EU AI Act Compliance with TealTiger
The EU AI Act (Regulation 2024/1689) is the world’s first comprehensive legal framework for artificial intelligence, establishing harmonized rules for the development, deployment, and use of AI systems in the European Union. It came into force on August 1, 2024, with a phased implementation timeline through 2027. TealTiger provides essential capabilities to help enterprises comply with EU AI Act requirements, particularly for high-risk AI systems that use Large Language Models (LLMs) and agentic AI.EU AI Act Overview
Risk-Based Classification
The EU AI Act classifies AI systems into four risk categories:| Risk Level | Examples | Requirements |
|---|---|---|
| Unacceptable Risk | Social scoring, real-time biometric identification | Prohibited |
| High Risk | Critical infrastructure, employment, law enforcement, education | Strict compliance required |
| Limited Risk | Chatbots, emotion recognition | Transparency obligations |
| Minimal Risk | AI-enabled video games, spam filters | No obligations |
High-Risk AI System Requirements
Article 9: Risk Management System
Requirement: Establish and maintain a risk management system throughout the AI system’s lifecycle. TealTiger Support (v1.0+):TealGuard Policies
Define risk mitigation policies for PII exposure, prompt injection, content moderation, and budget overruns
Policy Modes
Use MONITOR mode to assess risks before enforcement, then transition to ENFORCE mode
Risk Scoring
Assign risk scores to policy violations for prioritization and escalation
Continuous Monitoring
Real-time detection and logging of policy violations across all LLM interactions
- Automated risk assessment scoring
- Risk heat maps and dashboards
- Integration with enterprise risk management systems
Article 10: Data and Data Governance
Requirement: Training, validation, and testing data must be relevant, representative, and free from errors and biases. TealTiger Support (v1.0+):Input Validation
Validate and sanitize all inputs before sending to LLMs
Content Moderation
Detect and block harmful, biased, or inappropriate content
Audit Logging
Log all inputs, outputs, and policy decisions for data governance
Redaction
Automatically redact sensitive data from logs and audit trails
- Bias detection and mitigation
- Data quality metrics and reporting
- Automated data lineage tracking
Article 11: Technical Documentation
Requirement: Maintain detailed technical documentation describing the AI system’s design, development, and performance. TealTiger Support (v1.0+):Policy Documentation
Document all guardrails, policies, and risk mitigation strategies
Decision Logs
Comprehensive logs of all policy decisions with reason codes
Audit Events
Structured audit events with versioned schema for compliance reporting
Configuration Export
Export TealEngine configuration for documentation and audits
- Automated technical documentation generation
- Compliance report templates (EU AI Act format)
- Integration with document management systems
Article 12: Record-Keeping
Requirement: Keep logs of AI system operations for at least 6 months (or longer for high-risk systems). TealTiger Support (v1.0+):Audit Logging
Persistent logging of all LLM interactions and policy decisions
Structured Events
Versioned audit event schema for long-term storage and retrieval
Correlation IDs
Trace requests across distributed systems for compliance audits
Retention Policies
Configurable retention periods (6 months to 10 years)
- Automated compliance report generation
- Integration with SIEM systems (Splunk, Datadog)
- Long-term archival to AWS Glacier / Azure Archive
Article 13: Transparency and Information to Users
Requirement: Inform users that they are interacting with an AI system and provide clear information about its capabilities and limitations. TealTiger Support (v1.0+):Decision Transparency
Expose policy decisions and reason codes to users
Guardrail Notifications
Inform users when guardrails are triggered
Cost Transparency
Show users the cost of LLM interactions
Provider Disclosure
Disclose which LLM provider is being used
- User-facing transparency dashboard
- Automated AI disclosure banners
- Multi-language transparency notices
Article 14: Human Oversight
Requirement: High-risk AI systems must be designed to enable effective human oversight. TealTiger Support (v1.0+):Policy Modes
MONITOR mode allows human review before enforcement
Manual Override
Humans can override policy decisions when appropriate
Escalation Workflows
High-risk decisions can be escalated to human reviewers
Audit Review
Humans can review audit logs and policy violations
- Human review dashboard
- Approval workflows with SLA tracking
- Integration with ticketing systems (Jira, ServiceNow)
Article 15: Accuracy, Robustness, and Cybersecurity
Requirement: AI systems must achieve appropriate levels of accuracy, robustness, and cybersecurity. TealTiger Support (v1.0+):Prompt Injection Defense
Detect and block prompt injection attacks
Input Validation
Validate all inputs for malicious content
Rate Limiting
Prevent abuse and DDoS attacks
Budget Controls
Prevent runaway costs from adversarial inputs
- Adversarial robustness testing
