Regulation (EU) 2024/1689 — the EU Artificial Intelligence Act — introduces a horizontal, risk-based regime for AI systems placed on or used within the Union market. The compliance calendar runs in waves:
— Prohibitions on unacceptable-risk practices apply first.
— Obligations for general-purpose AI (GPAI) models follow.
— Full obligations for high-risk systems become applicable 24 months after entry into force, with a longer runway for certain regulated products.
For groups headquartered in Cyprus, the practical priorities are: (i) classification of each AI system across the four risk tiers, (ii) governance documentation aligned with the harmonised standards being prepared by CEN-CENELEC, and (iii) contractual flow-down to upstream model providers and downstream deployers.
Financial-services operators should also map AI Act obligations against DORA and MiCA, where overlapping incident reporting and operational resilience duties apply.
Corpora advises on AI governance frameworks, conformity assessment readiness, and cross-border allocation of provider/deployer responsibilities.




