Skip to content
Blog

The AI Act blog

Insights, guides, and practical answers about the EU AI Act and AI compliance.

  • AI Act

    What are the main goals and scope of the EU AI Act?

    An overview of the EU AI Act's objectives - promoting trustworthy AI, protecting fundamental rights, and supporting innovation - along with its broad, extraterritorial scope and key exclusions.

    ( read the article )
  • SME

    How are fine amounts adjusted for SMEs and start-ups?

    The AI Act caps fines for SMEs and start-ups at the lower of the two thresholds (fixed amount vs. turnover percentage), and requires authorities to consider company size and economic viability.

    ( read the article )
  • Compliance

    What criteria determines if a company is a 'provider'?

    Under the AI Act, a company is a 'provider' if it develops (or has developed) an AI system and places it on the market under its own name - but other entities can also become providers through rebranding, substantial modification, or changing the intended purpose.

    ( read the article )
  • Compliance

    How does a company determine if they are a deployer?

    A company is a 'deployer' if it uses an AI system under its authority - but must monitor for role shifts that could reclassify it as a provider with stricter obligations.

    ( read the article )
  • Compliance

    How do companies prove compliance for their AI deployments?

    To prove AI Act compliance, companies must map their AI usage across workspaces, maintain always-ready documentation including technical files and conformity assessments, register in the EU database, and continuously monitor for changes over a 10-year retention period.

    ( read the article )
  • Compliance

    What causes an AI role to shift from deployer to provider?

    Under Article 25 of the AI Act, a deployer becomes a provider - inheriting all stricter obligations - if they rebrand, substantially modify, or change the intended purpose of a high-risk AI system.

    ( read the article )
  • Compliance

    How do companies maintain compliance evidence over ten years?

    The AI Act requires companies to retain compliance documentation for 10 years - providers must keep technical documentation and quality management records, while importers and authorised representatives retain certificates and declarations.

    ( read the article )
  • Enforcement

    Which entities are authorized to audit these ten-year records?

    The AI Act requires that 10-year compliance records be available to national competent authorities, the European AI Office, and fundamental rights bodies - while enterprise customers and auditors also demand access in practice.

    ( read the article )
  • AI Act

    What problems does the AI Act aim to solve?

    An analysis of the key challenges the AI Act addresses - from algorithmic discrimination and lack of transparency to the need for accountability in AI decision-making systems.

    ( read the article )
  • AI Act

    Who does the AI Act really apply to

    An analysis of the wide scope of application of the AI Act, which goes beyond companies that develop AI and involves all actors in the AI ecosystem, with extraterritorial implications.

    ( read the article )
  • AI Act

    The risk-based approach of the AI Act

    An analysis of the innovative regulatory model of the AI Act, which categorizes AI systems into four risk levels - from unacceptable to minimal - ensuring proportional obligations.

    ( read the article )
  • AI Act

    Which artificial intelligence systems are banned by the AI Act

    An examination of prohibited AI applications classified as unacceptable risk - systems that pose such a high risk to fundamental rights that they cannot be mitigated through technical or procedural requirements.

    ( read the article )
  • AI Act

    What are high-risk artificial intelligence systems

    Among the various categories introduced by EU AI regulation, high-risk systems are likely the most relevant for businesses. Unlike prohibited applications, these systems can be developed and used, but must comply with specific requirements.

    ( read the article )
  • High-Risk AI

    In which sectors does the AI Act consider systems to be high-risk?

    After defining what high-risk AI systems are, it is important to understand in which contexts this classification concretely applies. The European regulation identifies specific areas where the use of AI is considered particularly sensitive.

    ( read the article )
  • High-Risk AI

    What obligations must high-risk AI systems comply with

    AI systems classified as high-risk represent one of the most regulated areas of the AI Act. Unlike prohibited applications, these systems can be used, but only if they comply with a series of specific requirements.

    ( read the article )
  • Risk Management

    The role of risk management in AI systems

    Within the requirements for high-risk artificial intelligence systems, risk management plays a central role. It is not an isolated control, but a structured process that must be integrated throughout the entire lifecycle of the AI system.

    ( read the article )
  • Data Governance

    Data quality in AI systems: what the AI Act requires

    Among the requirements for high-risk AI systems, data quality represents a fundamental element. The regulation establishes that datasets must meet specific quality standards to ensure reliability and prevent bias.

    ( read the article )
Aigolex

AI Act compliance assisted by AI. From your repositories and files to your inventory, with Legis or your assistant: less manual work, less time and lower costs.

( Understand Prove Repeat )

© 2026 Aigolex. All rights reservedBologna, Italy

Aigolex is software, not a law firm: it does not provide legal advice and does not replace a professional's.