GLACIS·EU AI Act series·Compliance guide·Updated August 2026

EU AI Act compliance, the working playbook for August 2026.

Regulation (EU) 2024/1689 in plain English: how risk classification works, what Articles 9–15 require, where the GPAI Code of Practice landed, and the high-risk dates now set by the AI Omnibus in force since 27 July 2026. With primary-source citations.

By Joe Braidwood, CEO GLACIS·26 min read·Updated 26 August 2026

Feb 2025
Prohibited practices in force; AI literacy obligations apply
Aug 2025
GPAI obligations live; Commission maintains the current Code signatory register
27 Jul 2026
AI Omnibus (Regulation (EU) 2026/1744) entered into force
2027 → 2028
Relevant Annex III duties: 2 Dec 2027; Annex I product-embedded duties: 2 Aug 2028

Executive summary

The EU AI Act (Regulation 2024/1689) entered into force on 1 August 2024 and establishes horizontal EU rules for specified AI practices and operator roles. Its penalty tiers vary by breach; the €35 million or 7% of global annual turnover maximum applies to prohibited practices.[1]

The phased calendar: prohibited practices have applied since 2 February 2025 and GPAI model obligations since 2 August 2025. After a provisional agreement in May 2026, the AI Omnibus was adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. Relevant Annex III high-risk obligations apply from 2 December 2027, while relevant Annex I product-embedded obligations apply from 2 August 2028.[12][13][14] Other AI Act obligations retain their own application dates.

Where we land in August 2026. The GPAI Code of Practice is finalised. Harmonised standards remain an important part of operational compliance, but organizations should classify each system and map the provisions that apply rather than treating either high-risk date as a deadline for the Act as a whole.[15][16]

€35M
Maximum fine[1]
Dec 2027
Relevant Annex III high-risk date
Live
GPAI Code public register[15]
27
EU member states

What changed by August 2026

August 2026 update brief

The AI Omnibus is adopted and in force. Regulation (EU) 2026/1744 entered into force on 27 July 2026. It sets 2 December 2027 for relevant Annex III high-risk obligations and 2 August 2028 for relevant Annex I product-embedded obligations.[12][13] This is no longer a proposal or provisional timetable.

GPAI Code of Practice signatories are maintained in a live Commission register. The public list was last updated 31 July 2026; xAI is listed for the Safety and Security chapter only. Because the register can change, procurement records should capture a provider’s status at the time of review rather than rely on a frozen count.[15]

CEN-CENELEC harmonised standards are now tracking to Q4 2026 delivery after the October 2025 acceleration measures. The first standard targets quality management (prEN 18286).[16]

Member-state competent authorities: Belgium designated BIPT (Federal Government Agreement, 2025-2029); Germany’s Bundestag adopted KI-MIG on 11 June 2026, with BNetzA and KoKIVO roles subject to promulgation and current notices; the Netherlands ran public consultation on its Implementation Act from 20 April through 1 June 2026; Poland is constructing a new single authority (KRiBSI); France has tasked ANSSI with cybersecurity competences; Italy’s national AI Law No. 132/2025 entered into force in October 2025 with implementing decrees due by 10 October 2026.[17][18][19][20][21][22]

AI Office: staffing has crossed 125, with a target of around 140. Five-unit structure under Lucilla Sioli.[23]

What is the EU AI Act?

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is the world’s first comprehensive legal framework regulating artificial intelligence systems. Adopted by the European Parliament on March 13, 2024, and entering into force August 1, 2024, it establishes harmonized rules for AI development, deployment, and use across all 27 EU member states.[1]

History and legislative process

The European Commission proposed the AI Act on April 21, 2021, as part of its digital strategy. After three years of trilogue negotiations between the Commission, Parliament, and Council, political agreement was reached December 9, 2023. The final text passed with 523 votes in favor, 46 against, and 49 abstentions.[4]

