EU AI Act: High-Risk System Compliance
Annex III classification, Article 9 risk management, Article 10 data governance, Article 15 accuracy and robustness, and the Annex IV technical file. What a Canadian FRFI with EU reach must produce before August 2, 2026.
What this paper is for.
Regulation (EU) 2024/1689, the EU AI Act, applies its high-risk obligations on August 2, 2026. Extraterritorial reach captures any provider or deployer placing AI on the EU market, plus any system whose output is used in the EU. This paper walks the full conformity assessment path for Canadian, US and UK institutions: classification, obligations, technical file, post-market monitoring, and how the same artifacts answer OSFI E-23, NIST AI RMF, and ISO 42001.
The takeaways our research desk stands behind.
- Extraterritorial scope captures institutions without an EU establishment. Output-based reach is the trigger most teams miss.
- Article 10 data governance is the hardest clause to retrofit; plan for it from day one.
- Annex IV technical documentation is the deliverable, not the sum of internal artifacts.
- GPAI obligations cascade to deployers through contractual flow-down. Due diligence must be documented.
- Serious incident reporting windows are short: 15 days baseline, 10 days for death cases, and 2 days for widespread infringement or critical infrastructure disruption.
What is inside.
- Executive summary
- Scope, extraterritoriality, and staged enforcement
- Prohibited practices: Article 5 screening
- High-risk classification: Annex III walkthrough
- Article 9: Risk management system
- Article 10: Data governance and quality
- Article 11: Technical documentation (Annex IV)
- Article 13: Transparency and user information
- Article 14: Human oversight
- Article 15: Accuracy, robustness, cybersecurity
- GPAI obligations and model provider diligence
- Post-market monitoring and incident reporting
- Conformity assessment routes
- Cross-walk: OSFI E-23, NIST AI RMF, ISO 42001
- Deployer vs provider obligations
- Appendix: Annex IV compilation checklist
Regulator and standards reach.
General Counsel, Data Protection Officers, Chief AI Officers and AI risk teams in cross-border institutions.