EUAIAct
High-Risk Obligations Land August 2026. Classify Your AI Before They Do.
The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive AI law. Prohibited practices are already banned, GPAI obligations are live, and the full high-risk regime lands 2 August 2026 — with penalties up to EUR 35 million or 7% of global turnover. Register your AI, classify every system against the Act’s risk tiers, run fundamental-rights impact assessments, and test for bias — on one platform.
Who needs it: Any organization that develops, deploys, imports, or distributes AI in the EU — plus non-EU providers whose AI output is used in the Union. SaaS vendors shipping AI features, HR-tech, fintech scoring, and healthcare AI face the earliest scrutiny.
What is EU AI Act?
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is the world's first comprehensive, horizontal law for artificial intelligence. It takes a risk-based approach: some practices are prohibited outright, high-risk systems face a full compliance regime, limited-risk systems carry transparency duties, and minimal-risk systems are largely unregulated. Separate obligations apply to general-purpose AI (GPAI) models.
The four tiers are Unacceptable risk (banned under Article 5 — social scoring, untargeted facial-image scraping, emotion recognition in the workplace or schools, and certain biometric categorisation), High risk (Annex III use cases plus Annex I embedded products, subject to Articles 9–15, 17, 27 and 49), Limited risk (Article 50 transparency: disclose AI interaction, label deepfakes and synthetic media, notify of emotion recognition), and Minimal risk (no obligations).
Enforcement is phased. The Act entered into force on 1 August 2024. The prohibited-practice ban applied from 2 February 2025 and GPAI obligations from 2 August 2025. The core high-risk regime for Annex III systems applies from 2 August 2026, with high-risk obligations for Annex I embedded products following on 2 August 2027. Penalties reach EUR 35 million or 7% of global annual turnover for prohibited-practice breaches, EUR 15 million or 3% for other obligations, and EUR 7.5 million or 1% for supplying incorrect information — with the higher of the two amounts applying.
Enforcement timeline
Where the regulation stands today — and the deadlines your program has to beat.
Act enters into force
Regulation (EU) 2024/1689 becomes law, starting the phased application clock.
Prohibited practices banned
Article 5 unacceptable-risk practices — social scoring, untargeted facial scraping, workplace emotion recognition — are prohibited across the Union.
GPAI obligations apply
General-purpose AI model obligations take effect: technical documentation, copyright policy, and training-content summaries.
High-risk regime applies (Annex III)
The full obligation set for Annex III high-risk systems lands — risk management, data governance, documentation, human oversight, FRIA, and EU-database registration. Be classified and operational before this date.
Annex I embedded-product obligations
High-risk obligations extend to AI embedded in products already covered by EU product-safety legislation (Annex I).
What you'll need to satisfy.
The core categories EU AI Act auditors evaluate — and what we ship to cover each one.
Prohibited Practices (Article 5)
- Social scoring by public or private actors
- Untargeted scraping of facial images to build recognition databases
- Emotion recognition in the workplace and education settings
- Biometric categorisation inferring sensitive attributes (race, political views, religion)
- Certain real-time remote biometric identification in public spaces
High-Risk Systems (Annex III + Articles 8–27)
- Risk management system (Art. 9) and data governance (Art. 10)
- Technical documentation (Art. 11) and record-keeping / logging (Art. 12)
- Transparency and instructions for use (Art. 13)
- Human oversight (Art. 14) and accuracy, robustness, cybersecurity (Art. 15)
- Quality management system (Art. 17)
- Fundamental Rights Impact Assessment (Art. 27)
- Registration in the EU database before deployment (Art. 49)
Transparency Obligations (Article 50)
- Disclose to people when they are interacting with an AI system
- Label AI-generated or manipulated content (deepfakes and synthetic media)
- Notify people subject to emotion recognition or biometric categorisation
- Mark machine-readable synthetic output
General-Purpose AI (Chapter V)
- Technical documentation and information for downstream providers
- Policy to respect EU copyright law
- Sufficiently detailed summary of training content
- Systemic-risk models: model evaluation, adversarial testing, incident tracking, cybersecurity
Post-Market & Incidents
- Post-market monitoring system (Art. 72)
- Serious-incident reporting to authorities within 15 days (Art. 73)
- Corrective actions and cooperation with regulators
- Records maintained for auditors and market-surveillance authorities
The problem we solve.
