EU Artificial Intelligence Act: AI Compliance Requirements
Regulation (EU) 2024/1689 — the world's first comprehensive AI law. Classifies AI systems by risk: prohibited (social scoring, subliminal manipulation), high-risk (Annex III: HR, credit, education, critical infrastructure, law enforcement), limited-risk (transparency obligations for chatbots and deepfakes), minimal-risk (most AI tools). Providers AND deployers have obligations. Extraterritorial: applies when the AI system's output is used in the EU regardless of provider location. TIMELINE UPDATE (Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026): the Annex III stand-alone high-risk obligations are deferred from 2 Aug 2026 to 2 Dec 2027 and the Annex I product-embedded high-risk obligations from 2 Aug 2027 to 2 Aug 2028; the already-live prohibited-practice (Feb 2025) and GPAI (Aug 2025) obligations were unchanged, and the Art. 50 transparency obligations took effect as scheduled on 2 Aug 2026 (the Art. 50(2) marking duty for AI systems placed on the market before 2 Aug 2026 has a grace period to 2 Dec 2026).
Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.
Key Facts
August 1, 2024
August 2, 2026
€35,000,000 or 7% of global annual turnover (whichever higher) for prohibited AI; €15M or 3% for high-risk violations; €7.5M or 1% for incorrect information to authorities
What Your Business Must Do
10 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.
AI Risk Classification
CriticalClassify each AI system you use or deploy as Minimal, Limited, High, or Unacceptable risk under EU AI Act Annex III. High-risk categories: biometric systems, critical infrastructure, education/vocational training, employment/HR, essential services (credit, insurance), law enforcement, migration/asylum, administration of justice. Annex III high-risk obligations were deferred from 2 Aug 2026 to 2 Dec 2027 by the Digital Omnibus (Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026).
Deadline: December 2, 2027
Art. 6, Annex IIIConformity Assessment (High-Risk)
CriticalProviders of Annex III high-risk AI systems must conduct conformity assessment before placing on market. Most systems: self-assessment via internal checks. Biometric and critical infrastructure: third-party assessment required. Annex III high-risk obligations were deferred from 2 Aug 2026 to 2 Dec 2027 by the Digital Omnibus (Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026, in force 27 July 2026).
Deadline: December 2, 2027
Art. 43, Annex VIProhibited: Non-Consensual Intimate Imagery & CSAM-Generation AI
CriticalDigital Omnibus amendment (Regulation (EU) 2026/1744) added two new Art. 5(1) prohibited practices, effective 2 Dec 2026: (ba) placing on market, putting into service, or using AI systems that generate or manipulate realistic depictions of an identifiable person's intimate body parts or sexually explicit activity without that person's freely-given, specific, informed, unambiguous, and explicit consent (targets "nudifier" apps); (bb) AI systems designed to generate child sexual abuse material, subject to narrow law-enforcement/crime-prevention/compliance-red-teaming exceptions. Providers are banned if generation/manipulation is the intended purpose OR a reasonably foreseeable outcome absent adequate technical safeguards (data cleaning, refusal training, content filtering, abuse detection); deployers are banned only for actual use to generate prohibited material.
Deadline: December 2, 2026
Art. 5(1)(ba), Art. 5(1)(bb) (inserted by Regulation (EU) 2026/1744)Transparency Disclosures
High PriorityInform users when they are interacting with AI (chatbots, generated content, AI-assisted decisions). Deepfake content must be labeled. AI chatbots must identify themselves. Cannot deploy AI that impersonates humans without disclosure.
Deadline: August 2, 2026
Art. 50AI Acceptable Use Policy
High PriorityDocument how employees may and may not use AI tools within your organization. Required for deployers of high-risk systems. Must include authorized uses, restrictions, human oversight requirements, and escalation procedures.