The regulation was published in the Official Journal of the European Union (EUR-Lex) on July 12, 2024, as Regulation (EU) 2024/1689, comprising 180 articles and 13 annexes spanning 144 pages.[1]

Scope and applicability

The AI Act applies to:

  • AI system providers placing systems on the EU market or putting them into service, regardless of location
  • AI system deployers (users) located in the EU
  • Providers and deployers of AI systems located in third countries where the output is used in the EU
  • Importers and distributors of AI systems in the EU

The regulation defines an “AI system” per Article 3(1) as “a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.”[1]

Key objectives

The regulation balances promoting AI innovation with protecting fundamental rights, health, safety, and democratic values. Article 1 establishes objectives including:

  • Ensuring AI systems placed on the EU market are safe and respect fundamental rights
  • Ensuring legal certainty to facilitate investment and innovation in AI
  • Enhancing governance and effective enforcement of existing law on fundamental rights
  • Facilitating the development of a single market for lawful, safe, and trustworthy AI systems

Risk categories

The AI Act employs a risk-based approach, classifying AI systems into four tiers with escalating regulatory requirements based on potential harm to health, safety, and fundamental rights.

Prohibited AI systems

Article 5 — Banned outright due to unacceptable risks to fundamental rights and human dignity. Effective February 2, 2025.

Examples:

  • Social scoring systems evaluating or classifying people based on behavior, socio-economic status, or personal characteristics
  • Untargeted scraping of facial images from internet or CCTV for facial recognition databases
  • Emotion recognition in workplace and educational settings (with limited exceptions)
  • Manipulative AI exploiting vulnerabilities of age, disability, or socio-economic circumstances
  • Real-time remote biometric identification in public spaces by law enforcement (narrow exceptions)

High-risk AI systems

Articles 6-7, Annex III — Covered systems can pose significant risks to health, safety, or fundamental rights and are subject to requirements before and during market placement. Relevant Annex III high-risk obligations apply from 2 December 2027 under the AI Omnibus.

Eight Categories (Annex III):

  • Biometric identification and categorization: Real-time/post remote biometric ID, emotion recognition (limited contexts)
  • Critical infrastructure: Safety components in road traffic, water, gas, heating, electricity management
  • Education and training: Determining educational institution access, evaluation of learning outcomes, exam supervision
  • Employment: Recruitment, task allocation, promotion decisions, performance monitoring, termination decisions
  • Essential services: Creditworthiness assessment, insurance pricing/underwriting, emergency dispatch prioritization
  • Law enforcement: Individual risk assessment, polygraphs, emotion detection, deep fake detection, evidence evaluation
  • Migration and asylum: Application examination, risk assessment, verification of authenticity of travel documents
  • Justice and democratic processes: Assisting judicial authorities in researching and interpreting facts and law

Limited-risk AI systems

Article 50 — Specific transparency obligations to ensure users are aware they are interacting with AI. Minimal regulatory burden.

Examples:

  • Chatbots and conversational agents (must disclose they are AI)
  • Emotion recognition systems (limited contexts, must inform users)
  • Biometric categorization systems (must inform data subjects)
  • Deep fakes and AI-generated content (must be labeled as synthetic)

Minimal-risk AI systems

No regulatory obligations beyond existing product safety and liability rules. Voluntary codes of conduct encouraged (Article 95).

Examples:

  • AI-enabled video games and spam filters
  • Inventory management and process optimization systems
  • Recommendation engines (non-manipulative)
  • Most enterprise productivity and automation tools

Timeline and deadlines

The AI Act follows a staggered application calendar. As of 26 August 2026, prohibited-practice, AI-literacy, GPAI-model, and specified transparency provisions are among those already applicable. The AI Omnibus is in force; relevant Annex III high-risk obligations apply from 2 December 2027 and relevant Annex I product-embedded obligations from 2 August 2028.[12][13]

