Contact

What are you looking for?

EU AI Act Compliance & Assurance Services

Achieve EU AI Act compliance and strengthen trust in your AI systems with independent assurance services from SGS.

The EU Artificial Intelligence Act is the world’s first comprehensive legal framework for AI. Adopted in 2024, it introduces a risk-based approach to ensure AI systems used in the EU are safe, transparent and respect fundamental rights. Organizations that develop, deploy or use AI systems must now demonstrate compliance across governance, data, technical performance and post-market monitoring.

We support you at every stage of your EU AI Act journey. From early gap analysis and governance alignment to technical testing, conformity assessment and certification, our end-to-end services help you meet regulatory obligations, reduce risk and build confidence in responsible AI.

Understanding the EU AI Act risk categories

The EU AI Act classifies AI systems into four categories based on risk:

  • Prohibited AI practices: including social scoring and manipulative techniques
  • High-risk AI systems: such as medical devices, autonomous vehicles and credit scoring
  • Limited-risk AI systems: subject to transparency obligations
  • Minimal-risk AI systems: with no specific regulatory requirements
CSRD

Discover the benefits of EU AI Act compliance services from SGS

  • Navigate complexity with confidence

    We help you understand which EU AI Act categories apply to your AI systems and what actions are required.

  • Identify risks early

    Our structured gap analyses highlight weaknesses across governance, data, models and processes.

  • Prove trustworthy AI

    Independent testing and certification demonstrate safety, transparency and accountability.

  • Build internal capability

    Training and advisory services equip your teams to manage compliance over time.

Our EU AI Act compliance and assurance services

The EU AI Act requires providers of high-risk AI systems to establish and maintain a quality management system (QMS) covering key aspects of the AI life cycle, from development, validation and risk management to change management and post-market activities.

We can support you in implementing and demonstrating effective quality management practices through EN 18286 – AI Quality Management for EU AI Act Regulatory Purposes, a European standard to support compliance with regulatory requirements applicable to high-risk AI systems.

Learn more about our EN 18286 services.

Transparency is a fundamental principle of the EU AI Act. Organizations may be required to provide clear information about AI system capabilities, limitations, intended use, human oversight measures and AI-generated content. Additional transparency obligations apply to General-Purpose AI (GPAI) models and various AI applications covered by the regulation.

We can help you assess and strengthen your transparency practices, supporting compliance with applicable EU AI Act requirements while building trust among users, customers and regulators.

Learn more about our AI Transparency Services.

Demonstrate compliance through independent assessment and certification, including:

Validate AI system performance, robustness and trustworthiness across model types and use cases.

We provide:

  • Technical AI model and data test protocol, and an evaluation report with reproducible metrics
  • Evidence pack: traceability to requirements, results and identified gaps
  • Corrective action recommendations

Testing includes:

  • In-scope performance and known limitations (e.g. operating conditions and acceptance criteria)
  • Robustness and stress testing (e.g. edge cases, perturbations and distribution shift)
  • Large language model (LLM) security testing (e.g. prompt injection and jailbreaks)
  • Privacy and data leakage testing (e.g. personally identifiable information (PII) leakage checks and inference-style risks)
  • Bias and discrimination testing (e.g. subgroup performance and fairness indicators)
  • Explainability testing (e.g. local and global explainability, timeliness and relevance)

Supported AI model types:

  • LLMs and chatbots
  • Computer vision systems
  • Recommendation engines
  • Deep neural networks (DNNs)

AI trustworthiness pillars assessed:

  • Human agency and oversight
  • Technical robustness and safety
  • Privacy and data governance
  • Transparency
  • Diversity, non-discrimination and fairness
  • Societal and environmental well-being
  • Accountability
Innovation and Digital Transformation Concept

EU AI Act compliance services from a leader in digital trust

As the world’s leading testing, inspection and certification company, we are trusted globally to deliver independent assurance across complex regulatory frameworks. As a Notified Body under multiple EU regulations, including MDR, IVDR, RED and the Machinery Regulation, we provide robust industry-focused EU AI Act compliance and assurance services.


Our services combine regulatory expertise, deep technical capabilities and a global network of digital trust specialists, enabling you to move from readiness to certification with confidence.

Frequently asked questions

The EU AI Act governs the development and use of artificial intelligence within the EU to ensure safety, transparency and protection of fundamental rights. It applies a risk-based regulatory approach depending on the intended use and potential impact of AI systems.

Compliance is both a legal and strategic requirement. Failure to comply can lead to substantial fines, product bans and loss of EU market access. Demonstrating compliance builds trust with regulators, customers and stakeholders while reinforcing leadership in responsible AI.

  • August 2024: EU AI Act enters into force
  • February 2025: AI literacy requirements and prohibitions on certain AI practices apply
  • August 2025: rules for General-Purpose AI (GPAI) models, governance and penalties apply
  • August 2026: transparency requirements become applicable
  • December 2027: compliance requirements for stand-alone high-risk AI systems apply
  • August 2028: compliance requirements for high-risk AI embedded in regulated products apply

The compliance deadlines differ depending on the AI system. The timeline is:

  • Annex III (high-risk systems in sensitive-use areas): August 2, 2026
    • AI systems used in sensitive sectors (e.g. biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, asylum, border control, justice and democratic processes)
  • Annex I (high-risk AI in regulated products and safety-critical components): August 2, 2027
    • AI systems that are regulated products (e.g. medical devices, machinery, toys and radio equipment) or safety components of such products and, therefore, require third-party conformity assessment under those regulations

Requirements include risk management, technical documentation, human oversight, transparency and post-market monitoring. Organizations should prepare now to ensure timely conformity assessment.

Penalties can reach up to EUR 35 million or 7% of global annual turnover. Non-compliance may also result in restricted or prohibited access to the EU market.

ISO/IEC 42001 is the first AI management system (AIMS) standard. It provides a structured framework for governance, risk management and accountability, supporting alignment with EU AI Act requirements and enabling efficient audits and global recognition.

EN 18286 is a European standard that provides requirements for quality management systems (QMS) supporting regulatory compliance for high-risk AI systems. It can help you establish structured processes for managing AI development, validation, risk management, documentation, change control and post-market activities. Implementing EN 18286 can support you in demonstrating readiness for applicable EU AI Act requirements. 

Yes. Providers of high-risk AI systems must establish and maintain a QMS covering key elements of the AI life cycle. The system should support consistent governance, risk management, technical documentation, monitoring and continual improvement.

The EU AI Act introduces transparency obligations for certain AI systems and General-Purpose AI (GPAI) models. Depending on the use case, your organization may need to provide information about AI capabilities, limitations, intended use, human oversight measures and AI-generated content. We offer AI Transparency Services to help you assess and strengthen compliance with these requirements.

ISO/IEC 42001 provides a foundation for AI governance, risk management and accountability across all AI systems. EN 18286 builds on these principles with quality management requirements designed to support compliance of high-risk AI systems under the EU AI Act.

For many organizations, ISO/IEC 42001 is the first step toward establishing a governance framework for future EN 18286 implementation.

News & Insights

  • SGS - Finland - Helsinki - SGS Academy

Takomotie 8,

00380,

Helsinki,

Finland