EU AI Act Compliance Readiness
Establishing which of your AI systems the Act actually covers, meeting the transparency duties that already apply, and building toward the high-risk obligations on their revised timetable rather than on the one everyone memorised in 2024.
The single most common state we find is an organisation that prepared against the original timetable, heard the deadlines had moved, and stopped. Both halves of that are wrong: some duties are already in force today, and the deferred ones bought preparation time rather than removing the obligation.
The EU AI Act is the European Union's regulation on artificial intelligence. It classifies systems by risk — prohibited, high-risk, limited-risk with transparency duties, and minimal — and places obligations on providers and deployers according to that classification and their role, with extraterritorial reach where output is used in the Union.
Where the timetable actually stands
The Digital Omnibus package, given final Council approval on 29 June 2026, deferred the high-risk deadlines. Everything else held. As matters stand:
| Obligation | Applies from | Status |
|---|---|---|
| Prohibited practices (Article 5) | 2 February 2025 | In force |
| AI literacy duties (Article 4) | 2 February 2025 | In force |
| General-purpose AI model obligations | 2 August 2025 | In force |
| Transparency duties (Article 50) | 2 August 2026 | In force |
| Marking of AI-generated content | 2 December 2026 | Grace period running |
| High-risk, Annex III stand-alone systems | 2 December 2027 | Deferred from 2 August 2026 |
| High-risk, Annex I embedded in regulated products | 2 August 2028 | Deferred from 2 August 2027 |
Deferred is not withdrawn, and we are not your lawyers
The substantive obligations were not softened — only the dates moved. Organisations that stopped preparing in 2026 will face the same requirements with less runway. This page reflects the position as we understand it in September 2026; the Act and its implementing measures continue to develop, and nothing here is legal advice. We work alongside your counsel rather than in place of them.
Classification is where the work begins
Are you a provider or a deployer?
The obligations differ substantially, and organisations frequently assume they are only deployers. Putting your name on a system, or materially modifying a third-party one, can make you a provider with the far heavier duty set. This is settled per system, in writing, with your counsel.
Does the Act reach you at all?
It reaches providers and deployers established in the Union, and also those outside it where the system's output is used in the Union. A great deal of non-EU AI activity is in scope and its owners have not checked.
Which systems are actually high-risk?
Annex III lists the stand-alone categories — biometrics, critical infrastructure, education, employment, essential services and credit, law enforcement, migration, justice. Annex I covers AI as a safety component of products already regulated. Being adjacent to one of these is not the same as being in it, and both over-classification and under-classification are expensive.
What is prohibited outright
Certain practices are banned and have been since February 2025. These are checked first, because everything else is a compliance question and this one is a stop.
Transparency duties you owe today
Telling people when they are interacting with an AI system, disclosing emotion recognition and biometric categorisation, and marking synthetic content. These are in force now, and they apply to a much wider set of systems than the high-risk regime — including ordinary chatbots and generated marketing content.
What high-risk readiness requires
Where a system is high-risk, the obligations are extensive and take longer to build than the remaining runway suggests. The core of it:
- A risk management system operating across the lifecycle, not a document produced once.
- Data governance covering training, validation and testing data, including examination for bias. See data quality.
- Technical documentation sufficient for an authority to assess conformity.
- Automatic logging over the system's lifetime, which has to be designed into the architecture rather than added afterwards.
- Human oversight that is genuinely capable of intervening, not a person nominally in the loop.
- Accuracy, robustness and cybersecurity appropriate to the purpose, with the claims evidenced. See red teaming.
- Quality management, conformity assessment and registration before the system is placed on the market.
Deployers carry a lighter but real set: using the system as instructed, assigning competent human oversight, monitoring, keeping logs, and in some cases a fundamental rights impact assessment.
How the engagement runs
Classification is settled with your counsel before any remediation is planned.
Inventory and scoping
AI systems catalogued, including third-party and embedded; territorial reach established.
