UNUS London  —  Compliance Architecture Division  |  UNCLASSIFIED // REGULATED INDUSTRIES
Home Solutions Legal & Professional Financial Services Manufacturing Healthcare Academy Blogs Ebooks About Book Discovery Call UNUS Govern
Regulatory Reference // EU AI Act 2024/1689

European Union
AI Act Bridge Series

The EU AI Act (Regulation 2024/1689) entered into force in August 2024 as the world's first comprehensive AI regulatory framework. UNUS London's Bridge Series maps every high-risk AI obligation directly to ISO/IEC 42001:2023 controls and database-driven evidence artefacts — giving UK regulated organisations a dual-compliance pathway from a single implementation.

Regulation Metadata
Regulation Reference
EU 2024/1689
Official Title
Artificial Intelligence Act
Entry into Force
1 August 2024
Full Application
2 August 2026
High-Risk AI Articles
Art. 8–15 — 8 Obligations
AIMS Bridge Standard
ISO/IEC 42001:2023
UNUS Bridge Coverage
100% High-Risk Articles
Deployment Tier
Enterprise — £32,347
🇪🇺
Regulation Purpose
The EU AI Act establishes a harmonised legal framework governing AI systems placed on or put into service in the EU market. Its risk-based approach classifies AI systems into four tiers — from Unacceptable Risk (prohibited) to Minimal Risk — with binding obligations for high-risk deployments.
🇬🇧
UK Relevance Post-Brexit
UK organisations operating in EU markets, supplying AI systems to EU providers, or serving EU clients shall assess EU AI Act applicability. UK regulators — including the FCA, ICO, and SRA — are actively monitoring for alignment. Early compliance reduces dual-regime risk and demonstrates AI accountability.
🔗
The UNUS Bridge Approach
UNUS London's Bridge Series cross-references each EU AI Act obligation to the corresponding ISO/IEC 42001:2023 control, database artefact, and UNUS Govern module. One implementation programme delivers conformance against both the international standard and the EU regulatory framework simultaneously.

The Four-Tier
AI Risk System

The EU AI Act classifies AI systems by risk level. The classification determines the applicable obligations. Organisations shall determine which tier applies to each AI system they develop, deploy, or use — prior to placing the system on the market or into service.

Unacceptable Risk

Prohibited AI Systems

AI systems posing an unacceptable risk to fundamental rights and safety are prohibited and shall not be deployed. No exceptions apply.

  • Social scoring by public authorities
  • Real-time biometric surveillance in public spaces
  • Subliminal manipulation of behaviour
  • Exploitation of vulnerable groups
High Risk

High-Risk AI Systems

Subject to mandatory requirements under Articles 8–15, including conformity assessment, registration, and ongoing monitoring obligations.

  • AI in legal proceedings and interpretation
  • Employment and recruitment screening AI
  • Credit scoring and access to essential services
  • Medical devices with AI components
  • Education and vocational training AI
Limited Risk

Limited Risk AI Systems

Transparency obligations apply — users shall be informed they are interacting with an AI system. Specific disclosure requirements for chatbots and deepfakes.

  • Chatbots and conversational AI
  • Emotion recognition systems
  • AI-generated content (disclosure required)
  • Deepfake generation tools
Minimal Risk

Minimal Risk AI Systems

No mandatory requirements apply. The Act encourages voluntary codes of conduct for minimal risk systems to support responsible AI use.

  • AI-powered spam filters
  • AI in video games
  • Inventory management AI
  • General productivity AI tools

Bridging EU Obligations
to ISO/IEC 42001 Controls

Each Bridge Series article takes one EU AI Act obligation for high-risk systems and maps it precisely to the corresponding ISO/IEC 42001:2023 AIMS control — then delivers the UNUS database artefact that evidences compliance with both simultaneously.

Bridge Article 1
Risk Management Systems
EU AI Act Art. 9 → ISO/IEC 42001:2023 Cl. 6 + A.8

Mandatory risk management systems for high-risk AI shall be documented, implemented, and maintained throughout the lifecycle. Maps directly to ISO 42001 AI risk assessment and Annex A.8 impact assessment controls — one UNUS AI Risk Register satisfies both.

