Cognistry Edge Blog

The EU AI Act: What It Requires and Who Must Comply

Written by Brian Lambert, PhD | Aug 25, 2026, 1:57:04 AM

The EU AI Act, formally Regulation (EU) 2024/1689, is a risk-based law that sets rules for how AI systems are built, sold, and used across the European Union. It applies to providers who build AI systems, deployers who use them, providers of general-purpose AI (GPAI) models, and third-country companies whose AI outputs reach EU users, regardless of where the company is headquartered.

If you’re responsible for compliance, start now, not later:

  • Inventory every AI system your organization builds, buys, or deploys.
  • Classify each one against the Act’s four risk tiers.
  • Begin technical documentation and risk assessments before your applicable deadline hits.

Pro Tip: GPAI obligations already took effect on August 2, 2025. If you provide or fine-tune a foundation model, you are not looking at a future deadline. You’re already in scope.Key Takeaways

The EU AI Act succeeds when organizations treat classification as an ongoing operational discipline, not a one-time filing, backed by evidence that oversight actually functions in practice.

Point Details
Confirm your role first Determine whether you’re a provider, deployer, or GPAI provider before assessing any other obligation.
GPAI deadlines already passed Obligations for general-purpose AI models took effect August 2, 2025.
Watch the 2026 to 2028 window Transparency and enforcement start August 2026; most high-risk deadlines run through December 2027, with embedded-product systems extended to August 2028.
Match NLF logic to the right chapter Only certain high-risk categories require conformity assessment and CE marking; applying NLF rules elsewhere creates unnecessary paperwork.
Evidence beats documentation alone Simulation logs and decision-practice outcomes demonstrate the human oversight your technical file only claims exists.

Table of Contents

What Is the EU AI Act Trying to Accomplish?

The Act isn’t a tech-safety footnote. It’s the world’s first comprehensive AI law, and its ambition is to make trustworthy AI the default setting for a market of over 450 million people, not an optional feature. The European Commission frames it around four goals: protecting fundamental rights, ensuring safety, harmonizing rules across all 27 member states, and giving businesses one regulatory bar to clear instead of 27 different national ones.

The law is organized around risk, not technology type. That distinction matters for how you’ll approach compliance:

  • Prohibited practices — a short list of AI uses banned outright, regardless of sector.
  • High-risk obligations — a heavy compliance load tied to specific use cases and sectors.
  • GPAI rules — a separate regime for foundation models, layered on top of the risk tiers.
  • Transparency duties — disclosure requirements under Article 50 for AI that interacts with people directly.

Alongside the binding rules, the Commission runs the AI Pact, a voluntary commitment program encouraging companies to adopt AI Act principles ahead of their legal deadlines. It’s not a substitute for compliance, but it’s a useful signal to regulators and customers that you’re moving early rather than waiting to be forced.

What Are the Four Risk Tiers Under the AI Act?

Every AI system placed on the EU market falls into one of four categories, and which one determines almost everything else about your obligations.

  1. Unacceptable risk. Banned outright. This covers things like social scoring by governments, manipulative AI that exploits vulnerabilities, and most real-time biometric identification in public spaces. If your system falls here, there’s no compliance path. You stop.
  2. High-risk. Legal, but heavily regulated. This tier covers AI used in hiring and HR decisions, credit scoring, law enforcement, migration control, critical infrastructure, medical devices, and education admissions. These systems trigger the Act’s most demanding requirements: risk management, technical documentation, and human oversight.
  3. Transparency risk. Legal with disclosure duties under Article 50. This is where most generative AI chatbots, deepfake generators, and emotion-recognition tools land. Users must be told they’re interacting with AI or viewing AI-generated content.
  4. Minimal or no risk. The vast majority of AI in use today, including spam filters and inventory-optimization tools, falls here with no new obligations attached.

The practical trigger point is use case, not the underlying model architecture. A large language model embedded in a customer service widget might sit at transparency risk. The same model repurposed to screen job applicants jumps straight to high-risk, with a completely different compliance burden attached.

What Must General-Purpose AI Providers Do?

If you provide a GPAI model, foundation models trained on broad data and adaptable to many downstream tasks, you’ve had binding obligations since August 2, 2025. The Commission’s guidelines define which models qualify based on compute thresholds and general applicability, and the obligations scale with capability.