Date Milestone Requirements Status (August 2026)
1 Aug 2024 Entry into force Regulation published, legally effective In force
2 Feb 2025 Prohibited practices Article 5 prohibitions, AI literacy obligations In force
2 Aug 2025 GPAI obligations Article 53–55 model-provider obligations; Code of Practice published 10 Jul 2025 In force
27 Jul 2026 AI Omnibus Regulation (EU) 2026/1744 amends the AI Act timeline In force
2 Dec 2027 Annex III high-risk Relevant high-risk obligations for Annex III systems Current application date
2 Aug 2028 Annex I product-embedded high-risk Relevant high-risk obligations for AI embedded in regulated products Current application date
Working baseline

Use the application date tied to the system’s classification: 2 December 2027 for relevant Annex III high-risk duties and 2 August 2028 for relevant Annex I product-embedded duties. Other provisions may already apply or follow different dates. Confirm the specific pathway with counsel and the relevant market-surveillance or notified-body authorities.

Requirements by category

Prohibited AI systems (Article 5)

Prohibited practices became illegal February 2, 2025. Organizations must immediately cease any:

  • Subliminal manipulation causing harm
  • Exploitation of vulnerabilities (age, disability, economic situation)
  • Social scoring by public authorities
  • Risk assessment based solely on profiling or personality traits
  • Facial recognition database creation via untargeted scraping
  • Emotion recognition in workplace/education (limited exceptions)

Penalty ceiling: Up to €35 million or 7% of total worldwide annual turnover for specified infringements. For undertakings other than SMEs, the higher applicable ceiling is used; for SMEs, including startups, Article 99 applies the lower applicable fixed or percentage ceiling.[1]

High-risk AI systems (Articles 8–15)

High-risk AI systems face comprehensive requirements across the entire lifecycle. Providers must implement:

Article 9: risk management system

Continuous iterative process throughout the AI system lifecycle comprising:

  • Identification and analysis of known and foreseeable risks
  • Estimation and evaluation of risks that may emerge during use
  • Evaluation of other possibly arising risks based on post-market monitoring
  • Adoption of suitable risk management measures

Article 10: data and data governance

Training, validation, and testing datasets must be subject to appropriate data governance and management practices:

  • Relevant, sufficiently representative, and free of errors
  • Consideration of geographic, contextual, behavioral, or functional settings
  • Examination for possible biases and mitigation where appropriate
  • Completeness considering intended purpose and reasonably foreseeable misuse

Article 11: technical documentation

Documentation prepared before placing on market and kept up to date, including:

  • General description of the AI system (intended purpose, developer, version)
  • Detailed description of system elements and development process
  • Detailed information about monitoring, functioning, and control
  • Risk management system description per Article 9
  • Validation and testing procedures, results, and reports

Article 12: record-keeping (logging)

Automatic recording of events (logs) throughout the AI system operation:

  • Logging capabilities ensuring traceability throughout the system lifecycle
  • Logging level appropriate to intended purpose of high-risk system
  • Records including input data period, reference database, persons involved in verification
  • Logs protected by appropriate security measures and retained for period appropriate to purpose

Article 13: transparency for deployers

High-risk systems must be designed with sufficient transparency to enable deployers to:

  • Interpret system output and use it appropriately
  • Understand system capabilities and limitations
  • Instructions for use in appropriate digital or non-digital format
  • Information on human oversight measures per Article 14

Article 14: human oversight

High-risk systems shall be designed to enable effective oversight by natural persons:

  • Fully understand capacities and limitations and monitor operation
  • Remain aware of possible tendency to automatically rely on output (automation bias)
  • Correctly interpret system output considering system characteristics
  • Decide to not use the system or override output in any particular situation

Article 15: accuracy, robustness and cybersecurity

High-risk systems must achieve appropriate levels of:

  • Accuracy: Ability to provide correct output or actions
  • Robustness: Reliability against errors, faults, inconsistencies, and unexpected situations
  • Cybersecurity: Resilience against attempts to alter use, behavior, or performance through exploitation
  • Technical solutions to address AI-specific vulnerabilities including data poisoning and model evasion

