The EU AI Act, formally Regulation (EU) 2024/1689, is a risk-based law that sets rules for how AI systems are built, sold, and used across the European Union. It applies to providers who build AI systems, deployers who use them, providers of general-purpose AI (GPAI) models, and third-country companies whose AI outputs reach EU users, regardless of where the company is headquartered.
If you’re responsible for compliance, start now, not later:
Pro Tip: GPAI obligations already took effect on August 2, 2025. If you provide or fine-tune a foundation model, you are not looking at a future deadline. You’re already in scope.Key Takeaways
The EU AI Act succeeds when organizations treat classification as an ongoing operational discipline, not a one-time filing, backed by evidence that oversight actually functions in practice.
| Point | Details |
|---|---|
| Confirm your role first | Determine whether you’re a provider, deployer, or GPAI provider before assessing any other obligation. |
| GPAI deadlines already passed | Obligations for general-purpose AI models took effect August 2, 2025. |
| Watch the 2026 to 2028 window | Transparency and enforcement start August 2026; most high-risk deadlines run through December 2027, with embedded-product systems extended to August 2028. |
| Match NLF logic to the right chapter | Only certain high-risk categories require conformity assessment and CE marking; applying NLF rules elsewhere creates unnecessary paperwork. |
| Evidence beats documentation alone | Simulation logs and decision-practice outcomes demonstrate the human oversight your technical file only claims exists. |
The Act isn’t a tech-safety footnote. It’s the world’s first comprehensive AI law, and its ambition is to make trustworthy AI the default setting for a market of over 450 million people, not an optional feature. The European Commission frames it around four goals: protecting fundamental rights, ensuring safety, harmonizing rules across all 27 member states, and giving businesses one regulatory bar to clear instead of 27 different national ones.
The law is organized around risk, not technology type. That distinction matters for how you’ll approach compliance:
Alongside the binding rules, the Commission runs the AI Pact, a voluntary commitment program encouraging companies to adopt AI Act principles ahead of their legal deadlines. It’s not a substitute for compliance, but it’s a useful signal to regulators and customers that you’re moving early rather than waiting to be forced.
Every AI system placed on the EU market falls into one of four categories, and which one determines almost everything else about your obligations.
The practical trigger point is use case, not the underlying model architecture. A large language model embedded in a customer service widget might sit at transparency risk. The same model repurposed to screen job applicants jumps straight to high-risk, with a completely different compliance burden attached.
If you provide a GPAI model, foundation models trained on broad data and adaptable to many downstream tasks, you’ve had binding obligations since August 2, 2025. The Commission’s guidelines define which models qualify based on compute thresholds and general applicability, and the obligations scale with capability.
Baseline requirements for all GPAI providers include:
Models classified as carrying “systemic risk” (generally the most capable, highest-compute models) face additional duties: adversarial testing, incident reporting to the AI Office, and cybersecurity safeguards.
Providers must submit specified documentation through EU SEND, the AI Office’s dedicated submission platform. This isn’t a generic compliance filing. The guidelines describe an expectation of proactive, ongoing collaboration between systemic-risk model providers and AI Office technical staff, not a one-time form submission you file and forget.
High-risk systems carry the Act’s heaviest compliance load, and it’s built to function like a product safety regime, not a data policy.
Core requirements include:
Some high-risk systems, particularly those embedded in regulated products like medical devices or machinery, follow the New Legislative Framework (NLF), the EU’s standard product-safety architecture. These require formal conformity assessment and CE marking before market entry. Other high-risk categories, like those governing employment or law enforcement, are regulated under the Act directly and do not follow NLF logic. The Commission’s Implementation Guidance specifically warns against treating every high-risk chapter as if it were NLF-governed. That confusion is one of the most common early missteps organizations make.
Pro Tip: If your organization already runs ISO-based quality management systems for another regulated product line, integrate AI Act documentation into that existing structure. The Regulation itself references NLF alignment specifically to avoid forcing companies into duplicate paperwork.
