The EU AI Act is in force.
Most organisations do not know where they stand.
The EU AI Act is the world’s first comprehensive legal framework for artificial intelligence. It applies to any organisation that develops, deploys, or uses AI systems in the EU, and to organisations outside the EU whose AI outputs affect people within it. For companies across APAC and the GCC, that reach is wider than most legal teams have assessed.
Prohibited uses carry fines of up to 35 million euros or 7 percent of global annual turnover. CorpStage maps your AI systems, classifies them against the Act’s risk tiers, identifies your obligations, and builds the gap analysis and remediation roadmap you need before the deadlines apply to you.
Four risk tiers. Very different obligations at each level.
Unacceptable Risk — Prohibited
AI systems banned outright. Social scoring by public authorities. Real-time biometric surveillance in public spaces. Subliminal manipulation. Exploitation of vulnerable groups. If your organisation operates any of these, the obligation is immediate cessation.
High Risk — Significant Obligations
AI in critical infrastructure, education, employment, essential services, law enforcement, migration, and justice. Requires conformity assessment before deployment, technical documentation, logging and audit trail, human oversight, and registration in the EU database.
Limited Risk — Transparency
AI systems that interact with people or generate content. Chatbots, deepfakes, and AI-generated content require disclosure to users that they are interacting with AI or viewing AI-generated material.
Minimal Risk — No Specific Obligations
AI systems that carry low risk to rights or safety. No specific requirements under the Act, though general product safety law still applies.
General Purpose AI Models
Foundation models and large language models have specific requirements around transparency, copyright compliance, systemic risk assessment, and reporting. Obligations depend on how third-party models are used and adapted.
The EU AI Act reaches further than most organisations expect
Providers
Organisations that develop AI systems placed on the EU market or put into service in the EU, regardless of where the provider is based.
Deployers
Organisations that use AI systems in a professional context in the EU. This includes organisations outside the EU using AI tools whose outputs affect people within it.
Importers and Distributors
Organisations that bring AI systems from outside the EU into the EU market.
APAC and GCC organisations specifically
If your organisation exports to the EU, operates EU subsidiaries, uses AI tools that process EU citizen data, or uses AI-generated content in EU-facing products, the Act’s reach extends to you. The prohibited use provisions applied from August 2024. High-risk system obligations apply from August 2026.
A structured assessment across five areas
AI System Inventory
Identify all AI systems across your organisation. Built, bought, or embedded in third-party tools. Most organisations discover more AI use than they initially account for.
Risk Classification
Map each system against the EU AI Act's four risk tiers. Determine whether systems fall into prohibited, high-risk, limited risk, or minimal risk categories.
Obligation Mapping
For high-risk systems, identify conformity assessment, documentation, logging, human oversight, and registration obligations. For limited-risk systems, identify transparency disclosure requirements.
Gap Analysis
Compare current AI governance practices against what the Act requires. Identify specific gaps in technical documentation, control design, human oversight, audit trail, and risk management.
Remediation Roadmap
A sequenced plan showing what to address before which deadline, who owns each action, and how AIVARA Core 360 supports ongoing compliance.
Five outputs. From inventory to roadmap.
AI System Inventory and Classification Register
A complete register of AI systems with risk classification, use context, affected populations, and deployment geography. The foundational document from which all other compliance work flows.
EU AI Act Obligation Matrix
A precise mapping of your specific obligations under the Act by system and risk tier. What is required, when, from whom, and what evidence needs to exist.
Gap Analysis Report
A structured assessment of where current AI governance practices fall short of EU AI Act requirements. Written for the legal, technology, and risk functions simultaneously.
Remediation Roadmap
A sequenced action plan showing what to fix before which deadline. Prioritised by regulatory risk, technical complexity, and organisational readiness.
Board and Executive Summary
A one-page view of your EU AI Act exposure, key obligations, and the steps being taken to address them. Written for board members who need the risk without the regulation.
AIVARA Core 360 turns the assessment into an ongoing control environment
The AI system inventory becomes the AI asset register. The obligation mapping feeds into the 150-control AI Control Library. The gap analysis becomes the control gap tracker. Compliance is not a one-time project. AIVARA Core 360 manages the ongoing environment as the Act is updated and new AI systems are deployed.
CTOs and Chief AI Officers
Technology leaders responsible for AI deployment who need a structured view of regulatory obligations before systems go live or before regulatory deadlines arrive.
Legal and Compliance Teams
Teams that need to translate the EU AI Act's legal text into specific organisational obligations, documented assessments, and defensible evidence of compliance.
Risk and Internal Audit
Functions that need to assess AI-related regulatory risk, build audit programmes around AI systems, and report on AI governance to the board or audit committee.
Boards and Audit Committees
Boards that need to understand AI regulatory exposure and confirm that management is taking appropriate steps before obligations become enforceable.
Questions before you start
Does the EU AI Act apply to us if we are based in Singapore or the GCC?
Yes, if your AI systems are used in the EU, deployed in EU-facing products, or produce outputs that affect EU residents. The Act applies to providers and deployers regardless of where they are incorporated.
What are the penalties for non-compliance?
Prohibited uses: up to 35 million euros or 7 percent of global annual turnover, whichever is higher. High-risk violations: up to 15 million euros or 3 percent of global turnover. Providing incorrect information to regulators: up to 7.5 million euros or 1 percent of global turnover.
When do the obligations apply?
Prohibited use provisions applied from August 2024. Obligations for general purpose AI models apply from August 2025. High-risk system requirements apply from August 2026. Certain high-risk systems have additional transition periods.
What if we use third-party AI tools like ChatGPT or Microsoft Copilot?
Deployers of third-party AI tools carry obligations depending on how those tools are used. Using a general-purpose AI model in a high-risk application context can create high-risk obligations for the deployer even if the model itself carries limited-risk classification.
How long does the assessment take?
Typically three to four weeks depending on the number of AI systems, geographic footprint, and current documentation maturity.
What is the relationship between the EU AI Act and ISO 42001?
ISO 42001 is the AI management system standard. It provides an operational framework for managing AI systems that complements the legal obligations of the EU AI Act. AIVARA Core 360 maps controls across both simultaneously.