Article 17: quality management system

Providers of high-risk systems must establish and maintain a documented quality management system ensuring:

  • Compliance strategy for regulatory requirements
  • Design, control, and quality assurance techniques and procedures
  • Post-market monitoring, reporting, and corrective action procedures
  • Examination, test, and validation procedures at design and throughout development

Penalty for high-risk non-compliance: Up to €15 million or 3% of total worldwide annual turnover (Article 99).[1]

Limited-risk AI systems (Article 50)

Limited-risk systems face only transparency obligations:

  • Chatbots: Inform users they are interacting with AI (unless obvious from context)
  • Emotion recognition/biometric categorization: Inform natural persons they are being subjected to such systems
  • Deep fakes: Disclose that content has been artificially generated or manipulated

Penalty: Up to €7.5 million or 1% of total worldwide annual turnover (Article 99).[1]

High-risk AI systems in detail

Classification criteria (Article 6)

An AI system is considered high-risk if:

  1. The AI system is intended to be used as a safety component of a product covered by EU harmonization legislation (Annex I), OR
  2. The AI system itself is a product covered by EU harmonization legislation (Annex I) and requires third-party conformity assessment, OR
  3. The AI system falls under one of the eight high-risk use cases listed in Annex III

Annex III high-risk use cases

High-risk AI categories (Annex III)

Category Specific Use Cases Examples
1. Biometrics Remote biometric identification (real-time/post), biometric categorization Airport facial recognition, emotion detection at borders
2. Critical Infrastructure Safety components managing road traffic, water, gas, heating, electricity Traffic signal AI, power grid management systems
3. Education Determining access, assessing students, detecting cheating Automated admissions, AI exam proctoring, grading systems
4. Employment Recruitment, promotion, task allocation, monitoring, termination Resume screening AI, performance monitoring, layoff decisions
5. Essential Services Creditworthiness, insurance pricing, emergency dispatch Loan approval AI, health insurance underwriting
6. Law Enforcement Risk assessment, polygraphs, emotion detection, evidence evaluation Recidivism prediction, crime forecasting, lie detection
7. Migration/Asylum Examination of applications, risk assessment, travel document verification Automated visa screening, asylum claim evaluation
8. Justice Assisting judicial authorities in researching/interpreting facts and law Legal research AI, case outcome prediction

Conformity assessment procedures (Articles 43–44)

Before placing high-risk AI systems on the market, providers must undergo conformity assessment to demonstrate compliance. Two pathways exist:

Internal control (Article 43)

Provider conducts self-assessment based on:

  • Technical documentation (Annex IV)
  • Quality management system implementation
  • Post-market monitoring plan
  • Drawing up EU declaration of conformity

Available for most high-risk systems

Notified body assessment (Article 43)

Third-party assessment required for:

  • Biometric identification systems
  • AI systems covered by other EU regulations requiring notified body involvement
  • Annex I product-related AI where the applicable Union product law requires third-party conformity assessment

Cost and timing vary materially with system scope, evidence readiness, quality-management maturity, notified-body involvement, and the applicable conformity-assessment path. Obtain a current, system-specific assessment.

Healthcare AI Under the EU AI Act

The EU AI Act doesn’t create one single healthcare deadline. Under the AI Omnibus now in force, relevant Annex III high-risk obligations apply from 2 December 2027, while relevant Annex I product-embedded obligations, including covered MDR/IVDR pathways, apply from 2 August 2028. Healthcare teams still need to classify first and calendar second.

Healthcare deployments often land in high-risk categories because they either:

  • Are AI systems or safety components in products regulated under the MDR or IVDR
  • Fall within Annex III use cases such as determining access to essential private or public services (including healthcare access, coverage, or prior-authorization workflows)
  • Support clinical workflows where a regulated-product pathway or another high-risk classification applies

Not every healthcare feature is automatically high-risk. Ambient documentation, clinical decision support, diagnostics, utilization management, and access workflows can land in different buckets depending on product classification, intended purpose, and how the output is used. For an operational breakdown by clinical-AI type, see our dedicated guides on ambient AI scribe, CDSS high-risk classification, and AI diagnosis high-risk classification.