Compliance teams that treat the AI Act as a checklist tend to produce documentation nobody trusts and controls nobody follows. A sequence built around evidence, not paperwork for its own sake, holds up better under regulatory scrutiny and internal audit.
Pro Tip: Treat the risk assessment as a living document, not a one-time gate. Systems drift, use cases expand, and a tool classified as minimal-risk at launch can quietly cross into high-risk territory six months later if someone repurposes it.
The Act entered into force in August 2024, but it applies in stages, not all at once, which is exactly why so many organizations misjudge their own deadline exposure.
Enforcement runs on two tracks: the European AI Office handles GPAI oversight and systemic-risk models at the EU level, while national competent authorities enforce high-risk and transparency obligations within their own member states. Both carry the power to demand corrective action, restrict market access, and levy fines. If you’re building a compliance timeline around a single “AI Act deadline,” you’re already behind. There isn’t one.
Skip the secondhand summaries and go to primary sources first, especially for anything you’ll cite in an audit trail.
Start with the Implementation Guidance for your timeline, then confirm specifics against EUR-Lex before finalizing internal policy.
Most compliance programs stop at the paperwork. They produce a risk register, a technical file, a transparency notice, and call it done. None of that tells you whether the people actually operating the system, the hiring manager relying on an AI screening tool, the frontline team overriding a fraud-detection flag, know how to exercise the human oversight the Act requires of them.
Cognistry’s approach starts earlier than most compliance playbooks do: diagnose what the work actually requires before deciding whether training is even the right enablement play. For AI Act compliance specifically, that means mapping the gap between what your documentation claims (human oversight exists, escalation paths are defined) and what your operational evidence actually shows.
Useful evidence to collect goes beyond the technical file:
Regulators increasingly ask not just “do you have a policy,” but “can your people demonstrate the judgment that policy assumes.” A technical file answers the first question. Simulation logs and decision-practice outcomes answer the second, and that’s the harder gap to close.
Not every AI system, and not every actor, falls under the Act’s full weight. The exemptions are narrower than most compliance teams assume, which is exactly where mistakes happen.
Research and development activity is exempt before a system is placed on the market, though that shield disappears the moment testing shifts to real-world conditions involving actual users. Military, defense, and national security applications sit outside the Act’s scope entirely, reflecting the EU’s limited competence over member-state security matters. Open-source AI components get a conditional carve-out from some GPAI obligations, but that exemption evaporates once the model qualifies as carrying systemic risk, regardless of its license.
Personal, non-professional use of AI also falls outside scope. Someone using a consumer chatbot for personal projects isn’t a “deployer” in the Act’s legal sense. But that exemption disappears fast once the same tool is used in a professional or organizational capacity, which is precisely the scenario most compliance teams need to watch for as employees adopt AI tools informally, ahead of any sanctioned procurement process.
None of these exemptions are blanket protections. Each is scoped tightly to a specific condition, and the condition, not the tool or the sector, determines whether the exemption actually holds. A model that starts as an exempt research project rarely stays exempt once it ships. Track that transition point deliberately.
Penalties under the AI Act scale with the severity of the violation, and they’re structured to make ignoring prohibited-practice bans dramatically more expensive than a documentation gap.
Violations involving banned AI practices, the unacceptable-risk tier, carry the steepest fines: up to €35 million or 7% of global annual turnover, whichever is higher. Most other violations, including failures to meet high-risk obligations around risk management, documentation, or human oversight, carry fines up to €15 million or 3% of global turnover. Supplying incorrect or misleading information to authorities during an investigation carries its own penalty tier, up to €7.5 million or 1% of turnover.
Those percentage-of-turnover figures matter more than the flat euro caps for large multinational providers, since 7% of global revenue for a major tech company dwarfs €35 million outright. National authorities also retain non-monetary enforcement tools: they can order a system withdrawn from the market, demand corrective modifications, or block market access outright while an investigation runs.
The reputational cost tends to compound the financial one. A public enforcement action against a high-risk AI system doesn’t just cost the fine. It signals to enterprise customers and procurement teams that your governance controls failed under scrutiny, which is a harder credibility gap to close than the fine itself.