Bridge Article 2
Data Governance & Management
EU AI Act Art. 10 → ISO/IEC 42001:2023 A.7.1 + A.9.3

Training, validation, and testing data shall meet documented quality criteria, including bias examination and data lineage records. UNUS data acquisition logs and quality control procedures address both the EU Act's Article 10 and ISO 42001's Annex A.7.1 data governance control.

Bridge Article 3
Technical Documentation
EU AI Act Art. 11 → ISO/IEC 42001:2023 Cl. 7.5 + A.9.5

High-risk AI systems shall have technical documentation prepared before market placement and kept up to date. UNUS's controlled document register, aligned to ISO 42001 Clause 7.5, provides version-controlled technical documentation that satisfies Annex III of the EU AI Act.

Bridge Article 4
Record-Keeping & Logging
EU AI Act Art. 12 → ISO/IEC 42001:2023 Cl. 7.5 + Cl. 9

High-risk AI systems shall automatically log events to enable post-market monitoring and investigation of incidents. UNUS Govern's immutable audit trail, designed for ISO 42001 performance evaluation requirements, delivers the automatic logging mandated by Article 12.

Bridge Article 5
Transparency & User Information
EU AI Act Art. 13 → ISO/IEC 42001:2023 A.10.1 + A.10.3

High-risk AI systems shall be sufficiently transparent to enable deployers to interpret outputs and use them appropriately. UNUS transparency records and explainability documentation, mapped to ISO 42001 Annex A.10, address Article 13 user information requirements directly.

Bridge Article 6
Human Oversight Measures
EU AI Act Art. 14 → ISO/IEC 42001:2023 A.7.3 + Cl. 8

High-risk AI systems shall allow effective oversight by natural persons, including the ability to override or halt the system. UNUS human oversight checkpoints, aligned to ISO 42001 Annex A.7.3, produce the documented oversight procedures required by Article 14.

Bridge Article 7
Accuracy, Robustness & Cybersecurity
EU AI Act Art. 15 → ISO/IEC 42001:2023 A.9.4 + ISO 27001

High-risk AI systems shall achieve appropriate levels of accuracy and be resilient to errors and adversarial inputs. UNUS validation and testing records, combined with ISO 27001 security controls, provide the dual evidence trail required by Article 15 and ISO 42001 Annex A.9.4.

Bridge Article 8
Conformity Assessment & Registration
EU AI Act Art. 43–51 → ISO/IEC 42001:2023 Cl. 9 + Cl. 10

High-risk AI systems shall undergo conformity assessment before deployment and be registered in the EU database. UNUS's internal audit programme and management review cycle — aligned to ISO 42001 Clauses 9 and 10 — generate the conformity evidence required to complete registration.

Bridge Article 9
Post-Market Monitoring
EU AI Act Art. 72 → ISO/IEC 42001:2023 Cl. 9.1 + Cl. 10

Providers of high-risk AI shall establish post-market monitoring systems and report serious incidents to authorities. UNUS's nonconformity and incident register, designed for ISO 42001 Clause 10 corrective action requirements, delivers the post-market monitoring evidence mandated by Article 72.

Article-by-Article
Compliance Mapping

The table below maps each high-risk AI obligation under the EU AI Act to its corresponding ISO/IEC 42001:2023 control reference and UNUS London evidence artefact. Organisations deploying one UNUS implementation shall address both frameworks simultaneously.