Baseline requirements for all GPAI providers include:

  • Maintaining technical documentation about training data, capabilities, and limitations.
  • Providing information downstream integrators need to understand the model’s behavior.
  • Publishing a summary of training content sufficient to address copyright obligations.

Models classified as carrying “systemic risk” (generally the most capable, highest-compute models) face additional duties: adversarial testing, incident reporting to the AI Office, and cybersecurity safeguards.

Providers must submit specified documentation through EU SEND, the AI Office’s dedicated submission platform. This isn’t a generic compliance filing. The guidelines describe an expectation of proactive, ongoing collaboration between systemic-risk model providers and AI Office technical staff, not a one-time form submission you file and forget.

What Do High-Risk AI Systems Require for Compliance?

High-risk systems carry the Act’s heaviest compliance load, and it’s built to function like a product safety regime, not a data policy.

Core requirements include:

  • A documented risk-management system, reviewed and updated across the system’s lifecycle.
  • Technical documentation detailing design, intended purpose, and performance metrics.
  • Data governance controls addressing training, validation, and testing data quality.
  • Accuracy, robustness, and cybersecurity measures appropriate to the use case.
  • Human oversight mechanisms that let a person intervene or override the system.
  • Logging capabilities that support post-market monitoring.

Some high-risk systems, particularly those embedded in regulated products like medical devices or machinery, follow the New Legislative Framework (NLF), the EU’s standard product-safety architecture. These require formal conformity assessment and CE marking before market entry. Other high-risk categories, like those governing employment or law enforcement, are regulated under the Act directly and do not follow NLF logic. The Commission’s Implementation Guidance specifically warns against treating every high-risk chapter as if it were NLF-governed. That confusion is one of the most common early missteps organizations make.

Pro Tip: If your organization already runs ISO-based quality management systems for another regulated product line, integrate AI Act documentation into that existing structure. The Regulation itself references NLF alignment specifically to avoid forcing companies into duplicate paperwork.

How Should Organizations Start Compliance Work?

Compliance teams that treat the AI Act as a checklist tend to produce documentation nobody trusts and controls nobody follows. A sequence built around evidence, not paperwork for its own sake, holds up better under regulatory scrutiny and internal audit.

  1. Diagnose before you classify. Inventory every AI system in production or procurement, and ground that inventory in real operational evidence, actual use cases, actual data flows, not vendor marketing claims about what a tool “can do.”
  2. Run risk assessments against the Act’s four tiers, and assign clear provider or deployer roles for each system. These roles carry different obligations, and getting the assignment wrong upstream creates gaps downstream.
  3. Build technical documentation and transparency notices in parallel, not sequentially. Waiting until documentation is “complete” before drafting user-facing disclosures under Article 50 wastes time you don’t have.
  4. Set up internal reporting paths so incidents, near-misses, and performance drift get escalated before a regulator finds them first.
  5. Embed AI Act obligations into procurement and vendor management. A high-risk system you buy from a third party doesn’t stop being your problem as deployer just because you didn’t build it.
  6. Engage stakeholders broadly, and layer in OECD-style due-diligence practices that go beyond minimum legal conformity toward genuinely responsible AI conduct across the system’s lifecycle.

Pro Tip: Treat the risk assessment as a living document, not a one-time gate. Systems drift, use cases expand, and a tool classified as minimal-risk at launch can quietly cross into high-risk territory six months later if someone repurposes it.

When Do the AI Act’s Rules Take Effect?

The Act entered into force in August 2024, but it applies in stages, not all at once, which is exactly why so many organizations misjudge their own deadline exposure.

  • Prohibited-practice bans took effect first, ahead of most other provisions.
  • Article 50 transparency duties and the enforcement architecture, including AI Office and national authority powers, activate in August 2026.
  • Most high-risk obligations for standalone use cases carry deadlines through December 2, 2027.
  • High-risk systems embedded in already-regulated products get the longest runway, extended to August 2, 2028 under the AI Omnibus adjustments.

Enforcement runs on two tracks: the European AI Office handles GPAI oversight and systemic-risk models at the EU level, while national competent authorities enforce high-risk and transparency obligations within their own member states. Both carry the power to demand corrective action, restrict market access, and levy fines. If you’re building a compliance timeline around a single “AI Act deadline,” you’re already behind. There isn’t one.

