Phased application through 2027.

Application is phased. Each layer starts on a different date, and knowing which window each of your systems falls into is the starting point.

1 Aug 2024

In force

Entry into force, 20 days after publication in the Official Journal of the EU. From here, the deadlines of each phase start running.

2 Feb 2025

Prohibited practices

Social scoring, subliminal manipulation, sensitive biometric categorisation, emotion recognition in workplace/education.

2 Aug 2025

GPAI

Obligations for general-purpose AI models: technical documentation, copyright policy, transparency.

2 Aug 2026

High risk

Annex III: biometrics, HR, credit, education, law enforcement, critical infrastructure, essential services.

5
2 Aug 2027

Remaining obligations

Annex I high-risk systems (products already CE-marked under existing regulations) and residual obligations.

Who's obliged. Providers (those who develop and place AI on the EU market), professional users (companies integrating it into operations), importers and distributors. It also applies outside the EU when the output of the system is used inside.

03 · How we work

Four technical phases on your code.

We work on your code, your pipelines and your logs. Legal interpretation stays with your legal advisors; we handle the technical detail where compliance is actually demonstrated.

1
Classification

What each system is

We inventory your AI systems and classify them: prohibited, high-risk (Annex III), limited or minimal risk. It is the starting point: it determines scope and obligations applicable to each one.

2
Technical gap

What's missing in the system

Against articles 9-15 and Annex IV: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and cybersecurity. Findings per system, each with its own sheet.

3
Implementation

Controls in the code

We instrument automatic logging, integrate data governance into your data pipelines, build the risk management system and the effective human oversight mechanisms. On your stack.

4
Post-market

Continuous monitoring

The AI Act mandates post-market monitoring and serious incident reporting. We leave the dashboards, alerts and operational processes so the team maintains it without depending on us.

SIXE is a technical consultant. Legal interpretation of the regulation belongs with your legal department or a specialised firm. We handle the technical side: inventorying, classifying, instrumenting, integrating. We work alongside your legal advisors.

04 · Technical obligations

What the AI Act asks of your engineers.

For high-risk systems (Annex III), articles 9-15 of the regulation are the ones that require code, not documents. Six fronts that an integrator has to leave in place.

Art. 9 · Risks

Risk management system

Continuous identification and evaluation of foreseeable risks of the system, with mitigation measures and testing before deployment. Iterative, documented, reviewed on every release.

Art. 10 · Data

Data governance

Training, validation and test datasets with verifiable quality, representativeness and absence of bias. Documentation of origin, processing and statistical properties. One of the areas that requires the most traceability work.

Art. 11-12 · Docs

Technical documentation and logging

Annex IV technical documentation kept current and automatic event logging throughout the operational lifecycle. Full traceability: what input, what output, when, by which model.

Art. 13 · UX

User transparency

Clear instructions of use, information on capabilities and limitations, expected accuracy, and runtime disclosures when the user interacts with AI (chatbots, synthetic content, deepfakes).

Art. 14 · HITL

Effective human oversight

Operational human-in-the-loop: the human operator must be able to interpret the output, override it and stop the system. Requires real UI design and decision flow.

Art. 15 · Robustness

Accuracy, robustness, cybersecurity

Declared and monitored accuracy metrics, tolerance to errors and to AI-specific attacks (adversarial inputs, data poisoning, model evasion). AI systems have their own attack surface, which calls for specific controls.

05 · It doesn't go alone

AI Act and ISO 42001, better together.

The AI Act is law and mandatory; it tells you what you have to comply with. ISO/IEC 42001 is a voluntary certifiable standard that gives you the how: the management system that makes that compliance sustainable and auditable over time.

The risk management system required by article 9 of the AI Act maps directly to clause 6.1 of ISO 42001. Article 12 logging maps to Annex A controls. Post-market monitoring maps to continual improvement in clause 10. Doing them separately doubles the effort. Doing them together halves it.

If you're going to do the AI Act anyway, consider closing ISO 42001 certification in the same project: the controls overlap and you come out with European compliance and the international seal.

06 · Frequently asked questions

EU AI Act, in plain English.

What exactly is the EU AI Act?
It is Regulation (EU) 2024/1689, the first comprehensive law on artificial intelligence in the world. It classifies AI systems by risk (prohibited, high, limited, minimal) and establishes technical and governance obligations for providers and professional users. It is directly applicable in all 27 member states; no national transposition required.
When does each part apply?
It entered into force on 1 August 2024. Prohibited practices apply from 2 February 2025. GPAI obligations (general-purpose AI models) from 2 August 2025. High-risk systems, from 2 August 2026. The remaining obligations, from 2 August 2027.
Who does it apply to?
Providers (those who develop AI systems and place them on the EU market), professional users (companies using AI in operations), importers and distributors. It also applies outside the EU when the output of the system is used within the EU. The territorial scope is broad.
How do I know if my system is high-risk?
The AI Act defines high risk in Annex III: biometrics, critical infrastructure, education, employment (recruitment, evaluation), essential services (credit, insurance), law enforcement, migration, administration of justice. An HR chatbot screening CVs is high risk; an internal assistant summarising meeting minutes is not. Formal classification is the first thing we do on any project.
What technical obligations does it actually impose?
For high-risk systems: risk management system, data governance (quality, bias, representativeness), technical documentation, automatic event logging, user transparency, effective human oversight, accuracy and cybersecurity, and post-market monitoring. All require actual instrumentation in the code and infrastructure.
AI Act or ISO 42001? Both?
AI Act is mandatory EU law. ISO/IEC 42001 is an international voluntary certifiable standard for AI management. They work together: the management system required by ISO 42001 is the framework where the controls required by the AI Act sit. Implementing both at once saves half the work.
Is SIXE a law firm or a consultant?
Technical consultant. For legal interpretation of the regulation we work with specialised law firms. SIXE covers the technical work that sits outside legal advice: instrumenting logging, classifying systems, building controls into infrastructure, integrating monitoring with your pipelines. Legal interpretation belongs to the firm; technical implementation belongs to us.

AI in production and AI Act unresolved?

Tell us which AI systems you have and what you use them for. We come back with a preliminary Annex III classification and a proposal with the phases broken down: classification, technical gap, implementation and post-market monitoring. Price per phase, no fluff.

+34 91 198 02 43 (EU)  ·  +1 628 900 3024 (US)  ·  Mon–Fri 8:30–16:30 (GMT+1)