EU AI Act Article Obligation Summary ISO 42001 Control UNUS Artefact
Art. 9
Risk management system — documented and operational throughout the AI lifecycle
Cl. 6 + A.8.3
AI Risk Register
Art. 10
Data governance — quality criteria, bias checks, and data lineage for training and test data
A.7.1 + A.9.3
Data Acquisition Log
Art. 11
Technical documentation — prepared before market placement, kept up to date
Cl. 7.5 + A.9.5
Document Register
Art. 12
Record-keeping — automatic logging of events throughout the operational lifetime
Cl. 7.5 + Cl. 9.1
Immutable Audit Trail
Art. 13
Transparency — sufficient information for deployers to interpret and use outputs appropriately
A.10.1 + A.10.3
Transparency Records
Art. 14
Human oversight — natural persons able to monitor, override, and halt the AI system
A.7.3 + Cl. 8
Oversight Checkpoint Log
Art. 15
Accuracy, robustness, and cybersecurity — resilient to errors, adversarial attacks, and data corruption
A.9.4 + ISO 27001
Validation & Test Records
Art. 43–51
Conformity assessment and EU database registration before deployment of high-risk systems
Cl. 9 + Cl. 10
Audit Programme + SoA
Art. 72
Post-market monitoring — systematic collection and review of data on operational performance
Cl. 9.1 + Cl. 10
NCR & Incident Register

UK Obligations
Alongside EU Requirements

UK organisations must navigate both domestic AI governance expectations and potential EU AI Act exposure. UNUS London's Bridge Series is structured to address both simultaneously — protecting against regulatory uncertainty on both sides of the Channel.

⚖️

UK Domestic Obligations

SRA, FCA, ICO, NHS — AI Governance
  • SRA Code of Conduct — competence obligations apply to AI-assisted legal work
  • ICO guidance on AI — accountability framework aligned to UK GDPR Article 22
  • FCA Consumer Duty — AI outputs in financial advice shall be fair and explainable
  • NHS AI Lab framework — clinical AI shall evidence patient safety governance
  • MHRA AI-as-a-Medical-Device guidance — lifecycle and post-market surveillance
  • UK AI Safety Institute frameworks — voluntary assurance for frontier AI systems
🔗

EU AI Act Exposure for UK Organisations

Extra-Territorial Application
  • UK providers placing AI systems on the EU market shall comply in full
  • UK organisations deploying AI for EU-based users shall assess applicability
  • UK legal firms serving EU clients with AI-assisted work should assess Art. 6 scope
  • UK financial firms using EU-regulated AI models shall verify provider obligations
  • Supply chain AI — UK manufacturers supplying EU integrators may face indirect obligations
  • UK organisations contracting EU AI providers shall verify provider compliance status

Compliance
Milestones

The EU AI Act applies progressively. Organisations shall track which obligations are now in force and plan for the obligations that apply from 2 August 2026. The timeline below identifies the key milestones relevant to UK organisations.

1 August 2024
Regulation Enters into Force
EU AI Act (Regulation 2024/1689) entered into force. The 24-month transition period for most provisions began. Prohibited AI system provisions apply from 2 February 2025.
In Force
2 February 2025
Prohibited AI Systems — Prohibitions Apply
Chapter II prohibitions on unacceptable risk AI systems entered into application. Organisations shall have removed or discontinued any AI system falling within the prohibited category.
Live
2 August 2025
GPAI Model Obligations Apply
Obligations for General Purpose AI (GPAI) model providers under Chapter V entered into application, including transparency requirements and systemic risk protocols for frontier model providers.
Live
2 August 2026
Full Regulation Application — High-Risk Obligations Active
All provisions, including Articles 8–15 high-risk AI system obligations, apply in full. Providers and deployers of high-risk AI shall have completed conformity assessments, established risk management systems, and registered systems in the EU database. This is the primary deadline for UNUS Bridge Series implementation.
Primary Deadline
2 August 2027
High-Risk AI in Existing Regulated Products
AI systems embedded in products regulated under existing EU sector legislation — including medical devices, machinery, and aviation — gain an additional year to achieve full compliance where the product requires significant re-certification.
Sector Extension

2 August 2026 Is
Closer Than It Looks

UNUS London delivers a fully evidenced EU AI Act compliance programme through the ISO/IEC 42001:2023 Bridge Series — one implementation, dual-framework coverage. High-risk AI operators shall not wait.