EN 1090
European standards for steel/aluminium structural execution and conformity
EU AI Act
EU regulation for risk-based AI governance and safety
Quick Verdict
EN 1090 mandates CE marking for structural steel/aluminium via FPC for EU construction market access, while EU AI Act regulates high-risk AI with conformity assessments and fines up to 7% turnover. Companies adopt EN 1090 for fabrication compliance, AI Act for safe AI deployment.
EN 1090
EN 1090 Execution of steel and aluminium structures
Key Features
- Mandates CE marking through certified Factory Production Control
- Risk-based Execution Classes EXC1-EXC4 scaling requirements
- Integrates ISO 3834 welding quality management system
- Enforces full material traceability and NDT inspections
- Enables EU market access for structural components
EU AI Act
Regulation (EU) 2024/1689 Artificial Intelligence Act
Key Features
- Risk-based classification of AI systems
- Prohibits unacceptable-risk AI practices
- High-risk conformity assessments and CE marking
- GPAI model transparency and systemic risk duties
- Post-market monitoring and incident reporting
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
EN 1090 Details
What It Is
EN 1090 is a harmonized European standard family (EN 1090-1, -2, -3) under the Construction Products Regulation (CPR). It governs execution and conformity assessment of steel and aluminium structural components/kits for construction works. Primary purpose: ensure controlled fabrication, welding, tolerances, and inspection for CE marking. Key approach: risk-based scaling via Execution Classes (EXC1-EXC4) linking consequence, service, and production categories.
Key Components
- **EN 1090-1FPC certification, AVCP systems, DoP issuance.
- **EN 1090-2/-3Technical rules for steel/aluminium (materials, welding per ISO 3834, tolerances, corrosion protection, NDT).
- Core principles: traceability, qualified personnel, inspection regimes.
- Compliance model: Notified Body certification with ongoing surveillance.
Why Organizations Use It
Mandated for EU/EEA market access; reduces liability, rework, failures. Drives capability building, competitive bidding, stakeholder trust via CE marking.
Implementation Overview
Phased: gap analysis, FPC development, welding quals, NB audits. Targets fabricators; 6-12 months typical; requires certification for EXC-rated production.
EU AI Act Details
What It Is
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is a comprehensive regulation establishing the first horizontal framework for AI in the EU. It entered into force on 1 August 2024 with phased applicability. Its primary purpose is to ensure AI systems are safe, transparent, and respect fundamental rights across sectors. The risk-based approach classifies AI into unacceptable (prohibited), high-risk, limited-risk (transparency), and minimal-risk categories.
Key Components
- Prohibited practices (Article 5), high-risk requirements (Articles 9-15: risk management, data governance, documentation, human oversight, cybersecurity).
- GPAI model obligations (Chapter V), conformity assessments, CE marking, EU database registration.
- Built on product safety principles with up to 7% global turnover fines.
- Compliance via self-assessment or notified bodies.
Why Organizations Use It
- Mandatory for EU market access, avoiding fines up to €40M or 7% turnover.
- Enhances risk management, trust, and competitiveness.
- Builds stakeholder confidence in regulated sectors like healthcare, finance.
Implementation Overview
- Phased: inventory, classify AI, build RMS/QMS, conformity, post-market monitoring.
- Applies to providers/deployers globally if outputs used in EU; cross-functional for all sizes.
Key Differences
| Aspect | EN 1090 | EU AI Act |
|---|---|---|
| Scope | Execution of steel/aluminium structural components | Risk-based regulation of AI systems lifecycle |
| Industry | Construction, fabrication (EU/EEA market) | All sectors using AI (EU-wide, extraterritorial) |
| Nature | Harmonized standard under CPR (mandatory CE) | Directly applicable EU regulation (mandatory) |
| Testing | FPC certification, surveillance audits by NB | Conformity assessment, notified body for high-risk |
| Penalties | Market exclusion, no CE marking | Fines up to 7% global turnover |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about EN 1090 and EU AI Act
EN 1090 FAQ
EU AI Act FAQ
You Might also be Interested in These Articles...

CIS Controls v8.1, Operationalized: Top 10 Reasons Compliance Monitoring Software Accelerates Real-World Implementation
Operationalize CIS Controls v8.1 with compliance monitoring software. Turn checklists into dashboards, tickets, and audit-proof workflows. Top 10 reasons it acc

Why the SEC Stepped In: The Investor-Driven Push for Cybersecurity Transparency
Discover why the SEC's 2023 cybersecurity rules treat cyber risks as material financial threats. Explore the 'stick and carrot' approach for standardized disclo

Proving CIS Controls v8.1 Works: A KPI & Evidence Framework for Board Reporting, Audits, and Continuous Assurance
Prove CIS Controls v8.1 effectiveness with KPI catalog, evidence checklist & reporting cadence. Ideal for board reports, audits & cyber-insurance. Measure outco
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Check out these other Gradum.io Standards Comparison Pages
CSL (Cyber Security Law of China) vs IATF 16949
CSL vs IATF 16949: Compare China's Cybersecurity Law data rules with automotive QMS standards. Master compliance, risks & strategies for global firms—unlock expert guide now!
CMMC vs SAMA CSF
Compare CMMC vs SAMA CSF: DoD's 3-tier NIST-based cert for DIB vs Saudi finance's 6-level maturity model. Unlock strategies, pitfalls & compliance paths. Secure your future now!
COBIT vs APRA CPS 234
Compare COBIT vs APRA CPS 234: Align IT governance with Australia's info sec standard for resilient finance. Boost compliance, board oversight & cyber risk mgmt. Dive in now!