Deadline: December 2, 2027
Art. 4, Art. 26Employee AI Monitoring Notice
High PriorityNotify employees if AI systems are used to monitor their work performance or productivity. Covers AI-assisted performance management, productivity scoring, and automated scheduling. Must be clear, written notice before deployment. Art. 26(7): before putting into service or using a high-risk AI system at the workplace, deployers who are employers must inform workers' representatives and the affected workers. As an Art. 26 high-risk deployer obligation this follows the Digital Omnibus deferral to 2 Dec 2027.
Deadline: December 2, 2027
Art. 26(7)Technical Documentation (Annex IV)
High PriorityProviders of high-risk AI systems must maintain Annex IV technical documentation: system description, development methodology, training data summary, testing procedures, accuracy metrics, post-market monitoring plan.
Deadline: December 2, 2027
Art. 11, Annex IVRecord Keeping & Logging
High PriorityDeployers of high-risk AI must keep logs for minimum 6 months. Providers must keep technical documentation for 10 years. Logs must enable reconstruction of circumstances leading to any incident.
Deadline: December 2, 2027
Art. 12, Art. 18, Art. 19, Art. 26(6)Human Oversight Procedures
Medium PriorityImplement procedures ensuring human review of high-risk AI decisions. Must document how humans can intervene, override, or halt the AI system. Human oversight must be technically possible and operationally implemented — a nominal checkbox does not suffice.
Deadline: December 2, 2027
Art. 14, Art. 26(1)-(2)GPAI Model Obligations
Medium PriorityGeneral Purpose AI (GPAI) model providers must publish technical documentation, maintain copyright compliance policy, and train providers who use their models. Systemic risk GPAI (>10^25 FLOPs training compute) have additional obligations: adversarial testing, serious incident reporting, cybersecurity measures.
Deadline: August 2, 2025
Art. 51-56Who Does This Apply To?
Applies to: (1) providers placing AI systems on EU market or putting into service, (2) deployers using AI systems within EU, (3) providers/deployers in third countries when output used in EU, (4) importers and distributors of AI systems. Exemptions: AI for military/national security, AI used solely for scientific research, open-source models (partial). SMB deployers using third-party AI tools (e.g., ChatGPT, Copilot) are "deployers" — must comply with Annex III obligations when using AI for HR decisions, credit assessments, or customer profiling.
Recent Enforcement Actions
Against: Clearview AI
CNIL fined Clearview AI €20,000,000 under GDPR (not the EU AI Act, which had no applicable prohibition provisions in force until Feb 2025) for unlawful biometric scraping and disregard of data-subject rights, plus a €5,200,000 periodic penalty (2023-04-13) for non-compliance with the deletion order. No EU AI Office action and no formal "EU market ban" exist on the public record — see the caseCitations entry below for the full corrected history (R133).
SourceAgainst: Meta
Meta publicly declined to sign the GPAI Code of Practice (Joel Kaplan statement), meaning Meta's LLaMA models get no rebuttable-compliance presumption under Art. 51-56 and are assessed directly against the statute. ~24 organizations (Amazon, Anthropic, Google, IBM, Microsoft, Mistral AI, Aleph Alpha, among others) had signed by June 2026.
SourceRecent Regulatory Guidance
EU AI Office GPAI Code of Practice (Final)
AI Office published the final GPAI Code of Practice covering transparency, copyright, and safety for general-purpose AI providers. Participation voluntary but creates safe harbor for Art. 51-56 compliance. Key requirement: model cards with capability disclosures, capability thresholds for enhanced red-teaming.
SourceCommission Guidance: Deployer Obligations for Third-Party AI Tools
Commission clarified that companies using ChatGPT Enterprise, Microsoft Copilot, or similar third-party AI tools for employment decisions are "deployers" under Art. 22(1) and must conduct their own fundamental rights impact assessment. Vendor contracts providing AI access do not transfer deployer liability to the provider.
