ARTIFICIAL INTELLIGENCE
AI regulation across systems, models, organisations and markets.
Artificial intelligence regulation increasingly reaches beyond governance into product design, regulatory roles, technical evidence, market access and continuing compliance.
OSTRAI advises organisations on the application and implementation of the EU Artificial Intelligence Act, from scope, regulatory role and classification to high-risk AI, general-purpose AI, governance, market access and continuing compliance. We translate regulatory obligations into workable responsibilities, controls and implementation across legal, product, technical and operational teams.
Principal EU regime
EU Artificial Intelligence Act
Scope · Classification · High-risk AI · GPAI · Governance · Market access · Continuing compliance
Principal focus: European regulation · International perspective
Discuss an AI regulatory matter
REGULATORY ARCHITECTURE
AI regulation does not operate through a single compliance model.
The regulatory position depends on what the technology is, how it is placed on the market or used, the role of the organisation, the intended purpose and the regulatory context in which the AI operates.
The EU AI Act distinguishes between AI systems and general-purpose AI models and imposes different requirements according to regulatory role, classification and use.
Its application may engage prohibited-practice rules, transparency obligations, high-risk requirements, general-purpose AI obligations or other provisions.
AI SYSTEMS & REGULATORY ROLES
Scope, applicability, intended purpose and operator responsibilities.
Provider · Deployer · Importer · Distributor · Product manufacturer · Authorised representative
HIGH-RISK AI SYSTEMS
Classification, requirements and implementation.
Risk · Data · Documentation · Human oversight · Accuracy · Robustness · Cybersecurity
GENERAL-PURPOSE AI
Model-level regulatory obligations.
Documentation · Downstream information · Copyright · Transparency · Systemic risk
GOVERNANCE & IMPLEMENTATION
Organisational responsibility and continuing oversight.
Ownership · Decisions · Controls · Evidence · AI literacy · Monitoring
CURRENT IMPLEMENTATION
The AI Act already applies, but not all obligations apply at the same time.
The AI Act applies through a phased timetable. As of September 2026, substantial parts of the framework are already applicable, including the general-purpose AI regime and the Article 50 transparency obligations, subject to specific transitional provisions. The principal high-risk requirements apply later.
Chapter III, Sections 1–3 high-risk requirements apply to AI systems classified as high-risk under Article 6(2) and Annex III.
Corresponding Chapter III, Sections 1–3 requirements apply to AI systems classified as high-risk under Article 6(1), in connection with the Annex I product framework.
Implementation continues
Implementation continues through Commission guidance, implementing and delegated measures, AI Office and AI Board activity and national supervision.
AI ACT ADVISORY & IMPLEMENTATION
From regulatory position to practical implementation.
OSTRAI supports organisations in determining which AI Act requirements apply and translating them into a workable regulatory and implementation programme.
SCOPE, APPLICABILITY & REGULATORY ROLES
AI-system and GPAI-model assessment, territorial scope, intended purpose, operator roles and regulatory responsibility mapping.
CLASSIFICATION & APPLICABLE REQUIREMENTS
Prohibited-practice screening, high-risk classification, transparency obligations, applicable requirements and implementation dates.
HIGH-RISK AI REQUIREMENTS & IMPLEMENTATION
Risk management, data governance, technical documentation, record-keeping, human oversight, accuracy, robustness, cybersecurity, quality management and applicable conformity requirements.
GENERAL-PURPOSE AI
GPAI classification, technical documentation, downstream information, copyright-related requirements, training-content transparency and systemic-risk obligations where applicable.
MARKET ACCESS & REPRESENTATION
Registration, declarations, CE-marking requirements where applicable, conformity-route analysis and EU authorised representation where required.
CONTINUING COMPLIANCE
Monitoring, incident governance, corrective action, change control, regulatory developments and continuing obligations.
HIGH-RISK AI
Regulatory requirements across the AI lifecycle.
For high-risk AI systems, the applicable framework extends across risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management and continuing obligations.
The applicable pathway depends on the basis for the high-risk classification and, where relevant, the interaction with applicable product legislation.
Classification · Risk management · Data governance · Documentation · Human oversight · Accuracy · Robustness · Cybersecurity · QMS