Where Can You Find Official AI Act Guidance?

Skip the secondhand summaries and go to primary sources first, especially for anything you’ll cite in an audit trail.

  • EUR-Lex full text — the binding legal text itself, your reference of last resort for any dispute.
  • Commission AI Act pages — plain-language policy summaries and links to supporting initiatives.
  • Implementation Guidance PDF — practical clarification on timelines and the NLF versus non-NLF distinction.
  • AI Act Service Desk — the Commission’s help channel for specific compliance questions.

Start with the Implementation Guidance for your timeline, then confirm specifics against EUR-Lex before finalizing internal policy.

Documentation Proves You Filed. It Doesn’t Prove You’re Ready.

Most compliance programs stop at the paperwork. They produce a risk register, a technical file, a transparency notice, and call it done. None of that tells you whether the people actually operating the system, the hiring manager relying on an AI screening tool, the frontline team overriding a fraud-detection flag, know how to exercise the human oversight the Act requires of them.

Cognistry’s approach starts earlier than most compliance playbooks do: diagnose what the work actually requires before deciding whether training is even the right enablement play. For AI Act compliance specifically, that means mapping the gap between what your documentation claims (human oversight exists, escalation paths are defined) and what your operational evidence actually shows.

Useful evidence to collect goes beyond the technical file:

  • Process artifacts showing how oversight decisions get made in practice.
  • Decision-practice outcomes from simulated high-stakes scenarios, not just training completion records.
  • Friction points surfaced when staff attempt to override or escalate a flagged AI output.

Regulators increasingly ask not just “do you have a policy,” but “can your people demonstrate the judgment that policy assumes.” A technical file answers the first question. Simulation logs and decision-practice outcomes answer the second, and that’s the harder gap to close.

Are There Exemptions Under the EU AI Act?

Not every AI system, and not every actor, falls under the Act’s full weight. The exemptions are narrower than most compliance teams assume, which is exactly where mistakes happen.

Research and development activity is exempt before a system is placed on the market, though that shield disappears the moment testing shifts to real-world conditions involving actual users. Military, defense, and national security applications sit outside the Act’s scope entirely, reflecting the EU’s limited competence over member-state security matters. Open-source AI components get a conditional carve-out from some GPAI obligations, but that exemption evaporates once the model qualifies as carrying systemic risk, regardless of its license.

Personal, non-professional use of AI also falls outside scope. Someone using a consumer chatbot for personal projects isn’t a “deployer” in the Act’s legal sense. But that exemption disappears fast once the same tool is used in a professional or organizational capacity, which is precisely the scenario most compliance teams need to watch for as employees adopt AI tools informally, ahead of any sanctioned procurement process.

None of these exemptions are blanket protections. Each is scoped tightly to a specific condition, and the condition, not the tool or the sector, determines whether the exemption actually holds. A model that starts as an exempt research project rarely stays exempt once it ships. Track that transition point deliberately.

What Happens If an Organization Doesn’t Comply?

Penalties under the AI Act scale with the severity of the violation, and they’re structured to make ignoring prohibited-practice bans dramatically more expensive than a documentation gap.

Violations involving banned AI practices, the unacceptable-risk tier, carry the steepest fines: up to €35 million or 7% of global annual turnover, whichever is higher. Most other violations, including failures to meet high-risk obligations around risk management, documentation, or human oversight, carry fines up to €15 million or 3% of global turnover. Supplying incorrect or misleading information to authorities during an investigation carries its own penalty tier, up to €7.5 million or 1% of turnover.

Those percentage-of-turnover figures matter more than the flat euro caps for large multinational providers, since 7% of global revenue for a major tech company dwarfs €35 million outright. National authorities also retain non-monetary enforcement tools: they can order a system withdrawn from the market, demand corrective modifications, or block market access outright while an investigation runs.

The reputational cost tends to compound the financial one. A public enforcement action against a high-risk AI system doesn’t just cost the fine. It signals to enterprise customers and procurement teams that your governance controls failed under scrutiny, which is a harder credibility gap to close than the fine itself.

How Does the AI Act Interact With GDPR and Other EU Laws?