Why teams pick Compliance Enablers for EU AI Act compliance.
Common challenges
- The full high-risk obligation set applies 2 August 2026, and prohibited practices have been banned since February 2025 — the runway is nearly gone
- Penalties reach EUR 35 million or 7% of global annual turnover for deploying a prohibited practice — higher than GDPR
- Nobody can say which AI systems are actually in production, what tier each falls in, or whether any touch an Annex III high-risk use case
- Most GRC tools bolted AI on as a policy-template pack: no classifier, no FRIA workflow, no bias testing, no incident clock
What we provide
- AI Governance module operational today: an AI system registry with four-tier EU AI Act classification and lifecycle governance
- One-click classifier that scores each system against Article 5 prohibited practices, the eight Annex III high-risk categories, and Article 50 transparency triggers — returning the tier and the article-by-article obligation set
- Fundamental Rights Impact Assessment (FRIA, Article 27) as a build-validate-gaps workflow with completion tracking
- Bias and fairness testing — disparate impact (the four-fifths rule), demographic parity, and equal-opportunity metrics with a fair-or-biased verdict
- AI incident classification with Article 73 reporting windows — the 15-day serious-incident clock and notify-party guidance built in
- Model-card validation against Article 11 technical-documentation expectations: a completeness score with missing and empty sections named
- Promote any AI risk, FRIA finding, or model-drift event straight into the risk register or an incident, with a live back-link
- ISO/IEC 42001 AIMS controls on the same module — the management system your AI Act evidence hangs on, cross-linked to your ISO 27001 ISMS via the SCF crosswalk
From kickoff to
audit-ready.
Step-by-step, exactly how we'll get you there.
AI Inventory
Register every AI system, model, vendor, and use case in the AI Governance registry — the single source of truth your auditors and enterprise customers now ask for.
Risk Classification
Run the one-click classifier per system against Article 5 prohibited practices, the eight Annex III high-risk categories, and Article 50 transparency triggers. It returns the tier and the article-by-article obligation set.
High-Risk Obligations
For systems that land high-risk, work Articles 9–15, 17, 27 and 49 as a tracked checklist — risk management, data governance, documentation, human oversight, and EU-database registration.
FRIA & Impact
Build, validate, and gap-check the Fundamental Rights Impact Assessment (Article 27) as a workflow with completion tracking — not a one-off memo.
Testing & Transparency
Compute bias and fairness metrics (disparate impact, demographic parity, equal opportunity), validate model cards against Article 11, and record transparency labeling for limited-risk systems.
Incidents & Monitoring
Classify AI incidents with the Article 73 15-day serious-incident clock, run post-market monitoring, and promote material risks straight into the risk register.
framework
ISO/IEC 42001 is the management system that operationalizes AI Act evidence — the same AI Governance module runs both, and your existing ISO 27001 ISMS clauses carry across via the SCF crosswalk. See our ISO 42001 framework guide.
Most platforms answer the EU AI Act with a policy-template pack and a slide about risk tiers. Compliance Enablers ships a working engine: a classifier that reads Article 5, Annex III, and Article 50; a FRIA workflow; quantitative bias metrics; Article 11 model-card validation; and an Article 73 incident clock — all feeding the same risk register your ISO 27001 program already uses. And we govern our own AI in the same module: Sage runs on Anthropic Claude with a disclosed provider, logged actions, and human approval.
Key modules for EU AI Act.
Everything these modules ship, included in every tier.
EU AI Act FAQ
Get EU AI Act
audit-ready.
AI inventory and per-system risk classification in days. 425+ pre-generated documents. 50+ evidence collectors. Everything you need to pass EU AI Act, out of the box.