Skip to content
AI Act compliance and AI literacy training for your teams

AI Act compliance and AI literacy training for your teams

The EU Artificial Intelligence Act (Regulation 2024/1689) has applied in full since 2 August 2026. Two obligations already affect every company using AI: training your people and telling users when they interact with an AI. Castelis maps your AI systems, establishes what you actually owe under the regulation, and trains the teams who build and use those systems.

# They chose our expertise

/ Our Clients

Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
Logo
/

Your obligations depend on your AI systems' risk level

The AI Act regulates use, not technology. Four risk levels, and the heavy obligations only apply to a minority of systems. AI Act compliance therefore starts with knowing exactly where yours sit.

Unacceptable risk: banned uses

Unacceptable risk: banned uses

Social scoring, manipulation, untargeted scraping of facial images, emotion recognition in the workplace. These Article 5 practices have been prohibited since 2 February 2025.

High risk: the strictest requirements

High risk: the strictest requirements

Eight areas under Annex III, including recruitment, education, credit scoring and critical infrastructure. Risk management, documentation, logging and human oversight are all required.

Limited risk: transparency duties

Limited risk: transparency duties

The most common case in business. Article 50 requires you to tell people they are interacting with an AI and to mark generated content in a machine-readable format.

Minimal risk and general-purpose models

Minimal risk and general-purpose models

Most internal uses carry no specific obligation. Providers of general-purpose AI models have their own regime, applicable since 2 August 2025.

/
Where does the AI Act timeline stand in 2026?

The regulation entered into force on 1 August 2024 and applies in stages: prohibitions and AI literacy since 2 February 2025, general-purpose models and penalties since 2 August 2025, general application and Article 50 transparency since 2 August 2026.

Regulation (EU) 2026/1744, known as the digital omnibus, pushed back the substantive requirements for high-risk systems: 2 December 2027 for Annex III, 2 August 2028 for Annex I. Nothing already applicable is suspended. That extra time is for mapping and documenting, not for waiting.

Where does the AI Act timeline stand in 2026?
/

How we support your AI Act compliance

We treat AI Act compliance as an engineering topic as much as a governance one. In practice that means looking at what your systems actually do, with which data and under what human oversight, then fixing what needs fixing inside the applications themselves.

AI system inventory

AI system inventory

A full record of every system in production or in the pipeline, including AI features embedded in your off-the-shelf software and tools adopted without IT sign-off.

Role and risk classification

Role and risk classification

Whether you act as provider or deployer for each system, how it classifies against the annexes, and which obligations genuinely follow from that.

Gap analysis and roadmap

Gap analysis and roadmap

Your current practices measured against the applicable requirements, then a prioritised action plan aligned with the real deadline for each category of system.

Article 50 implementation

Article 50 implementation

Transparency measures built into your applications: disclosure on your chatbots, marking of generated content, notices shown at first interaction.

Technical documentation and traceability

Technical documentation and traceability

The documentation required for high-risk systems: system description, training data governance, logging, testing and human oversight measures.

AI governance

AI governance

Your AI usage policy, the approval path for new use cases, and clear roles and responsibilities, aligned with your GDPR obligations and your cybersecurity governance.

Security of AI systems

Security of AI systems

The risks specific to AI in production: data leakage through prompts, prompt injection, access control to models and separation of environments.

Compliance by design

Compliance by design

Requirements built into your new AI projects from the design stage, so you never have to retrofit a system already deployed and adopted by the business.

Regulatory watch

Regulatory watch

Tracking changes to the regulation, Commission guidelines and codes of practice, with your roadmap updated whenever the framework moves.

/ Our AI Act compliance method

Five steps that start from how you actually use AI rather than from the legal text, so the effort goes where the regulation genuinely demands it.

1

Inventory

Every AI system used or built across the organisation, including those embedded in your existing tools.

Mapping Use cases
2

Classification

The risk level of each system and your role as provider or deployer.

Risk level Role
3

Gap analysis

Your practices measured against the applicable requirements, with actions prioritised by real deadline.

Gaps Priorities
4

Implementation

Fixes inside the applications, documentation assembled, human oversight and logging put in place.

Engineering Documentation
5

Training and steering

Teams brought up to speed, governance embedded, and regulatory changes tracked over time.

Training Governance

/
AI Act training is a legal duty, not an option

Article 4 requires providers and deployers alike to ensure a sufficient level of AI literacy among the people operating these systems on their behalf. It has applied since 2 February 2025, with no size threshold, and it covers your own staff as well as contractors.

We build a path per audience rather than one generic module: obligations for executives and legal teams, classification and documentation for product and data teams, safe use of generative AI for business users. Every session is built on your own use cases, which makes the training record defensible if you are ever challenged.

AI Act training is a legal duty, not an option

/
Frequently asked questions about AI Act compliance

The AI Act is Regulation (EU) 2024/1689 on artificial intelligence, the first comprehensive legal framework dedicated to AI. It does not regulate the technology itself but the way it is used, sorting systems into four risk levels: unacceptable, high, limited and minimal. The greater the risk to health, safety or fundamental rights, the heavier the obligations. Being a regulation, it applies directly in every member state with no national transposition.

The regulation mainly distinguishes two roles. A provider develops an AI system or places it on the market under its own name. A deployer uses an AI system under its own authority in a professional context. Most companies are deployers, but an organisation that heavily customises a system or sells it under its own brand can shift into provider status, with significantly heavier obligations. The regulation also reaches organisations established outside the EU whenever the output of their system is used within the EU.

Article 99 sets three tiers of administrative fines. Up to 35 million euros or 7 % of total worldwide annual turnover for using a practice prohibited by Article 5. Up to 15 million euros or 3 % for breaching other obligations, notably those on high-risk systems. Up to 7.5 million euros or 1 % for supplying incorrect or misleading information to authorities. For SMEs and start-ups, the lower of the two figures applies.

There is no official label certifying a company as generally AI Act compliant. The regulation provides for a conformity assessment on high-risk systems, followed by an EU declaration of conformity under Article 47 and CE marking. For every other category, compliance is demonstrated through documentation, governance and the measures actually in place, not through a certificate. Be wary of commercial offers presenting an AI Act certification as a mandatory prerequisite.

Article 50 covers transparency and affects many companies that fall outside the high-risk category. People must be told they are interacting with an AI system unless that is obvious. Synthetic audio, image, video or text content must be marked as artificially generated or manipulated, in a machine-readable format. People exposed to emotion recognition or biometric categorisation systems must be informed. The information has to be clear and given at the latest at the first interaction.

It moves a deadline, it cancels no obligation. Regulation (EU) 2026/1744 postpones the substantive requirements for stand-alone high-risk systems to 2 December 2027, and to 2 August 2028 for those embedded in already regulated products. Prohibited practices, the AI literacy duty, the rules on general-purpose models and the transparency obligations all remain applicable. The real benefit of the delay is the time it buys to map and document, provided you use it.

CONTACT

Let's review your AI Act compliance