The AI Act doesn’t replace GDPR, product safety law, or liability rules. It sits alongside them, and compliance with one doesn’t automatically satisfy the others.
Where AI systems process personal data, GDPR still governs lawful basis, data minimization, and individual rights like access and erasure, completely independent of the AI Act’s risk classification. A high-risk hiring tool under the AI Act still needs a GDPR lawful basis for processing candidate data, and clearing one obligation says nothing about the other.
Product safety law interacts most directly with high-risk AI systems embedded in regulated products, medical devices, machinery, and toys. This is where the NLF connection matters: an AI-powered medical device needs both AI Act conformity assessment and compliance with the underlying medical device regulation, layered together rather than treated as alternatives.
Liability rules are evolving in parallel. The EU’s approach to AI-related liability is still developing alongside the Act, meaning organizations should not assume AI Act compliance shields them from separate liability exposure if an AI system causes harm. Treat the AI Act as a floor for safety and governance, not a ceiling that resolves your full legal exposure. Legal teams reviewing AI deployments need to check all three frameworks (AI Act, GDPR, and applicable product/liability law) rather than assuming one covers the others.
Notified bodies are independent, EU member-state-designated organizations authorized to assess whether certain high-risk AI systems meet the Act’s requirements before they reach the market. They matter specifically for the subset of high-risk systems governed by the New Legislative Framework, the same NLF logic that applies to CE-marked medical devices and machinery.
Not every high-risk system needs a notified body. Many high-risk categories under the Act, like those covering employment decisions or law enforcement, allow providers to conduct self-assessment and issue their own declaration of conformity. Notified body involvement becomes mandatory when the AI system is a safety component of a product already subject to third-party conformity assessment under existing Union harmonization legislation, medical devices being the clearest example.
To earn designation, notified bodies must demonstrate technical competence, independence from the providers they assess, and adequate resources to evaluate the specific AI system category they’re authorized for. They review technical documentation, may test the system directly, and issue certificates that permit CE marking once satisfied.
For providers, the practical implication is sequencing: identify early whether your high-risk system triggers NLF conformity assessment or self-assessment, because notified body engagement can add significant lead time to a product launch. Building that assessment into your development timeline late is one of the more expensive planning mistakes a provider can make.
The conventional advice on the AI Act treats it as a documentation exercise: build the technical file, publish the transparency notice, file with EU SEND, and move on. That advice isn’t wrong. It’s incomplete.
The Act’s own language keeps returning to human oversight, a requirement that only means something if the humans in question can actually exercise judgment under pressure, not just sign a form confirming a policy exists. A hiring manager who’s never practiced overriding a flagged AI recommendation will defer to the system the first time it matters, policy or no policy.
That’s the gap conventional compliance work skips. Organizations should prioritize diagnosing where oversight actually breaks down operationally, not just where the paperwork says it shouldn’t, before building any training response. Sometimes the fix is a clearer escalation path. Sometimes it’s decision practice that builds real judgment under realistic conditions. Rarely is it a slide deck. Get the diagnosis right first, and the right enablement play becomes obvious instead of assumed.
The EU AI Act, Regulation (EU) 2024/1689, is a risk-based law governing how AI systems are developed, sold, and used across the European Union, with obligations scaled to each system’s risk tier.
Yes. It entered into force in August 2024 and is now being implemented in stages, with GPAI obligations already binding since August 2025 and further chapters activating through 2028.
Yes, if a US-based company’s AI system output is used within the EU, it falls under the Act’s scope regardless of where the company is headquartered, following the same extraterritorial logic used by GDPR.
Its purpose is to make AI systems used in the EU safer and more transparent while protecting fundamental rights, without blocking innovation, by tying compliance obligations to how much risk a given AI use case actually carries.
No. Only high-risk systems governed by the New Legislative Framework, mainly AI embedded in already-regulated products like medical devices, require conformity assessment and CE marking; other high-risk categories typically allow self-assessment.