Expertise / 01

ARTIFICIAL INTELLIGENCE

AI regulation across systems, models, organisations and markets.

Artificial intelligence regulation increasingly reaches beyond governance into product design, regulatory roles, technical evidence, market access and continuing compliance.

OSTRAI advises organisations on the application and implementation of the EU Artificial Intelligence Act, from scope, regulatory role and classification to high-risk AI, general-purpose AI, governance, market access and continuing compliance. We translate regulatory obligations into workable responsibilities, controls and implementation across legal, product, technical and operational teams.

Principal EU regime

EU Artificial Intelligence Act

Scope · Classification · High-risk AI · GPAI · Governance · Market access · Continuing compliance

Principal focus: European regulation · International perspective

Discuss an AI regulatory matter
Open limestone terrace with olive trees overlooking a sunlit Mediterranean bay

REGULATORY ARCHITECTURE

AI regulation does not operate through a single compliance model.

The regulatory position depends on what the technology is, how it is placed on the market or used, the role of the organisation, the intended purpose and the regulatory context in which the AI operates.

The EU AI Act distinguishes between AI systems and general-purpose AI models and imposes different requirements according to regulatory role, classification and use.

Its application may engage prohibited-practice rules, transparency obligations, high-risk requirements, general-purpose AI obligations or other provisions.

01

AI SYSTEMS & REGULATORY ROLES

Scope, applicability, intended purpose and operator responsibilities.

Provider · Deployer · Importer · Distributor · Product manufacturer · Authorised representative

02

HIGH-RISK AI SYSTEMS

Classification, requirements and implementation.

Risk · Data · Documentation · Human oversight · Accuracy · Robustness · Cybersecurity

03

GENERAL-PURPOSE AI

Model-level regulatory obligations.

Documentation · Downstream information · Copyright · Transparency · Systemic risk

04

GOVERNANCE & IMPLEMENTATION

Organisational responsibility and continuing oversight.

Ownership · Decisions · Controls · Evidence · AI literacy · Monitoring

CURRENT IMPLEMENTATION

The AI Act already applies, but not all obligations apply at the same time.

The AI Act applies through a phased timetable. As of September 2026, substantial parts of the framework are already applicable, including the general-purpose AI regime and the Article 50 transparency obligations, subject to specific transitional provisions. The principal high-risk requirements apply later.

Chapter III, Sections 1–3 high-risk requirements apply to AI systems classified as high-risk under Article 6(2) and Annex III.

Corresponding Chapter III, Sections 1–3 requirements apply to AI systems classified as high-risk under Article 6(1), in connection with the Annex I product framework.

Implementation continues

Implementation continues through Commission guidance, implementing and delegated measures, AI Office and AI Board activity and national supervision.

AI ACT ADVISORY & IMPLEMENTATION

From regulatory position to practical implementation.

OSTRAI supports organisations in determining which AI Act requirements apply and translating them into a workable regulatory and implementation programme.

01

SCOPE, APPLICABILITY & REGULATORY ROLES

AI-system and GPAI-model assessment, territorial scope, intended purpose, operator roles and regulatory responsibility mapping.

02

CLASSIFICATION & APPLICABLE REQUIREMENTS

Prohibited-practice screening, high-risk classification, transparency obligations, applicable requirements and implementation dates.

03

HIGH-RISK AI REQUIREMENTS & IMPLEMENTATION

Risk management, data governance, technical documentation, record-keeping, human oversight, accuracy, robustness, cybersecurity, quality management and applicable conformity requirements.

04

GENERAL-PURPOSE AI

GPAI classification, technical documentation, downstream information, copyright-related requirements, training-content transparency and systemic-risk obligations where applicable.

05

MARKET ACCESS & REPRESENTATION

Registration, declarations, CE-marking requirements where applicable, conformity-route analysis and EU authorised representation where required.

06

CONTINUING COMPLIANCE

Monitoring, incident governance, corrective action, change control, regulatory developments and continuing obligations.

HIGH-RISK AI

Regulatory requirements across the AI lifecycle.

For high-risk AI systems, the applicable framework extends across risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management and continuing obligations.

The applicable pathway depends on the basis for the high-risk classification and, where relevant, the interaction with applicable product legislation.

Classification · Risk management · Data governance · Documentation · Human oversight · Accuracy · Robustness · Cybersecurity · QMS

Ordered limestone passage with bronze doors and olive trees

GENERAL-PURPOSE AI

Regulation at model level.