The Article 12 operational test: Article 12 logging isn’t satisfied by vague promises that logging exists somewhere. High-risk healthcare teams need records they can actually retrieve and explain when regulators, customers, or conformity assessors ask how a system operated in a specific patient encounter.

GPAI obligations and Code of Practice

The AI Act sets specific obligations for providers that place general-purpose AI models on the EU market. Those obligations have applied since 2 August 2025; the Commission’s enforcement powers began applying on 2 August 2026.[15]

GPAI Code of Practice — register checked August 2026

The voluntary Code was published on 10 July 2025 and assessed by the Commission and AI Board as an adequate tool for demonstrating compliance with the relevant GPAI obligations. The Commission maintains the current signatory register; its page was last updated 31 July 2026.[15]

xAI is listed for the Safety and Security chapter only and must demonstrate compliance with transparency and copyright obligations by other adequate means. Signatory status is one diligence input, not proof that a particular model or deployment complies.

Definition and classification (Article 3)

A general-purpose AI model is defined as an AI model “trained on large amounts of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks regardless of the way the model is placed on the market.”[1]

All in-scope GPAI model providers face baseline obligations. Models classified as posing systemic risk face additional duties; Article 51 includes a rebuttable compute-based presumption and also permits Commission designation based on capabilities or impact.

Standard GPAI models

Article 53: Baseline obligations for in-scope GPAI model providers, subject to the Act’s stated exceptions.

Requirements:

  • Technical documentation per Annex XI (architecture, training data, compute resources)
  • Information and documentation to downstream providers to enable compliance
  • Copyright policy including sufficiently detailed summary of training data content
  • Publicly available summary of training data subject to copyright protection

GPAI models with systemic risk

Articles 51 and 55: Models classified as posing systemic risk face enhanced obligations. Training compute above 1025 FLOPs creates a rebuttable presumption under Article 51; the Commission may amend the threshold and may designate models using other criteria.

Additional Requirements:

  • Model evaluation per standardized protocols including adversarial testing
  • Assessment and mitigation of systemic risks (including cybersecurity threats)
  • Tracking, documenting, and reporting serious incidents to AI Office and national authorities
  • Ensuring adequate cybersecurity protection for model and physical infrastructure

Do not infer legal classification from a model name, benchmark, or vendor marketing tier. Record the provider’s notification or designation status and the model version actually used.

Compliance deadline

GPAI obligations have applied since 2 August 2025. The Commission’s enforcement powers began applying on 2 August 2026; providers of models placed on the market before 2 August 2025 have until 2 August 2027 to comply.[15]

Penalties and enforcement

The AI Act establishes one of the most stringent penalty regimes in technology regulation, mirroring GDPR’s structure with fines tied to global annual turnover.

Penalty tiers (Article 99)

EU AI Act penalty structure

Violation Type Maximum Fine Articles
Prohibited AI practices €35M or 7% global revenue Article 5
Non-compliance with high-risk requirements €15M or 3% global revenue Articles 8-15, 17, 26
Non-compliance with GPAI obligations €15M or 3% global revenue Articles 53, 55
Providing incorrect information €7.5M or 1% global revenue Article 71 (authority requests)
Non-compliance with transparency obligations €7.5M or 1% global revenue Article 50 (limited-risk AI)

Important: “Global annual turnover” means worldwide revenue for the preceding financial year. For undertakings other than SMEs, Article 99 uses the higher applicable percentage or fixed ceiling. For SMEs, including startups, each fine must not exceed the lower applicable percentage or fixed ceiling. The authority still sets any actual fine under the Act’s criteria and the facts.[1]

Enforcement structure

The AI Act establishes a multi-layered enforcement architecture:

EU AI Office (Article 64)

Central coordination body within the European Commission responsible for GPAI model oversight, implementing acts, and cross-border enforcement coordination. Exclusive competence over systemic-risk GPAI models.

