GLACIS·EU AI Act series·Updated August 2026

EU AI Act high-risk compliance, before the cliff edge.

The Act can apply to providers and deployers inside or outside the EU when its territorial conditions are met. Prohibited-practice fines can reach €35M or 7% of global turnover. The AI Omnibus entered into force on 27 July 2026: relevant high-risk obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product-embedded systems. Technical documentation and Article 12 logging must be ready when the applicable duties begin.

Talk to us Verify a record Read the full compliance guide →
General Counsel CCO CISO DPO
Feb 2025
Prohibited practices in force
Aug 2025
GPAI obligations live; Commission maintains the current Code signatory register
27 Jul 2026
AI Omnibus (Regulation (EU) 2026/1744) entered into force
2027 → 2028
Relevant Annex III duties: 2 Dec 2027; Annex I product-embedded duties: 2 Aug 2028
What changed by August 2026

After a provisional agreement in May 2026, the AI Omnibus was formally adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. Relevant Annex III high-risk obligations now apply from 2 December 2027, and relevant Annex I product-embedded obligations from 2 August 2028. Other AI Act obligations retain their own application dates; the amendment did not postpone the Act as a whole.

The dates are reflected in the consolidated AI Act on EUR-Lex. Classification and the applicable conformity pathway remain system-specific; this page is general information, not legal advice.

High-risk systems under Annex III

For an Annex III use case, Article 6(2) classification turns on the system’s intended purpose and the specific Annex III entry. Article 6(3) provides a limited route for a listed system that does not pose a significant risk of harm to health, safety, or fundamental rights, subject to its conditions; profiling systems listed in Annex III remain high-risk. A system classified high-risk is subject to Articles 9–15 (risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy/robustness/cybersecurity), plus Article 17 quality management.

DomainTypical systems in scope
BiometricsRemote identification, categorisation, emotion recognition (outside law-enforcement carve-outs)
Critical infrastructureSafety components for water, gas, electricity, traffic management, digital networks
Education & vocational trainingAdmissions scoring, exam evaluation, attainment-level assignment, prohibited-behaviour detection
EmploymentRecruitment, selection, performance evaluation, termination, work allocation
Essential servicesCreditworthiness, life and health insurance pricing, public-benefit access decisions, emergency triage
Law enforcementRisk assessment of natural persons, polygraphs, evidence reliability, profiling
Migration, asylum & borderRisk assessment, document verification, application examination support
Justice & democratic processesJudicial-decision support, alternative dispute resolution, election influence systems
Where this bites first

Employment screening is Annex III high-risk: recruitment, ranking and evaluation systems carry the full Articles 9–15 load. See how signed runtime evidence works for hiring AI. Clinical AI embedded in regulated products follows the embedded-product track; start with medical devices.

What Articles 9–15 actually require

ArticleRequirement
Art. 9Risk management system across the lifecycle: identify, evaluate, mitigate, monitor.
Art. 10Data governance for training, validation, testing — relevance, representativeness, error checks.
Art. 11Technical documentation per Annex IV (nine substantive sections).
Art. 12Automatic event logging capabilities appropriate to the covered high-risk system’s intended purpose. Configured GLACIS paths can contribute scoped records for selected events.
Art. 13Transparency and instructions for downstream deployers.
Art. 14Effective human oversight measures.
Art. 15Accuracy, robustness, cybersecurity — including resilience to adversarial input.
Art. 17Quality management system covering compliance, post-market monitoring, incident reporting.

Penalty structure under Article 99

Three penalty bands. For undertakings other than SMEs, the higher fixed amount or turnover percentage is the ceiling; for SMEs, each fine must not exceed the lower of those two ceilings. National competent authorities set the actual fine within the applicable ceiling; the AI Office handles GPAI providers directly.

ViolationMaximum fineOr % of global turnover
Prohibited practices (Article 5)€35,000,0007%
Other non-compliance (Articles 9–15, 17, etc.)€15,000,0003%
Incorrect information to authorities€7,500,0001%
Enforcement status

Enforcement and institutional design remain phased across the Union. Confirm the current competent authority, applicable system category, and effective date before relying on this overview for a specific deployment.

How GLACIS fits the obligations

GLACIS can connect configured controls to signed operational records for a defined AI workflow. Those records may support an organization’s Article 12 logging and review process; they do not replace technical documentation, conformity assessment, or legal analysis.

ArticleWhat GLACIS produces
Art. 9 Risk managementScoped records showing which configured controls evaluated an in-scope action and which outcome was reported.
Art. 11 Technical docsOperational evidence that can supplement, but does not generate or replace, Annex IV documentation.
Art. 12 LoggingSigned event records with explicit scope, identity, timestamps, control outcomes, and integrity checks.
Art. 14 Human oversightRecords of configured escalation, review, and override events for covered actions.
Art. 15 RobustnessEvidence from configured tests and runtime controls, interpreted alongside system-level evaluation.
Art. 17 QMSEvidence artifacts that can support an organization’s quality-management and post-market processes.
Talk to us Verify a record

Signed, scoped records may contribute to an Article 12 evidence set when their fields and coverage are relevant; they do not replace the system’s logging design or establish conformity.

Go deeper

Full compliance guide Risk categories, Articles 9–15 in detail, GPAI obligations, conformity assessment paths, the Omnibus status.
For Chief Compliance Officers Programme architecture, audit-readiness checklist, board reporting, certification routes.
For CISOs Article 12 logging architecture, Article 15 robustness, sec-eng integration.
For General Counsel Liability allocation, vendor and deployer contracts, extraterritorial scope.
EU AI Act vs HIPAA Crosswalk for healthcare and life-sciences operators with US obligations.
Colorado ADMT law (SB 26-189) The US transparency analogue — covered automated decision-making technology, with substantive compliance from 1 January 2027; what stacks with the EU regime.

By member state

GermanyBundestag adopted KI-MIG on 11 June 2026, assigning roles to BNetzA, sector authorities and KoKIVO; verify promulgation, entry into force and the current authority route.
FranceDecentralised model: CNIL on workplace/education emotion-recognition; ANSSI on cybersecurity; PEReN technical support; the multi-authority DDADUE bill passed the Senate on 18 February 2026 and remains before the National Assembly.
ItalyNational AI Law No. 132/2025 in force 10 October 2025; AgID notifying authority, ACN market surveillance, Garante on data; delegated implementing decrees have a statutory deadline of 10 October 2026.
SpainAESIA operational since June 2024; 16 detailed compliance guides published December 2025; regulatory sandbox; draft national AI Law (March 2025).
NetherlandsProposed hybrid 10-authority model led by AP, with AP+RDI co-coordination; public consultation on the proposed Implementation Act ran 20 April – 1 June 2026 and is closed.
BelgiumBIPT designated main market surveillance authority (2025-2029 Federal Government Agreement); 21 fundamental-rights bodies under Article 77.
PolandNew body KRiBSI under construction (single-authority model); operational support nested in Ministry of Digital Affairs; UODO disputing advisory-only role.