The AI Act establishes a distinct framework for providers of general-purpose AI models, with additional obligations where a model presents systemic risk.

Requirements can include technical documentation, information for downstream providers, copyright-related obligations, training-content transparency and, for models with systemic risk, model evaluation, risk assessment and mitigation, serious-incident obligations and cybersecurity.

GPAI classification · Documentation · Downstream information · Copyright · Transparency · Systemic risk · AI Office

Reflected olive branches and coastal light in curved glass

AI GOVERNANCE

Turning regulatory obligations into organisational responsibility.

AI governance determines how an organisation identifies its AI, allocates responsibility, makes regulatory decisions, implements controls, maintains evidence and oversees AI throughout its lifecycle.

The appropriate structure depends on the organisation’s regulatory role, systems and models, use cases, classification and operating context.

OSTRAI helps organisations design governance arrangements that connect management, legal, compliance, product, technical, privacy, cybersecurity and procurement functions without creating unnecessary parallel structures.

  1. 01

    VISIBILITY & OWNERSHIP

    AI inventory · Systems · Models · Use cases · Responsible owners

  2. 02

    DECISIONS & ACCOUNTABILITY

    Management oversight · Approval rights · Regulatory review · Escalation

  3. 03

    CONTROLS & EVIDENCE

    Policies · Risk controls · Human oversight · Documentation · Records

  4. 04

    CONTINUING OVERSIGHT

    Monitoring · Incidents · Change · Suppliers · Regulatory developments

AI literacy should reflect the roles, technical knowledge, experience, education and training of relevant personnel and the context in which AI systems are developed, deployed or used. OSTRAI supports role-based implementation rather than treating AI literacy as a single prescribed training programme.

REGULATORY INTERSECTIONS

AI does not operate in regulatory isolation.

The AI Act can operate alongside product, cybersecurity, data-protection, operational-resilience and sector-specific regulation. The relevant frameworks should be coordinated where they overlap rather than treated as interchangeable.

01

CYBERSECURITY & PRODUCT REGULATION

AI incorporated into products may require the AI Act to be considered together with the Cyber Resilience Act and applicable product legislation, including product-cybersecurity and conformity requirements.

02

DATA PROTECTION

The AI Act does not replace the GDPR. Where AI involves personal data, both frameworks may require coordinated assessment and implementation.

03

FINANCIAL SERVICES

For financial entities, AI Act obligations may interact with existing ICT-risk, operational-resilience and third-party frameworks, including DORA.

04

SECTOR-SPECIFIC REGULATION

Existing approval, oversight and monitoring structures in regulated sectors may need to be integrated into the AI compliance model rather than duplicated.

Limestone threshold through successive arches towards daylight

EU MARKET ACCESS & REPRESENTATION

EU market access for third-country AI providers.

OSTRAI advises third-country providers on EU market-entry requirements, including the appointment and regulatory role of an EU authorised representative where required under the AI Act.

OSTRAI also provides EU authorised representative services where applicable, including in relation to qualifying high-risk AI systems and general-purpose AI models.

Regulatory position · Representation · Documentation · Authority interface · Continuing obligations

GPAI Authorised Representative

High-Risk AI Authorised Representative

STANDARDS & REGULATORY EVIDENCE

Relevant standards may support implementation, regulatory evidence and conformity strategy. Their regulatory effect depends on the applicable framework; publication of a European Standard does not by itself create an Article 40 presumption of conformity.

OSTRAI considers relevant standards where they materially affect the regulatory or implementation pathway.

See Standards & Standardisation

REGULATORY INTELLIGENCE

AI regulation continues to develop after adoption.

Implementation of the AI Act continues to develop through Commission guidance, delegated and implementing measures, AI Office and AI Board activity, national supervision and evolving sector-specific practice.

OSTRAI follows these developments to identify how they affect regulatory positions, implementation programmes, market-access strategies and continuing compliance.

Commission guidance · AI Office · AI Board · Delegated acts · Implementing acts · National authorities · Enforcement · Regulatory deadlines

ARTIFICIAL INTELLIGENCE

Establish the regulatory position for your AI system, model or use case.

OSTRAI helps organisations determine what applies, identify the regulatory role and requirements that matter, and structure the pathway to implementation, governance, market access and continuing compliance.

Discuss an AI regulatory matter