Skip to content
Cyber Horizon
All frameworks

// EU Regulations

EU AI Act Compliance Software

First comprehensive EU legal framework for AI systems, classifying AI by risk level.

Framework at a glance

Short name

EU AI Act

Version

Category

EU Regulations

Controls

36

What EU AI Act covers

36 controls across 26 domains — every one tracked, owned and evidenced in Cyber Horizon.

AI Risk

3 controls
  • A9.1 Risk management system
  • A9.2 Risk management throughout lifecycle
  • A9.3 Residual risk assessment

Testing

1 controls
  • A9.4 Risk testing

Training Data

1 controls
  • A10.1 Training data governance

Data Quality

1 controls
  • A10.2 Data quality criteria

Bias

1 controls
  • A10.3 Bias examination

Privacy

1 controls
  • A10.4 Personal data in training

Technical Docs

1 controls
  • A11.1 Technical documentation

Maintenance

1 controls
  • A11.2 Technical documentation updates

Logging

2 controls
  • A12.1 Logging capabilities
  • A12.2 Log retention

Information

2 controls
  • A13.1 Transparency and information provision
  • A13.3 Capabilities and limitations disclosure

Documentation

2 controls
  • A13.2 Instructions for use
  • A17.2 QMS documentation

Controls

2 controls
  • A14.1 Human oversight measures
  • A14.3 Ability to override AI

Explainability

1 controls
  • A14.2 Ability to understand AI outputs

Safety

1 controls
  • A14.4 Override and stop capability

Performance

1 controls
  • A15.1 Accuracy specifications

Resilience

1 controls
  • A15.2 Robustness

Security

1 controls
  • A15.3 Cybersecurity

Market Placement

1 controls
  • A16.1 CE marking

Management

1 controls
  • A17.1 Quality management system

Assessment

1 controls
  • A18.1 Conformity assessment

Compliance

4 controls
  • A19.1 Registration in EU database
  • A20.1 Serious incident reporting
  • A27.1 Distributor obligations
  • A53.1 GPAI model obligations

Regulatory

1 controls
  • A21.1 Cooperation with authorities

Transparency

2 controls
  • A22.1 AI system identification
  • A50.1 GPAI model transparency

Operations

1 controls
  • A25.1 Deployer obligations

Third-Party

1 controls
  • A26.1 Importer obligations

Rights

1 controls
  • A29.1 Fundamental rights assessment

How Cyber Horizon automates EU AI Act

Every EU AI Act control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is EU AI Act?

First comprehensive EU legal framework for AI systems, classifying AI by risk level.

How many controls does EU AI Act have?

EU AI Act has 36 controls in Cyber Horizon's catalogue, organised across 26 domains.

How does Cyber Horizon help with EU AI Act?

Cyber Horizon maps EU AI Act into a shared control library alongside every other framework you run, so evidence collected once counts towards EU AI Act and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See EU AI Act mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of EU AI Act in Cyber Horizon.