SECaaS.IT

EU AI Act

EU AI Act — risk classification in hours, not weeks.

Regulation (EU) 2024/1689 is in force; obligations for high-risk AI systems have applied since 2 August 2026. With PRISM AI Act you classify your system, identify the compliance gap and document in conformity with the standard — as a provider or deployer. 200+ organisations already manage their evidence in PRISM.

Why now

  • • Enterprise customer or investor asking about AI Act conformity in a security questionnaire?
  • • Unclear whether your system qualifies as a high-risk AI system under Annex III?
  • • First AI feature in the product — and no in-house legal department yet?

Obligations for high-risk AI systems (Art. 6, Annex III) apply since 2 August 2026. Violations can be fined up to €35M or 7% of global annual turnover — regardless of company size.

What PRISM brings to the AI Act

AI System Classification & Documentation

AI Act: classify AI systems and document conformity.

The AI Act requires risk classification, technical documentation, conformity assessment and transparency obligations for AI systems. PRISM ISO structures these requirements as actionable controls — mapped to your existing management system.

AI Act Classification High-Risk AI Documentation ISO 42001 Crosswalk
PRISM ISO — AI Act Risk Assessment

Who is this for?

Yes, if

  • SaaS/tech company that develops or deploys an AI system (provider or deployer)
  • Founder or CTO without in-house legal department, enterprise deal or investor requiring AI Act proof
  • Unclear whether own system qualifies as high-risk AI
  • Goal: risk classification and obligations catalogue in days not months

Not suitable

  • Providers of systems with Annex I product integration requiring a notified body for conformity assessment — additional specialist legal advice is needed here
  • Companies without any AI system deployment — ISO 27001 or NIS 2 is the right starting point

Many AI providers also need an ISMS for enterprise deals — with the integrated crosswalk you fulfill the AI Act and ISO 27001 without double effort.

Frequently asked questions about the EU AI Act

What is the EU AI Act?
The EU AI Act is the world's first comprehensive AI regulatory framework. It classifies AI systems by risk level (unacceptable risk → prohibited, high risk → strict requirements, limited risk → transparency obligations, minimal risk → no requirements) and sets out corresponding compliance obligations.
Am I affected by the AI Act?
If you develop, place on the market, operate or use AI systems within your organisation, you are affected. High-risk applications (e.g. in HR, critical infrastructure, medicine, law enforcement) are subject to the strictest requirements, including conformity assessment, technical documentation and registration obligations.
What are the deadlines for the AI Act?
Prohibited AI practices: from February 2025. Requirements for high-risk AI in regulated products (Annex I): from August 2026. Requirements for all other high-risk AI systems (Annex III): from August 2026. GPAI models (General Purpose AI): from August 2025.
What specifically do I need to document?
For high-risk AI systems the AI Act requires: a risk management system, technical documentation (datasets, architecture, performance metrics), conformity assessment, transparency documentation for users, human oversight and post-market monitoring. PRISM ISO maps these requirements as controls — with a crosswalk to ISO 42001.
What is the difference between the AI Act and ISO 42001?
The AI Act is a regulatory obligation (EU Regulation with fines of up to €35M or 7% of global annual turnover). ISO 42001 is a voluntary certification standard for AI management systems. An ISO 42001 certification can serve as evidence of AI Act conformity — PRISM ISO contains both crosswalks.

Software only — or with consultant and auditor?

Three tiers, one goal: your EU AI Act evidence. From the licence to the fixed-price package including auditor.

Compare packages →

So geht PRISM vor

Von der Lücke bis zum laufenden Betrieb.

Vier Phasen, eine Plattform — kein Wechsel zwischen Tools, keine Lücken zwischen Phasen.

Wo stehen Sie heute?
Was muss sich ändern?
Was können Sie dem Auditor zeigen?
Was passiert nach dem Audit?

Wo stehen Sie heute?

PRISM bewertet Ihre bestehenden Dokumente, Prozesse und Kontrollen gegen alle Anforderungen der AI Act. Jede Lücke kommt mit Begründung und direktem Link zur Maßnahme — kein manuelles Zusammensuchen.

Was muss sich ändern?

Aus der Analyse entstehen priorisierte Maßnahmen mit Verantwortlichen, Fristen und Fortschrittsanzeige. Was kritisch ist, steht oben. Verantwortlichkeiten sind klar zugewiesen — kein Aufgaben-Ping-Pong.

Was können Sie dem Auditor zeigen?

Richtlinien, Kontrollen und Evidenz werden norm-konform verwaltet und auf Audit-Bereitschaft geprüft. Das Evidenz-Paket entsteht auf Knopfdruck — mit revisionssicherer Änderungshistorie.

Was passiert nach dem Audit?

PRISM läuft nicht bis zum Zertifikat — danach erst richtig. Wiederkehrende Aufgaben, Monitoring, Vorfallmanagement und AI Act-Überwachungsaudits bleiben in der Plattform. Das ISMS bleibt lebendig.

Was unsere Kunden sagen

„Der Security Health Check war sehr effizient und zielführend und half uns, Transparenz zu schaffen."

Johannes Beier

IT-Leiter · B2B Medical

Security Health Check

Alle Fallstudien lesen →

Trusted by

  • Logo GIZ
  • Logo varisano Kliniken
  • Logo Kath. St. Paulus Gesellschaft
  • Logo Planfox
  • Logo iS2
  • Logo CareSocial
  • Logo EuroTax Consulting
  • Logo nubedian
  • Logo Ypsilon
  • Logo BFMT
  • Logo Haub + Partner
  • Logo DYNAMED
  • Logo B2B Medical

AI risk classification in under 2 hours.

In the initial call we clarify whether and where your system is classified as high-risk AI.