EU AI Act compliance is the set of obligations an organisation must meet when it develops, deploys or uses an artificial intelligence system in the European Union, under Regulation (EU) 2024/1689. The regulation classifies systems by risk level, and the duties attached to a system depend on which tier it falls into, not on how advanced the underlying model is.
The Act defines four tiers. Unacceptable risk practices, such as social scoring, are banned outright. High-risk systems, listed in Annex III, carry the heaviest requirements: risk management, data governance, technical documentation, event logging, human oversight and conformity assessment. Limited risk systems owe transparency duties. Minimal risk systems, the large majority, carry no specific obligation.
Most finance automation sits outside the high-risk tier. An agent that extracts invoice data, checks a line price against a contract or reconciles a bank statement is not deciding a person's access to credit, employment or essential services. Creditworthiness assessment of individuals is high-risk under Annex III; supplier invoice control is not. What does apply to a finance team is AI literacy for the people operating the systems, transparency about what is automated, and ordinary AI governance discipline.
Phacet is built for that discipline by default. Data is hosted in Europe on AWS Bedrock, the platform is ISO 27001 certified and GDPR compliant, and client data is never used to train models. Every agent output carries a native audit trail, and every match exposes its reasoning instead of returning a verdict from a black box. Validation thresholds keep a person in the loop on anything material, which is human-in-the-loop control by design rather than by policy.
Compliance is far easier to demonstrate when traceability is built into the process than when it has to be reconstructed after the fact.