AI Governance

Available now

EU AI Act · 2024

The EU AI Act (Regulation (EU) 2024/1689) is the European Union’s risk-based law for artificial intelligence. It sorts AI into tiers, prohibited practices, high-risk systems with strict requirements, limited-risk transparency duties, and minimal-risk, and adds obligations for general-purpose AI models.

31

requirements tracked · part of the standard

Premium

Access

Add-on from $39/mo

Scope

How much of the standard Keel models

Models part of the standard

Keel models part of this standard, not all of it. A readiness score here is a percentage of the scope described below, not of the whole published standard, so read it that way, and tell your assessor the same.

What is not modeled: The Act is a regulation, not a control set, so it has no canonical leaf inventory. Keel models the enumerable obligations by risk tier. Deciding what "complete" means here is a product decision, not an authoring backlog.

Authored in Keel
31 requirements · part of the standard
Defined by the standard
Not verified against the published standard yet, so Keel states no number

Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework

Who it is for

Who needs EU AI Act?

  • Companies placing AI systems on the EU market or serving EU users
  • Providers and deployers of high-risk AI use cases
  • Teams that need to know which tier their AI falls into and what it triggers

What Keel does

How Keel helps with EU AI Act

  • The Act organized by risk tier so you can see which obligations apply to you
  • Prohibited practices, high-risk requirements, transparency, and GPAI duties as a control set
  • Coverage shared with ISO 42001 and the NIST AI RMF so overlapping work counts once

Collect once, comply everywhere

EU AI Act shares canonical controls with AI Governance Essentials, ISO/IEC 42001 and NIST AI Risk Management Framework. Implement one of those controls and it counts toward every framework it satisfies, so adding EU AI Act rarely means starting from scratch.

Shares canonical controls with

  • ISO/IEC 27001 no shared canonical controls
  • CIS Critical Security Controls no shared canonical controls
  • PCI DSS no shared canonical controls
  • SOC 2 no shared canonical controls
  • SOX (Sarbanes-Oxley) Section 404 no shared canonical controls
  • NIST Cybersecurity Framework no shared canonical controls
  • NIST SP 800-53 no shared canonical controls
  • FedRAMP Rev5 Class B no shared canonical controls
  • FedRAMP Rev5 Class C no shared canonical controls
  • FedRAMP Rev5 Class D no shared canonical controls
  • FedRAMP 20x no shared canonical controls
  • FedRAMP Consolidated Rules no shared canonical controls
  • NIST SP 800-171 no shared canonical controls
  • HIPAA no shared canonical controls
  • GDPR no shared canonical controls
  • COPPA no shared canonical controls
  • Google Play Families no shared canonical controls
  • Amazon Appstore Child-Directed Apps no shared canonical controls
  • Apple App Store Kids Category no shared canonical controls
  • PIPEDA no shared canonical controls
  • ISO 9001 no shared canonical controls
  • AI Governance Essentials shares canonical controls
  • ISO/IEC 42001 shares canonical controls
  • NIST AI Risk Management Framework shares canonical controls
  • ESG Essentials no shared canonical controls
  • US Employment Law - Federal Baseline no shared canonical controls

A framework is lit when at least one canonical control satisfies both EU AI Act and that framework. Unlit means none of them do, which is an absence rather than a judgment about that standard. 3 of 26 are lit here.