National competent authorities (Article 70)

Each member state must designate at least one authority to enforce the AI Act within its territory. National authorities have investigatory powers including access to training data, source code, and algorithms. May impose penalties per Article 99.

Notified bodies (Articles 31–39)

Independent third-party conformity assessment bodies designated by member states to conduct assessments of high-risk AI systems requiring external certification (e.g., biometric systems, medical devices). Must be accredited per ISO 17065.

European AI Board (Article 65)

Expert group consisting of national authorities promoting consistent application across member states, advising the Commission, and contributing to international AI governance cooperation.

Market surveillance powers (Article 74)

National authorities have extensive investigatory powers including:

  • Requesting access to all documentation and data demonstrating conformity
  • Requesting access to training, validation, and testing datasets
  • Requesting access to source code and algorithms (protected as confidential)
  • Requiring providers to take corrective action or withdraw systems from market

Member-state implementation, reviewed August 2026

The Act applies directly across the 27 member states, but each must designate national competent authorities (Article 70) and a single point of contact. The implementation picture remains uneven; the entries below are dated status summaries, not legal advice, with country deep dives linked.[17][18][19][20][21][22]

Country Competent authority Reviewed August 2026
Germany BNetzA (main MSA); BaFin (financial-sector high-risk); KoKIVO coordination centre Draft KI-MIG explicitly excludes BfDI. BfDI publishes AI/GDPR-interplay guidance.
France Decentralised: CNIL, ANSSI, sectoral regulators; PEReN technical support Multi-authority bill pending Parliament. ANSSI tasked with AI Act cybersecurity competences (Apr 2026).
Italy AgID (notifying); ACN (market surveillance, EU SPOC); Garante (data overlap) National AI Law No. 132/2025 in force October 2025. Implementing decrees due 10 Oct 2026.
Spain AESIA (national MSA, operational since June 2024) 16 detailed compliance guides published December 2025; sandbox running; draft national AI Law (March 2025).
Netherlands Hybrid 10-authority model led by AP; AP+RDI co-coordinate Public consultation on the proposed Implementation Act ran 20 April – 1 June 2026 and is closed. The ten-authority structure remains a proposal pending legislation.
Belgium BIPT (main MSA); GBA/APD on data; FAMHP, FSMA sectoral; 21 fundamental-rights bodies BIPT designated by 2025-2029 Federal Government Agreement; missed Aug 2025 governance deadline.
Poland KRiBSI (Commission for AI Development and Security) — single MSA model February 2026 draft confirms KRiBSI; operational support nested in Ministry of Digital Affairs. UODO disputes advisory-only role.

Compliance roadmap

Organizations should implement a phased approach aligned with system classification and the provision-specific calendar. Relevant Annex III high-risk duties apply from 2 December 2027 and relevant Annex I product-embedded duties from 2 August 2028.

GLACIS logoGLACIS
GLACIS framework

EU AI Act compliance roadmap

1

AI system inventory and risk classification

Catalog all AI systems across the organization. Classify each system using the Act’s categories and applicable Annex I or Annex III pathway. Identify provisions already applicable and systems with 2027 or 2028 high-risk dates. Document intended purpose, deployment context, and affected populations.

2

High-risk system prioritisation

For high-risk systems, assess current state against Articles 9-15 requirements. Identify gaps in risk management, data governance, logging, transparency, human oversight, and cybersecurity. Prioritize systems by business criticality and compliance gap severity. Determine which systems require notified body assessment vs. internal control.

3

Risk management system implementation

Establish continuous risk management per Article 9. Implement processes for identifying foreseeable risks, estimating harm likelihood and severity, evaluating post-market monitoring findings, and adopting mitigation measures. Document risk management activities per Annex IV technical documentation requirements. Integrate with existing ISO 42001 or NIST AI RMF frameworks where implemented.

