Summary
The EU AI Act (Regulation (EU) 2024/1689) is the European Union's regulation governing the development, deployment, and use of artificial intelligence. It classifies AI systems by risk level and assigns obligations based on role, provider or deployer, rather than certifying products as a whole. High-risk obligations take full effect on August 2, 2026.
Red Hat's role under the Act varies by product. For AI platforms that customers use to build and run their own AI systems, Red Hat is an infrastructure provider: the platform is not itself classified as an AI system, and high-risk obligations apply to what the customer builds on it, not to the platform itself. For select product features that generate AI output directly, Red Hat is a limited-risk AI provider with transparency obligations. For a small set of advisory machine-learning features, no mandatory obligations apply.
The EU AI Act does not establish a certification scheme. There is no "EU AI Act certified" designation to obtain, and Red Hat does not represent any product as certified under the Act. This page describes how Red Hat's AI portfolio maps to the Act's roles and risk categories so customers can understand their own compliance position.
Disclaimer
This document is provided for informational purposes only. It is intended to describe Red Hat's AI portfolio's relationship to the EU AI Act as of the publication date and is subject to change at Red Hat's sole discretion. The information is provided "as is" with no guarantee or warranty of accuracy, completeness, or fitness for a particular purpose. Red Hat is not responsible for any errors or omissions in this document. If further detail or clarification is required, contact your Red Hat representative, who will forward the request to the Red Hat Product Security Governance, Risk, and Compliance team for further consideration.
Last updated: July 2026
Red Hat AI Portfolio and the EU AI Act
Red Hat's AI portfolio falls into three groups under the Act. Each group carries a different role and obligation set.
AI Platforms
Red Hat OpenShift AI, Red Hat AI Inference Server, and Red Hat OpenShift provide the infrastructure customers use to develop, train, and serve their own AI systems. Under the Act, the customer's AI application, not the underlying platform, is what may be classified as high-risk. These platforms provide logging, monitoring, role-based access control, and model management capabilities that customers can use as part of demonstrating their own compliance with Articles 9 through 15 of the Act, covering risk management, data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy, robustness, and cybersecurity.
AI-Assisted Product Features
Ansible Lightspeed, OpenShift Lightspeed, RHEL Lightspeed, Developer Lightspeed for Migration Toolkit, and Ask Red Hat generate AI-assisted content or recommendations within their respective products. For these features, Red Hat is a limited-risk AI provider under the Act. Article 50 requires that users be informed when they are interacting with AI-generated output. Red Hat's Lightspeed features are designed to disclose their AI-generated output to users.
Advisory Machine-Learning Features
Red Hat Lightspeed (formerly Insights) and Red Hat Advanced Cluster Security use machine learning to generate recommendations, including configuration guidance, vulnerability prioritization, and threat detection. These are advisory, human-in-the-loop features and fall into the Act's minimal-risk category, which carries no mandatory obligations.
Related Frameworks
- EU AI Act (Regulation (EU) 2024/1689)
- ISO/IEC 42001:2023 AI Management Systems, addressed on the ISO 42001 compliance page
Red Hat's Own Use of AI
Red Hat's use of AI in its own internal operations is governed by Red Hat's AI governance policies in accordance with the EU AI Act.