AI Governance Library

EU AI Act Compliance Matrix

An IAPP reference matrix mapping the articles of the EU AI Act to the operators they primarily concern — providers, deployers, importers, distributors, product manufacturers and authorised representatives — across high-risk AI systems, AI systems and general-purpose AI models.
Cover of EU AI Act Compliance Matrix

⚡ Quick Summary

Published by the IAPP, this compliance matrix is a reference aid for organisations working towards compliance with the EU AI Act. It presents the Act's requirements as tables that map individual articles to the operators they primarily concern across three classes: high-risk AI systems, AI systems and general-purpose AI models. Checkmarks indicate the operators to which an article is of primary relevance, while the text notes that a requirement may still be applicable to others not explicitly marked.

The document defines six operator roles — providers, deployers, importers, distributors, product manufacturers and authorised representatives — quoting Articles 3(3), 3(4), 3(6), 3(7), 2(1)(e) and 3(5), and lists exclusions from scope under Article 2, including military, defence and national security uses, scientific research, purely personal non-professional use and most open-source systems.

The tables then cover high-risk AI systems, from Article 6 to Article 86, from risk management and data governance through human oversight, conformity assessment, registration, post-market monitoring and incident reporting, plus other AI systems (Articles 4, 49, 50 and 71) and general-purpose AI models (Articles 41 and 51 to 56, including systemic-risk classification and codes of practice).

🧩 What’s Covered

  • The operators: definitions of the six roles addressed by the Act — provider (Article 3(3)), deployer (3(4)), importer (3(6)), distributor (3(7)), product manufacturer (2(1)(e), with the Article 25(3) rule that a manufacturer of a product containing a safety-component high-risk AI system becomes its provider) and authorised representative (3(5)).
  • Who or what is excluded: a "nonexhaustive list" from Article 2 covering military, defence and national security uses (2(3)), third-country law enforcement and judicial cooperation (2(4)), research and development (2(6), 2(8)), personal non-professional use (2(10)) and free and open-source systems unless high risk or caught by Articles 5 or 50 (2(12)).
  • High-risk AI systems: tables covering Articles 6, 8–27, 41, 43–44, 47–49, 71–73 and 86, from classification rules, risk management, data governance, technical documentation, record-keeping, transparency, human oversight and cybersecurity through quality management, 10-year documentation keeping, six-month log retention, corrective actions, importer and distributor duties, value-chain responsibilities, deployer obligations, fundamental rights impact assessments, conformity assessment, CE marking, registration, post-market monitoring and incident reporting to the right to explanation.
  • AI systems: Articles 4, 49, 50 and 71 — AI literacy for staff and users, registration and EU database entry, and transparency towards people interacting with an AI system.
  • General-purpose AI models: Articles 41 and 51–56 plus 89 — common specifications, classification of models with systemic risk, notification procedures, provider documentation duties, authorised representatives in third countries, model evaluation and systemic-risk mitigation, codes of practice, and complaints by downstream providers.
  • Contacts and disclaimer: Müge Fazlioglu, Joe Jones, research@iapp.org, and a statement that nothing in the material is legal advice.

💡 Why it matters?

The matrix answers a scoping question that precedes most EU AI Act work: which articles bind which role in the value chain. By separating high-risk systems, other AI systems and general-purpose models, and marking the operators each article mainly addresses, it lets a provider, deployer, importer, distributor or product manufacturer read its own column instead of the whole Act. The exclusions list helps teams rule out activities before investing in compliance work. It is a navigation aid rather than an interpretation of the requirements, and assumes the reader will then consult the articles themselves.

❓ What’s Missing

Each article is summarised in one or two lines, so the matrix gives locations and headline topics, not the substance of the obligations: thresholds, technical detail and the wording of requirements are absent. It does not cover Article 5 prohibited practices or penalties, nor the phased application dates of the Act. Annex III categories are referenced but not reproduced, and the systemic-risk thresholds behind Article 51 are not quantified. Only the EU regime appears; there is no mapping to other frameworks. The checkmarks that carry the operator mapping are not present in the extracted text.

👥 Best For

Compliance and legal teams mapping which AI Act articles attach to their organisation's role; providers and deployers building gap analyses or control inventories; importers, distributors and product manufacturers checking downstream duties; and policy or research staff who need a quick orientation to the Act's structure and scope exclusions before reading the articles themselves.

📄 Source Details

EU AI Act Compliance Matrix, by Müge Fazlioglu, CIPP/E, CIPP/US, Principal Researcher, Privacy Law and Policy at the IAPP; published by the IAPP, last updated October 2024; 14 pages, English. The document states the analysis is based on the EU AI Act published 13 June 2024 in the Official Journal of the European Union. Contacts for Müge Fazlioglu, Joe Jones and research@iapp.org are printed. No URL for the document itself appears; readers are directed to iapp.org for a condensed version. The text extraction covered all 14 pages, but table checkmarks were not captured.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.