/ Our Clients
Your obligations depend on your AI systems' risk level
The AI Act regulates use, not technology. Four risk levels, and the heavy obligations only apply to a minority of systems. AI Act compliance therefore starts with knowing exactly where yours sit.
Unacceptable risk: banned uses
Social scoring, manipulation, untargeted scraping of facial images, emotion recognition in the workplace. These Article 5 practices have been prohibited since 2 February 2025.
High risk: the strictest requirements
Eight areas under Annex III, including recruitment, education, credit scoring and critical infrastructure. Risk management, documentation, logging and human oversight are all required.
Limited risk: transparency duties
The most common case in business. Article 50 requires you to tell people they are interacting with an AI and to mark generated content in a machine-readable format.
Minimal risk and general-purpose models
Most internal uses carry no specific obligation. Providers of general-purpose AI models have their own regime, applicable since 2 August 2025.
/
Where does the AI Act timeline stand in 2026?
The regulation entered into force on 1 August 2024 and applies in stages: prohibitions and AI literacy since 2 February 2025, general-purpose models and penalties since 2 August 2025, general application and Article 50 transparency since 2 August 2026.
Regulation (EU) 2026/1744, known as the digital omnibus, pushed back the substantive requirements for high-risk systems: 2 December 2027 for Annex III, 2 August 2028 for Annex I. Nothing already applicable is suspended. That extra time is for mapping and documenting, not for waiting.
How we support your AI Act compliance
We treat AI Act compliance as an engineering topic as much as a governance one. In practice that means looking at what your systems actually do, with which data and under what human oversight, then fixing what needs fixing inside the applications themselves.
AI system inventory
A full record of every system in production or in the pipeline, including AI features embedded in your off-the-shelf software and tools adopted without IT sign-off.
Role and risk classification
Whether you act as provider or deployer for each system, how it classifies against the annexes, and which obligations genuinely follow from that.
Gap analysis and roadmap
Your current practices measured against the applicable requirements, then a prioritised action plan aligned with the real deadline for each category of system.
Article 50 implementation
Transparency measures built into your applications: disclosure on your chatbots, marking of generated content, notices shown at first interaction.
Technical documentation and traceability
The documentation required for high-risk systems: system description, training data governance, logging, testing and human oversight measures.
AI governance
Your AI usage policy, the approval path for new use cases, and clear roles and responsibilities, aligned with your GDPR obligations and your cybersecurity governance.
Security of AI systems
The risks specific to AI in production: data leakage through prompts, prompt injection, access control to models and separation of environments.
Compliance by design
Requirements built into your new AI projects from the design stage, so you never have to retrofit a system already deployed and adopted by the business.
Regulatory watch
Tracking changes to the regulation, Commission guidelines and codes of practice, with your roadmap updated whenever the framework moves.
/ Our AI Act compliance method
Five steps that start from how you actually use AI rather than from the legal text, so the effort goes where the regulation genuinely demands it.
Inventory
Every AI system used or built across the organisation, including those embedded in your existing tools.
Classification
The risk level of each system and your role as provider or deployer.
Gap analysis
Your practices measured against the applicable requirements, with actions prioritised by real deadline.
Implementation
Fixes inside the applications, documentation assembled, human oversight and logging put in place.
Training and steering
Teams brought up to speed, governance embedded, and regulatory changes tracked over time.
/
AI Act training is a legal duty, not an option
Article 4 requires providers and deployers alike to ensure a sufficient level of AI literacy among the people operating these systems on their behalf. It has applied since 2 February 2025, with no size threshold, and it covers your own staff as well as contractors.
We build a path per audience rather than one generic module: obligations for executives and legal teams, classification and documentation for product and data teams, safe use of generative AI for business users. Every session is built on your own use cases, which makes the training record defensible if you are ever challenged.
/
Frequently asked questions about AI Act compliance
The AI Act is Regulation (EU) 2024/1689 on artificial intelligence, the first comprehensive legal framework dedicated to AI. It does not regulate the technology itself but the way it is used, sorting systems into four risk levels: unacceptable, high, limited and minimal. The greater the risk to health, safety or fundamental rights, the heavier the obligations. Being a regulation, it applies directly in every member state with no national transposition.
The regulation mainly distinguishes two roles. A provider develops an AI system or places it on the market under its own name. A deployer uses an AI system under its own authority in a professional context. Most companies are deployers, but an organisation that heavily customises a system or sells it under its own brand can shift into provider status, with significantly heavier obligations. The regulation also reaches organisations established outside the EU whenever the output of their system is used within the EU.
Article 99 sets three tiers of administrative fines. Up to 35 million euros or 7 % of total worldwide annual turnover for using a practice prohibited by Article 5. Up to 15 million euros or 3 % for breaching other obligations, notably those on high-risk systems. Up to 7.5 million euros or 1 % for supplying incorrect or misleading information to authorities. For SMEs and start-ups, the lower of the two figures applies.
There is no official label certifying a company as generally AI Act compliant. The regulation provides for a conformity assessment on high-risk systems, followed by an EU declaration of conformity under Article 47 and CE marking. For every other category, compliance is demonstrated through documentation, governance and the measures actually in place, not through a certificate. Be wary of commercial offers presenting an AI Act certification as a mandatory prerequisite.
Article 50 covers transparency and affects many companies that fall outside the high-risk category. People must be told they are interacting with an AI system unless that is obvious. Synthetic audio, image, video or text content must be marked as artificially generated or manipulated, in a machine-readable format. People exposed to emotion recognition or biometric categorisation systems must be informed. The information has to be clear and given at the latest at the first interaction.
It moves a deadline, it cancels no obligation. Regulation (EU) 2026/1744 postpones the substantive requirements for stand-alone high-risk systems to 2 December 2027, and to 2 August 2028 for those embedded in already regulated products. Prohibited practices, the AI literacy duty, the rules on general-purpose models and the transparency obligations all remain applicable. The real benefit of the delay is the time it buys to map and document, provided you use it.
Let's review your AI Act compliance