AI Governance Solutions / EU AI Act Readiness

The EU AI Act is in force.
Most organisations do not know where they stand.

The EU AI Act is the world’s first comprehensive legal framework for artificial intelligence. It applies to any organisation that develops, deploys, or uses AI systems in the EU, and to organisations outside the EU whose AI outputs affect people within it. For companies across APAC and the GCC, that reach is wider than most legal teams have assessed.

Prohibited uses carry fines of up to 35 million euros or 7 percent of global annual turnover. CorpStage maps your AI systems, classifies them against the Act’s risk tiers, identifies your obligations, and builds the gap analysis and remediation roadmap you need before the deadlines apply to you.

Book EU AI Act AssessmentTry AIVARA Core 360 Free →
The Regulation

Four risk tiers. Very different obligations at each level.

Unacceptable Risk — Prohibited

AI systems banned outright. Social scoring by public authorities. Real-time biometric surveillance in public spaces. Subliminal manipulation. Exploitation of vulnerable groups. If your organisation operates any of these, the obligation is immediate cessation.

High Risk — Significant Obligations

AI in critical infrastructure, education, employment, essential services, law enforcement, migration, and justice. Requires conformity assessment before deployment, technical documentation, logging and audit trail, human oversight, and registration in the EU database.

Limited Risk — Transparency

AI systems that interact with people or generate content. Chatbots, deepfakes, and AI-generated content require disclosure to users that they are interacting with AI or viewing AI-generated material.

Minimal Risk — No Specific Obligations

AI systems that carry low risk to rights or safety. No specific requirements under the Act, though general product safety law still applies.

General Purpose AI Models

Foundation models and large language models have specific requirements around transparency, copyright compliance, systemic risk assessment, and reporting. Obligations depend on how third-party models are used and adapted.

Scope

The EU AI Act reaches further than most organisations expect

Providers

Organisations that develop AI systems placed on the EU market or put into service in the EU, regardless of where the provider is based.

Deployers

Organisations that use AI systems in a professional context in the EU. This includes organisations outside the EU using AI tools whose outputs affect people within it.

Importers and Distributors

Organisations that bring AI systems from outside the EU into the EU market.

APAC and GCC organisations specifically

If your organisation exports to the EU, operates EU subsidiaries, uses AI tools that process EU citizen data, or uses AI-generated content in EU-facing products, the Act’s reach extends to you. The prohibited use provisions applied from August 2024. High-risk system obligations apply from August 2026.

Assessment Scope

A structured assessment across five areas

Area 01

AI System Inventory

Identify all AI systems across your organisation. Built, bought, or embedded in third-party tools. Most organisations discover more AI use than they initially account for.

Area 02

Risk Classification

Map each system against the EU AI Act's four risk tiers. Determine whether systems fall into prohibited, high-risk, limited risk, or minimal risk categories.

Area 03

Obligation Mapping

For high-risk systems, identify conformity assessment, documentation, logging, human oversight, and registration obligations. For limited-risk systems, identify transparency disclosure requirements.

Area 04

Gap Analysis

Compare current AI governance practices against what the Act requires. Identify specific gaps in technical documentation, control design, human oversight, audit trail, and risk management.

Area 05

Remediation Roadmap

A sequenced plan showing what to address before which deadline, who owns each action, and how AIVARA Core 360 supports ongoing compliance.

What You Receive

Five outputs. From inventory to roadmap.

Deliverable 01

AI System Inventory and Classification Register

A complete register of AI systems with risk classification, use context, affected populations, and deployment geography. The foundational document from which all other compliance work flows.

Deliverable 02

EU AI Act Obligation Matrix

A precise mapping of your specific obligations under the Act by system and risk tier. What is required, when, from whom, and what evidence needs to exist.

Deliverable 03

Gap Analysis Report

A structured assessment of where current AI governance practices fall short of EU AI Act requirements. Written for the legal, technology, and risk functions simultaneously.

Deliverable 04

Remediation Roadmap

A sequenced action plan showing what to fix before which deadline. Prioritised by regulatory risk, technical complexity, and organisational readiness.

Deliverable 05

Board and Executive Summary

A one-page view of your EU AI Act exposure, key obligations, and the steps being taken to address them. Written for board members who need the risk without the regulation.

The Platform Layer

AIVARA Core 360 turns the assessment into an ongoing control environment

The AI system inventory becomes the AI asset register. The obligation mapping feeds into the 150-control AI Control Library. The gap analysis becomes the control gap tracker. Compliance is not a one-time project. AIVARA Core 360 manages the ongoing environment as the Act is updated and new AI systems are deployed.

Try AIVARA Core 360 Free →
Who This Is For

CTOs and Chief AI Officers

Technology leaders responsible for AI deployment who need a structured view of regulatory obligations before systems go live or before regulatory deadlines arrive.

Legal and Compliance Teams

Teams that need to translate the EU AI Act's legal text into specific organisational obligations, documented assessments, and defensible evidence of compliance.

Risk and Internal Audit

Functions that need to assess AI-related regulatory risk, build audit programmes around AI systems, and report on AI governance to the board or audit committee.

Boards and Audit Committees

Boards that need to understand AI regulatory exposure and confirm that management is taking appropriate steps before obligations become enforceable.

Questions before you start

Does the EU AI Act apply to us if we are based in Singapore or the GCC?

Yes, if your AI systems are used in the EU, deployed in EU-facing products, or produce outputs that affect EU residents. The Act applies to providers and deployers regardless of where they are incorporated.

What are the penalties for non-compliance?

Prohibited uses: up to 35 million euros or 7 percent of global annual turnover, whichever is higher. High-risk violations: up to 15 million euros or 3 percent of global turnover. Providing incorrect information to regulators: up to 7.5 million euros or 1 percent of global turnover.

When do the obligations apply?

Prohibited use provisions applied from August 2024. Obligations for general purpose AI models apply from August 2025. High-risk system requirements apply from August 2026. Certain high-risk systems have additional transition periods.

What if we use third-party AI tools like ChatGPT or Microsoft Copilot?

Deployers of third-party AI tools carry obligations depending on how those tools are used. Using a general-purpose AI model in a high-risk application context can create high-risk obligations for the deployer even if the model itself carries limited-risk classification.

How long does the assessment take?

Typically three to four weeks depending on the number of AI systems, geographic footprint, and current documentation maturity.

What is the relationship between the EU AI Act and ISO 42001?

ISO 42001 is the AI management system standard. It provides an operational framework for managing AI systems that complements the legal obligations of the EU AI Act. AIVARA Core 360 maps controls across both simultaneously.

CorpStage uses cookies to understand how visitors use the site and to improve your experience. Analytics cookies are only set if you accept. Privacy Policy