EU AI Act Compliance Checker AI Act Service Desk

EU AI Act compliance

Knowing exactly which role your organization plays — and where the handoffs sit — is the first step in scoping the workload. Covers AI in critical infrastructure, education, employment, law enforcement, and medical devices — strict pre- and post-market rules apply. Axis Intelligence Research does not accept retainers, consulting fees, or compensation from any organization whose compliance status is tracked in this report. EU AI Act compliance tracker 2026 — every milestone, live status. The penalty structure does not change under the Digital Omnibus.

EU AI Act compliance

A provider is an organization (or natural person) that develops an AI system and places it on the market or puts it into service. The AI system inventory is the foundation of every other EU AI Act compliance activity. You cannot classify what you have not identified, you cannot assess risk for systems you do not know exist, and you cannot build https://ordercialisjlp.com/?p=16546 governance for a scope you have not defined. However, ISO certification alone does not satisfy EU AI Act conformity assessment requirements. Organizations should integrate their AI incident response procedures across all three frameworks. For a company with €10 billion in global revenue, a Tier 1 violation carries a maximum penalty of €700 million.

The EU AI Act applies a risk-based approach — meaning your compliance obligations depend entirely on how your AI system is classified. Organizations should treat December 2, 2027, as a hard compliance deadline for Annex III systems. Understanding which obligations are active now versus which have been deferred is the most important EU AI Act compliance question of the moment. The EU AI Act’s implementation timeline shifted significantly in August 2026 — and most EU AI Act compliance guides published before July 2026 are now outdated.

  • Give reviewers scoped operational records they can inspect.
  • Penalties are calculated as the greater of a fixed maximum or a percentage of global annual turnover — meaning for large multinational organizations, the percentage-based calculation typically produces the larger number.
  • Organizations must complete their risk classification analysis now, using the current Article 6 framework and Annex III categories, regardless of the compliance deadline.
  • For most organizations, EU AI Act compliance will intersect with existing GDPR obligations, sector-specific regulations, and international frameworks like ISO/IEC and the NIST AI RMF.

⚠️ 2. EU AI Act Risk Classification: The Four Levels Explained

  • Registers statistical data on users’ behaviour on the website.
  • Announcements that materially change the compliance timeline or obligations for organizations operating in or serving the EU.
  • If you build and sell an HR screening tool, you are the provider.
  • Must verify that the foreign provider has completed the necessary conformity assessment procedures before the system enters the single market.
  • AI systems embedded in products subject to existing sectoral legislation.
  • Milestone means a change to the Act’s application schedule, a new binding or quasi-binding guideline, or a code of practice publication that creates a compliance safe harbor.

A US company that sells software with AI features to EU customers or deploys AI affecting persons in the EU must classify its systems and comply with the applicable obligations. Any provider or deployer whose AI output is used in the EU is in scope regardless of where the organization is headquartered. As of August 24, 2026 — 22 days into the enforcement era — no fine, formal investigation opened by Commission decision, or market withdrawal order under the EU AI Act has been publicly confirmed by the European AI Office, the European Data Protection Supervisor, or any national competent authority.

Those records do not, by themselves, prove effectiveness, complete coverage, safety, or EU AI Act compliance. Because the register can change, procurement records should capture a provider’s status at the time of review rather than rely on a frozen count. Its penalty tiers https://medicalcases.eu/amia-calls-for-tighter-coordination-of-data-privacy-rules/ vary by breach; the €35 million or 7% of global annual turnover maximum applies to prohibited practices.

For high-risk systems, assess current state against Articles 9-15 requirements. Identify provisions already applicable and systems with 2027 or 2028 high-risk dates. Classify each system using the Act’s categories and applicable Annex I or Annex III pathway.

EU AI Act compliance

  • A deployer is an organization that uses an AI system in a professional context for its intended purpose.
  • Minimal risk systems like games and spam filters can be freely used.
  • For organizations that are deployers rather than providers — meaning you use GPAI models like GPT-5, Claude Opus 4.7, or Gemini 3.1 Pro via API to build products or automate workflows — your obligations are different.
  • As the EU AI Act enters full effect and enforcement deadlines approach—with prohibited AI already banned since February 2025 and high-risk requirements due August 2026—AI governance has evolved from a voluntary best practice to a core compliance obligation.
  • As the 2027 and 2028 deadlines approach, focus shifts from designing the framework to stress-testing it.

For foundational governance frameworks, see our guide on building an AI governance framework. It is written for compliance officers, legal teams, CISOs, AI governance leads, and business leaders — not as a beginner introduction, but as a working reference for organizations assessing and managing their EU AI Act exposure in 2026. GLACIS can record which configured controls were evaluated and what they reported, then map those bounded records to review questions. Conduct periodic reviews that assess ongoing compliance with the applicable Articles 9-15 duties and prepare for competent-authority requests. Give reviewers scoped operational records they can inspect. The AI Act establishes one of the most stringent penalty regimes in technology regulation, mirroring GDPR’s structure with fines tied to global annual turnover.

The AI Act employs a risk-based approach, classifying AI systems into four tiers with escalating regulatory requirements based on potential harm to health, safety, and fundamental rights. Adopted by the European Parliament on March 13, 2024, and entering into force August 1, 2024, it establishes harmonized rules for AI development, deployment, and use across all 27 EU member states. Home PlatformRules, control decisions, and records anyone can verify Resources PricingStart free, pay when a workflow https://scivast.com/articles/understanding-data-lineage-governance/ goes into production Company AI systems embedded in products subject to existing sectoral legislation. This guide covers who must comply, what DORA requires, and how to build a compliant training programme. The GDPR governs the processing of personal data (lawful basis, data subject rights, accountability), while the EU AI Act governs AI systems themselves (risk classification, safety, transparency, human oversight).

EU AI Act compliance

What are the penalties of the EU AI Act?

He holds CISSP and CISM certifications and advises organizations on NIS2, the EU AI Act, and cybersecurity awareness programs. The European Commission estimated in an impact study that only 5-15% of applications would be subject to stricter rules. Technical documentation and risk-management frameworks are living artifacts.

评论

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注