// EU Regulations
EU AI Act Compliance Software
First comprehensive EU legal framework for AI systems, classifying AI by risk level.
Framework at a glance
Short name
EU AI Act
Version
—
Category
EU Regulations
Controls
36
What EU AI Act covers
36 controls across 26 domains — every one tracked, owned and evidenced in Cyber Horizon.
AI Risk
3 controls- A9.1 Risk management system
- A9.2 Risk management throughout lifecycle
- A9.3 Residual risk assessment
Testing
1 controls- A9.4 Risk testing
Training Data
1 controls- A10.1 Training data governance
Data Quality
1 controls- A10.2 Data quality criteria
Bias
1 controls- A10.3 Bias examination
Privacy
1 controls- A10.4 Personal data in training
Technical Docs
1 controls- A11.1 Technical documentation
Maintenance
1 controls- A11.2 Technical documentation updates
Logging
2 controls- A12.1 Logging capabilities
- A12.2 Log retention
Information
2 controls- A13.1 Transparency and information provision
- A13.3 Capabilities and limitations disclosure
Documentation
2 controls- A13.2 Instructions for use
- A17.2 QMS documentation
Controls
2 controls- A14.1 Human oversight measures
- A14.3 Ability to override AI
Explainability
1 controls- A14.2 Ability to understand AI outputs
Safety
1 controls- A14.4 Override and stop capability
Performance
1 controls- A15.1 Accuracy specifications
Resilience
1 controls- A15.2 Robustness
Security
1 controls- A15.3 Cybersecurity
Market Placement
1 controls- A16.1 CE marking
Management
1 controls- A17.1 Quality management system
Assessment
1 controls- A18.1 Conformity assessment
Compliance
4 controls- A19.1 Registration in EU database
- A20.1 Serious incident reporting
- A27.1 Distributor obligations
- A53.1 GPAI model obligations
Regulatory
1 controls- A21.1 Cooperation with authorities
Transparency
2 controls- A22.1 AI system identification
- A50.1 GPAI model transparency
Operations
1 controls- A25.1 Deployer obligations
Third-Party
1 controls- A26.1 Importer obligations
Rights
1 controls- A29.1 Fundamental rights assessment
How Cyber Horizon automates EU AI Act
Every EU AI Act control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.
Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.
Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.
Frequently asked questions
What is EU AI Act?
First comprehensive EU legal framework for AI systems, classifying AI by risk level.
How many controls does EU AI Act have?
EU AI Act has 36 controls in Cyber Horizon's catalogue, organised across 26 domains.
How does Cyber Horizon help with EU AI Act?
Cyber Horizon maps EU AI Act into a shared control library alongside every other framework you run, so evidence collected once counts towards EU AI Act and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.
See EU AI Act mapped to your environment
Start with the free 20-question readiness check — no signup — or get a personal walkthrough of EU AI Act in Cyber Horizon.