SourceEDPB Opinion 28/2024 — Personal Data in AI Models (legal basis for training)
EDPB Opinion 28/2024 (adopted 17 Dec 2024, at the Irish DPC's request) addresses processing personal data when developing/deploying AI models: an AI model trained on personal data is not automatically "anonymous" (case-by-case test), and a controller may rely on legitimate interest for AI-model development/deployment only after the full three-part balancing test — it does not apply automatically. Note: the Opinion expressly excluded automated decision-making/Art. 22, profiling and DPIAs from its scope.
SourceEU AI Office: Q&A on Annex III Scope for HR AI Tools
AI Office Q&A confirmed that AI tools used for candidate screening, employee scheduling optimization, and performance monitoring meet the Annex III high-risk threshold. "Substantially assisting" a consequential HR decision — even with human final sign-off — qualifies as high-risk AI.
SourceKey Case Law & Precedent
CNIL v. Clearview AI
French CNIL (Commission Nationale de l'Informatique et des Libertés) · 2022A GDPR action, NOT an EU AI Act action (Art. 5 biometric-surveillance prohibitions became applicable Feb 2025 and have no enforcement on record as of this entry). The CNIL found Clearview's scraping of facial images and biometric processing had no legal basis (GDPR Art. 6) and disregarded data-subject rights (Arts. 12, 15, 17), and ordered deletion of French residents' data. Establishes that scraping facial images to build a recognition database is unlawful biometric processing under EU data-protection law — a relevant precedent for any biometric-AI deployer, but under the GDPR, not the AI Act.
Outcome: IMPOSED: €20,000,000 GDPR fine (17 Oct 2022) plus a €5,200,000 periodic penalty (13 Apr 2023) for failure to comply with the deletion order. No EU AI Act penalty and no "EU market ban" exist — those framings were corrected as fabricated (Round 133).
Case referenceLoomis v. Wisconsin (Referenced in EU guidance)
Wisconsin Supreme Court → EU guidance context · 2016US case (COMPAS recidivism AI) cited in EU AI Office guidance as example of high-risk AI in justice sector requiring human oversight under Art. 14. Established that opaque AI scoring in consequential decisions raises due process concerns even without explicit bias finding.
Outcome: Referenced in EU Art. 14 human oversight guidance
Case referenceQuarterly Enforcement Digest
Q3 2026 update: Commission published deployer guidance clarifying third-party AI tool liability. EDPB Opinion 28/2024 confirmed AI-model training on personal data needs its own GDPR legal basis (legitimate interest is not automatic). Cycle 8 (2026-08-22) correction: removed two uncorroborated "EU AI Office formal inquiry" claims against OpenAI and Meta that had no independent source and were procedurally impossible as dated (GPAI enforcement powers only became legally active 2026-08-02); the real, verified fact is that Meta declined to sign the GPAI Code of Practice (2025-07-18) while ~24 other organizations signed. The Clearview AI enforcementActions entry was also corrected to match this entry's own already-corrected caseCitations record — it is a 2022 CNIL GDPR fine, not an EU AI Act/AI Office action, and no "EU market ban" exists on the public record.
Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.
Industry Playbooks covering EU Artificial Intelligence Act
These industry playbooks include jurisdiction-specific checklist items and guidance for EU Artificial Intelligence Act.
Frequently Asked Questions
Does EU Artificial Intelligence Act apply to my business?
Regulation (EU) 2024/1689 — the world's first comprehensive AI law. Classifies AI systems by risk: prohibited (social scoring, subliminal manipulation), high-risk (Annex III: HR, credit, education, critical infrastructure, law enforcement),… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.
What is the penalty for non-compliance?
The maximum penalty under EU Artificial Intelligence Act is: €35,000,000 or 7% of global annual turnover (whichever higher) for prohibited AI; €15M or 3% for high-risk violations; €7.5M or 1% for incorrect information to authorities. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.
How do I comply with EU Artificial Intelligence Act?
The 10 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.
Official Source
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689Last updated: 2026-08-22 — verify at source before relying on this information.
Don't leave compliance to chance
Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.
Start your free compliance scan