4

Technical documentation and logging

Prepare the applicable Annex IV technical documentation. Implement automatic logging capabilities appropriate to the intended purpose and the Article 12 events that apply. Set proportionate access, integrity, and retention controls under the relevant rules. Pair logs with testing, routing, coverage, and source evidence; a log does not by itself prove that a control executed or was effective.

5

Quality management system and conformity assessment

Establish the applicable Article 17 quality-management system, covering compliance strategy, design controls, post-market monitoring, and corrective actions. For systems requiring notified-body assessment, begin engagement well before the applicable 2027 or 2028 date. For an internal-control pathway, prepare the required declaration of conformity and CE marking.

6

Post-market monitoring and continuous compliance (ongoing)

Implement the applicable post-market monitoring system, including relevant performance, incident, and feedback signals. Establish Article 73 serious-incident procedures, maintain required documentation, and update it as the system evolves. Conduct periodic reviews that assess ongoing compliance with the applicable Articles 9–15 duties and prepare for competent-authority requests.

Critical insight: Notified-body capacity is finite. Teams that begin classification and evidence work well ahead of the applicable 2027 or 2028 high-risk date reduce assessment bottlenecks, rushed implementations, and avoidable enforcement exposure.

GPAI provider roadmap

Foundation model providers faced the August 2, 2025 deadline. Immediate priorities include:

All GPAI models (Article 53)

  • Prepare technical documentation (Annex XI)
  • Document training data sources and compute
  • Publish copyright policy and training data summary
  • Provide downstream compliance documentation

Systemic-risk GPAI (Article 55)

  • Conduct model evaluation with adversarial testing
  • Assess and document systemic risks
  • Implement incident tracking and reporting
  • Establish cybersecurity protections

Frequently asked questions

Does the EU AI Act apply to US companies?

Potentially. The Act applies to providers placing AI systems or GPAI models on the Union market, deployers located in the Union, and providers or deployers outside the Union where output produced by the system is used in the Union, subject to the Act’s definitions and exclusions. Processing EU data alone is not the territorial trigger; classify the system, role, market activity, and output use.

How do I know if my AI system is high-risk?

Check if your system falls under Annex III categories: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration/asylum, or justice. Also check if it’s a safety component of a product covered by Annex I harmonization legislation (medical devices, machinery, etc.). If uncertain, document your risk assessment rationale—regulators may disagree with your classification.

What is a notified body and when do I need one?

Notified bodies are third-party conformity-assessment bodies designated under applicable EU law. Whether one is required depends on the system’s classification, the conformity-assessment route in Article 43, and any product-safety legislation that also applies. Confirm the route with qualified counsel and the relevant sector authority; the Act does not set a universal price or completion time.

Can I use ChatGPT or Claude in my high-risk AI system?

Potentially. Start with the exact model, system, intended purpose, and your role in the value chain. Using a GPAI model does not by itself determine whether you are a deployer or provider of a high-risk system; placing a system on the market under your name, changing its intended purpose, or making a substantial modification can change the analysis. Document the classification and obtain legal advice for the specific deployment.

How does the EU AI Act interact with GDPR?

The AI Act and GDPR can apply in parallel, but each has its own material and territorial scope. Where an in-scope AI system processes personal data in processing subject to GDPR, the responsible parties must analyze both regimes and their roles. Relevant overlaps can include data governance, transparency, lawful basis, automated decision-making, security, and rights handling.

What should I do if my AI system causes harm after August 2026?

Article 73 requires providers of high-risk AI systems to report immediately once a causal link or reasonable likelihood is established. The general outer limit is 15 days from awareness, reduced to 2 days for specified widespread or critical-infrastructure incidents and 10 days where a person has died. Build classification, notification, corrective-action, and documentation workflows around the applicable trigger and authority.