- Model output validation
- Automated security scanning
Limited-Risk AI System Requirements
Article 50: Transparency Obligations
Requirement: Users must be informed that they are interacting with an AI system. TealTiger Support (v1.0+): All TealTiger features for high-risk systems also apply to limited-risk systems, with simplified configuration:Compliance Roadmap
Current Capabilities (v1.0 - v1.1)
Planned Enhancements (v1.2 - v1.3)
Automated Risk Assessment (v1.2)
Risk heat maps, automated scoring, integration with enterprise risk management
Future Platform Features (v2.0+)
Centralized Compliance Hub
Multi-tenant platform for managing EU AI Act compliance across organizations
Implementation Timeline
The EU AI Act has a phased implementation timeline:| Date | Milestone | TealTiger Readiness |
|---|---|---|
| Aug 2, 2024 | EU AI Act enters into force | ✅ Core capabilities available |
| Feb 2, 2025 | Prohibited AI practices banned | ✅ Content moderation ready |
| Aug 2, 2025 | General-purpose AI model rules apply | ✅ LLM guardrails ready |
| Aug 2, 2026 | High-risk AI system obligations apply | ✅ v1.1 compliance features |
| Aug 2, 2027 | Full enforcement for all AI systems | 🚧 v1.3 full compliance |
Best Practices for EU AI Act Compliance
1. Classify Your AI System
1. Classify Your AI System
Determine if your LLM application is high-risk, limited-risk, or minimal-risk based on EU AI Act Annex III.High-risk examples:
- Employment decisions (hiring, firing, promotions)
- Credit scoring and loan approvals
- Law enforcement applications
- Critical infrastructure management
- Educational assessments
- Customer service chatbots
- Content generation tools
- Marketing assistants
2. Implement Risk Management
2. Implement Risk Management
Use TealGuard policies to identify, assess, and mitigate risks throughout the AI system lifecycle.
3. Maintain Technical Documentation
3. Maintain Technical Documentation
Document all TealEngine configurations, policies, and risk mitigation strategies.
- Export TealEngine configuration regularly
- Document policy changes and rationale
- Maintain audit logs for at least 2 years
- Create compliance reports quarterly
4. Enable Human Oversight
4. Enable Human Oversight
Design workflows that allow humans to review and override AI decisions.
5. Ensure Transparency
5. Ensure Transparency
Inform users that they are interacting with an AI system and provide clear information.
- Display AI disclosure banners
- Show guardrail notifications to users
- Provide cost transparency
- Explain policy decisions with reason codes
6. Test for Robustness
6. Test for Robustness
Regularly test your AI system for accuracy, robustness, and security.
- Use TealTiger’s policy test harness (v1.1+)
- Conduct adversarial testing
- Monitor for prompt injection attacks
- Review audit logs for anomalies
Compliance Checklist
Use this checklist to assess your EU AI Act compliance readiness:- High-Risk Systems
- Limited-Risk Systems
High-Risk AI System Compliance Checklist
- Risk Management System (Article 9)
- TealGuard policies defined for all identified risks
- Risk scores assigned to policy violations
- Policy modes configured (MONITOR → ENFORCE)
- Continuous monitoring enabled
- Data Governance (Article 10)
- Input validation implemented
- Content moderation enabled
- Audit logging configured
- PII redaction enabled (GDPR compliance)
- Technical Documentation (Article 11)
- TealEngine configuration documented
- Policy documentation maintained
- Decision logs exported regularly
- Audit event schema documented
- Record-Keeping (Article 12)
- Audit logs retained for ≥2 years
- Logs stored in durable storage (S3, Azure Blob)
- Logs encrypted at rest (AES-256)
- Correlation IDs enabled for traceability
- Transparency (Article 13)
- AI disclosure banner displayed to users
- Guardrail notifications shown to users
- Cost transparency enabled
- Reason codes exposed in UI
- Human Oversight (Article 14)
- MONITOR mode used for risk assessment
- Manual override capability implemented
- Escalation workflows configured
- Human review dashboard deployed (v1.2+)
- Accuracy & Cybersecurity (Article 15)
- Prompt injection detection enabled
- Input validation configured
- Rate limiting implemented
- Budget controls set
Getting Help
Documentation
Review TealTiger’s governance reference architecture
Best Practices
Follow our governance best practices checklist
Support
Contact our team for EU AI Act compliance guidance
Consulting
Enterprise consulting for EU AI Act compliance
Additional Resources
EU AI Act Full Text
Official EU AI Act regulation (Regulation 2024/1689)
European AI Office
European Commission’s AI Office for guidance and support
OWASP Top 10 for LLMs
Security best practices for LLM applications
GDPR Compliance
TealTiger’s GDPR compliance features
Disclaimer: This documentation provides general guidance on how TealTiger can support EU AI Act compliance. It is not legal advice. Organizations should consult with legal counsel to ensure full compliance with the EU AI Act and other applicable regulations.
Last Updated: March 7, 2026
TealTiger Version: v1.0 - v1.1
EU AI Act Version: Regulation (EU) 2024/1689