GENERAL-PURPOSE AI
Regulation at model level.
The AI Act establishes a distinct framework for providers of general-purpose AI models, with additional obligations where a model presents systemic risk.
Requirements can include technical documentation, information for downstream providers, copyright-related obligations, training-content transparency and, for models with systemic risk, model evaluation, risk assessment and mitigation, serious-incident obligations and cybersecurity.
GPAI classification · Documentation · Downstream information · Copyright · Transparency · Systemic risk · AI Office

AI GOVERNANCE
Turning regulatory obligations into organisational responsibility.
AI governance determines how an organisation identifies its AI, allocates responsibility, makes regulatory decisions, implements controls, maintains evidence and oversees AI throughout its lifecycle.
The appropriate structure depends on the organisation’s regulatory role, systems and models, use cases, classification and operating context.
OSTRAI helps organisations design governance arrangements that connect management, legal, compliance, product, technical, privacy, cybersecurity and procurement functions without creating unnecessary parallel structures.
- 01
VISIBILITY & OWNERSHIP
AI inventory · Systems · Models · Use cases · Responsible owners
- 02
DECISIONS & ACCOUNTABILITY
Management oversight · Approval rights · Regulatory review · Escalation
- 03
CONTROLS & EVIDENCE
Policies · Risk controls · Human oversight · Documentation · Records
- 04
CONTINUING OVERSIGHT
Monitoring · Incidents · Change · Suppliers · Regulatory developments
AI literacy should reflect the roles, technical knowledge, experience, education and training of relevant personnel and the context in which AI systems are developed, deployed or used. OSTRAI supports role-based implementation rather than treating AI literacy as a single prescribed training programme.
REGULATORY INTERSECTIONS
AI does not operate in regulatory isolation.
The AI Act can operate alongside product, cybersecurity, data-protection, operational-resilience and sector-specific regulation. The relevant frameworks should be coordinated where they overlap rather than treated as interchangeable.
CYBERSECURITY & PRODUCT REGULATION
AI incorporated into products may require the AI Act to be considered together with the Cyber Resilience Act and applicable product legislation, including product-cybersecurity and conformity requirements.
DATA PROTECTION
The AI Act does not replace the GDPR. Where AI involves personal data, both frameworks may require coordinated assessment and implementation.
FINANCIAL SERVICES
For financial entities, AI Act obligations may interact with existing ICT-risk, operational-resilience and third-party frameworks, including DORA.
SECTOR-SPECIFIC REGULATION
Existing approval, oversight and monitoring structures in regulated sectors may need to be integrated into the AI compliance model rather than duplicated.

EU MARKET ACCESS & REPRESENTATION
EU market access for third-country AI providers.
OSTRAI advises third-country providers on EU market-entry requirements, including the appointment and regulatory role of an EU authorised representative where required under the AI Act.
OSTRAI also provides EU authorised representative services where applicable, including in relation to qualifying high-risk AI systems and general-purpose AI models.
Regulatory position · Representation · Documentation · Authority interface · Continuing obligations
STANDARDS & REGULATORY EVIDENCE
Relevant standards may support implementation, regulatory evidence and conformity strategy. Their regulatory effect depends on the applicable framework; publication of a European Standard does not by itself create an Article 40 presumption of conformity.
OSTRAI considers relevant standards where they materially affect the regulatory or implementation pathway.
REGULATORY INTELLIGENCE
AI regulation continues to develop after adoption.
Implementation of the AI Act continues to develop through Commission guidance, delegated and implementing measures, AI Office and AI Board activity, national supervision and evolving sector-specific practice.
OSTRAI follows these developments to identify how they affect regulatory positions, implementation programmes, market-access strategies and continuing compliance.
Commission guidance · AI Office · AI Board · Delegated acts · Implementing acts · National authorities · Enforcement · Regulatory deadlines
ARTIFICIAL INTELLIGENCE
Establish the regulatory position for your AI system, model or use case.
OSTRAI helps organisations determine what applies, identify the regulatory role and requirements that matter, and structure the pathway to implementation, governance, market access and continuing compliance.