Classification
Provider or deployer role and risk classification per system, documented with reasoning, agreed with your counsel.
Gap assessment
Current state measured against the duties that apply now and those arriving in 2027 and 2028.
Remediation plan and immediate fixes
Transparency duties brought into compliance now; high-risk work sequenced against the revised deadlines.
Handover
Documentation pack, monitoring approach and the review cadence as implementing measures develop.
What you receive
A defensible classification per system, the duties that bind you today met, and a sequenced plan for the rest.
System inventory
Built and bought AI in scope, with territorial reach assessed.
Classification record
Provider or deployer role and risk class per system, with the reasoning written down.
Gap assessment
Against duties in force now and those arriving December 2027 and August 2028.
Immediate remediation
Transparency, disclosure and content marking brought into compliance.
Sequenced readiness plan
High-risk requirements with owners, effort and dates against the revised timetable.
Documentation pack
Technical documentation structure, logging design and oversight arrangements.
Is this the right engagement?
Worth being direct. EU AI Act Compliance Readiness is the wrong spend in some situations, and those are listed rather than buried.
Good fit if
- You place AI on the EU market or its output is used in the Union.
- A system may fall within Annex III and nobody has assessed it properly.
- Customer-facing AI exists and the transparency duties have not been addressed.
- Preparation stopped when the deadlines moved.
- An enterprise customer or regulator has asked for your position.
Choose something else if
- You need legal advice on interpretation, which is your counsel's role, not ours.
- You need certification against a standard. See ISO/IEC 42001.
- No AI system touches the Union in any way, directly or through output.
- You want a certificate of compliance, which no consultancy can issue.
Frequently asked questions
Marked up with FAQPage schema so these answers can surface directly in search results and inside AI assistant responses.
When do EU AI Act high-risk obligations actually apply?
Following the Digital Omnibus package approved by the Council on 29 June 2026, Annex III stand-alone high-risk systems apply from 2 December 2027, and Annex I systems embedded in regulated products from 2 August 2028 — deferred from 2 August 2026 and 2 August 2027 respectively. The substance was not softened; only the dates moved. This is our understanding as at September 2026 and should be confirmed with your counsel.
What applies to us right now?
The prohibitions and AI literacy duties since February 2025, general-purpose AI model obligations since August 2025, and the Article 50 transparency duties since 2 August 2026 — telling people they are dealing with an AI system, disclosing emotion recognition and biometric categorisation, and marking synthetic content, with a grace period on content marking running to 2 December 2026.
Does the Act apply to companies outside the EU?
It can. It reaches providers and deployers established in the Union and also those outside it where the system's output is used in the Union. A substantial amount of non-EU activity is in scope, and the territorial question is one of the first things the assessment settles.
Are we a provider or a deployer?
It depends on the system and it matters enormously, because provider obligations are far heavier. Putting your name on a system or materially modifying a third-party one can make you a provider even where you assumed you were merely using someone else's product. We document the position per system for your counsel to confirm.
Should we still prepare given the delay?
Yes. High-risk readiness — lifecycle risk management, data governance, technical documentation, lifetime logging designed into the architecture, evidenced human oversight — takes considerably longer than the remaining runway suggests. The deferral bought preparation time; organisations treating it as a reprieve will meet the same requirements with less of it.
Often paired with this
Most clients combine two or three engagements from the AI Governance, Security and Compliance pillar. These are the ones that most often run immediately before or after.
AI Risk Assessment and Model Cards
Risk assessments that end in decisions, and model cards that state limits honestly rather than advertising.
Read more →ISO/IEC 42001 Implementation
An AI management system built for certification and for use, reusing your ISO 27001 machinery rather than duplicating it.
Read more →AI Governance Framework Design
Proportionate risk tiers, named accountability and decision rights — a framework people follow rather than route around.
Read more →Is this the right engagement?
Tell us what you are trying to build. If a different service fits better, or if you do not need us at all, we will say so.