The AI Act doesn’t replace GDPR, product safety law, or liability rules. It sits alongside them, and compliance with one doesn’t automatically satisfy the others.

Where AI systems process personal data, GDPR still governs lawful basis, data minimization, and individual rights like access and erasure, completely independent of the AI Act’s risk classification. A high-risk hiring tool under the AI Act still needs a GDPR lawful basis for processing candidate data, and clearing one obligation says nothing about the other.

Product safety law interacts most directly with high-risk AI systems embedded in regulated products, medical devices, machinery, and toys. This is where the NLF connection matters: an AI-powered medical device needs both AI Act conformity assessment and compliance with the underlying medical device regulation, layered together rather than treated as alternatives.

Liability rules are evolving in parallel. The EU’s approach to AI-related liability is still developing alongside the Act, meaning organizations should not assume AI Act compliance shields them from separate liability exposure if an AI system causes harm. Treat the AI Act as a floor for safety and governance, not a ceiling that resolves your full legal exposure. Legal teams reviewing AI deployments need to check all three frameworks (AI Act, GDPR, and applicable product/liability law) rather than assuming one covers the others.

What Role Do Notified Bodies Play in Conformity Assessment?

Notified bodies are independent, EU member-state-designated organizations authorized to assess whether certain high-risk AI systems meet the Act’s requirements before they reach the market. They matter specifically for the subset of high-risk systems governed by the New Legislative Framework, the same NLF logic that applies to CE-marked medical devices and machinery.

Not every high-risk system needs a notified body. Many high-risk categories under the Act, like those covering employment decisions or law enforcement, allow providers to conduct self-assessment and issue their own declaration of conformity. Notified body involvement becomes mandatory when the AI system is a safety component of a product already subject to third-party conformity assessment under existing Union harmonization legislation, medical devices being the clearest example.

To earn designation, notified bodies must demonstrate technical competence, independence from the providers they assess, and adequate resources to evaluate the specific AI system category they’re authorized for. They review technical documentation, may test the system directly, and issue certificates that permit CE marking once satisfied.

For providers, the practical implication is sequencing: identify early whether your high-risk system triggers NLF conformity assessment or self-assessment, because notified body engagement can add significant lead time to a product launch. Building that assessment into your development timeline late is one of the more expensive planning mistakes a provider can make.

Why Most AI Act Compliance Programs Are Solving the Wrong Problem

The conventional advice on the AI Act treats it as a documentation exercise: build the technical file, publish the transparency notice, file with EU SEND, and move on. That advice isn’t wrong. It’s incomplete.

The Act’s own language keeps returning to human oversight, a requirement that only means something if the humans in question can actually exercise judgment under pressure, not just sign a form confirming a policy exists. A hiring manager who’s never practiced overriding a flagged AI recommendation will defer to the system the first time it matters, policy or no policy.

That’s the gap conventional compliance work skips. Organizations should prioritize diagnosing where oversight actually breaks down operationally, not just where the paperwork says it shouldn’t, before building any training response. Sometimes the fix is a clearer escalation path. Sometimes it’s decision practice that builds real judgment under realistic conditions. Rarely is it a slide deck. Get the diagnosis right first, and the right enablement play becomes obvious instead of assumed.

Sources

FAQ

What Is the AI Act in the EU?

The EU AI Act, Regulation (EU) 2024/1689, is a risk-based law governing how AI systems are developed, sold, and used across the European Union, with obligations scaled to each system’s risk tier.

Has the EU AI Act Been Passed?

Yes. It entered into force in August 2024 and is now being implemented in stages, with GPAI obligations already binding since August 2025 and further chapters activating through 2028.

Does the EU AI Act Apply to the US?

Yes, if a US-based company’s AI system output is used within the EU, it falls under the Act’s scope regardless of where the company is headquartered, following the same extraterritorial logic used by GDPR.

What Is the Point of the EU AI Act?

Its purpose is to make AI systems used in the EU safer and more transparent while protecting fundamental rights, without blocking innovation, by tying compliance obligations to how much risk a given AI use case actually carries.

Do All High-Risk AI Systems Need CE Marking?

No. Only high-risk systems governed by the New Legislative Framework, mainly AI embedded in already-regulated products like medical devices, require conformity assessment and CE marking; other high-risk categories typically allow self-assessment.