References

  1. [1] European Union. "Regulation (EU) 2024/1689 of the European Parliament and of the Council." Official Journal of the European Union, July 12, 2024. EUR-Lex 32024R1689
  2. [2] European Commission. "Questions and Answers: Artificial Intelligence Act." March 13, 2024. europa.eu
  3. [3] European Parliament. "EU AI Act: First Regulation on Artificial Intelligence." News release, March 13, 2024. europarl.europa.eu
  4. [4] European Parliament. "Artificial Intelligence Act: MEPs Adopt Landmark Law." Press release, March 13, 2024. europarl.europa.eu
  5. [5] European AI Office. "AI Office Governance Structure." European Commission, 2024. ec.europa.eu
  6. [6] NIST. "Artificial Intelligence Risk Management Framework (AI RMF 1.0)." January 2023. nist.gov
  7. [7] ISO/IEC. "ISO/IEC 42001:2023 Information Technology — Artificial Intelligence — Management System." December 2023. iso.org
  8. [8] European Commission. "Annexes to Regulation (EU) 2024/1689." EUR-Lex, July 12, 2024. EUR-Lex Annexes
  9. [9] Future of Life Institute. "EU Artificial Intelligence Act: Analysis and Recommendations." Policy report, 2024. futureoflife.org
  10. [10] Stanford HAI. "AI Index Report 2025." Stanford Human-Centered AI, March 2025. hai.stanford.edu
  11. [11] European Commission. "EU AI Act: Implementation Timeline and Milestones." Digital Strategy Portal, 2024. ec.europa.eu
  12. [12] European Commission. “AI Omnibus enters into force.” 27 July 2026. digital-strategy.ec.europa.eu
  13. [13] European Union. Consolidated Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. Current version 27 July 2026. EUR-Lex
  14. [14] European Union. Regulation (EU) 2026/1744 amending the AI Act. Official Journal, July 2026. EUR-Lex
  15. [15] European Commission. “The General-Purpose AI Code of Practice.” Digital Strategy Portal, register last updated 31 July 2026; accessed 26 August 2026. digital-strategy.ec.europa.eu
  16. [16] CEN-CENELEC. "Update on CEN and CENELEC’s Decision to Accelerate the Development of Standards for Artificial Intelligence." 23 October 2025. cencenelec.eu
  17. [17] Simmons & Simmons. "Germany’s Implementation Act for the EU AI Act (KI-MIG)." 2025. simmons-simmons.com
  18. [18] AI Regulation. "EU AI Act Implementation: France Still Without Designated National Competent Authorities." 2026. ai-regulation.com
  19. [19] IAPP. "Italy becomes first EU member state to pass an AI law." 2025. iapp.org
  20. [20] Stibbe. "Dutch proposal for AI supervision: hybrid cooperation between market supervisory authorities." 2026. stibbe.com
  21. [21] BIPT. "Application of the AI Act." Belgian Institute for Postal Services and Telecommunications. bipt.be
  22. [22] Blavatnik School of Government. "The AI Act’s enforcement gap: what Poland’s new regulator reveals about Europe’s challenge." 2026. bsg.ox.ac.uk
  23. [23] European Commission. “European AI Office.” Digital Strategy Portal, accessed June 2026. digital-strategy.ec.europa.eu
  24. [24] Inside Privacy. "Spain Issues Guidance Under the EU AI Act." December 2025. insideprivacy.com

From requirement to operating evidence

Start with one consequential workflow and a defined evidence boundary.

GLACIS can record which configured controls were evaluated and what they reported, then map those bounded records to review questions. The record does not by itself establish control effectiveness, complete coverage, or EU AI Act compliance.

Talk to us Talk to us

Related guides

Country implementation guides

Each EU member state is establishing its own national competent authority and implementation approach. These guides cover country-specific requirements:

Role-specific guides

EU AI Act compliance requires cross-functional collaboration. These guides provide tailored action plans for key stakeholders:

High-risk classification guides

Annex III of the EU AI Act lists specific high-risk use cases with enhanced requirements. These guides explain how to classify and comply:

Framework crosswalks

Map EU AI Act requirements against other compliance frameworks to identify overlaps and reduce duplicate effort: