EU AI Act
// Binding Regulation - The Global Benchmark
The EU AI Act is the first comprehensive AI statute anywhere and the template other regulators are adapting. It regulates by risk tier rather than technology, phases obligations through 2028, and reaches any provider or deployer touching the EU market regardless of where they build.
Key Highlights
What the Act actually demands, and when each phase bites.
- 01
The world's first comprehensive, binding horizontal AI law, with extraterritorial reach: it applies to any provider or deployer whose AI system is placed on the EU market or whose output is used inside the EU.
- 02
A four-tier risk model structures everything: prohibited practices, high-risk systems, transparency-risk systems (chatbots, synthetic content), and minimal-risk systems left unregulated.
- 03
Phased application: prohibitions and AI-literacy duties applied February 2025; general-purpose AI model rules August 2025; the general application date arrived August 2, 2026 with transparency and registration obligations.
- 04
The Digital Omnibus amendment (in force July 2026) deferred stand-alone high-risk obligations under Annex III to December 2, 2027, and product-embedded high-risk systems under Annex I to August 2, 2028. Deferral, not deletion: the underlying obligations are unchanged.
- 05
Two new prohibitions land December 2, 2026: systems generating non-consensual intimate imagery ("nudifier" apps) and child sexual abuse material.
- 06
High-risk providers must run a lifecycle risk management system, enforce training-data governance, maintain technical documentation and automatic logs (minimum six months retention), design human oversight, guarantee accuracy, robustness and cybersecurity, pass conformity assessment, and operate post-market monitoring with serious-incident reporting.
- 07
Transparency duties: people must be told when they interact with AI, and synthetic content must carry machine-readable marking.
- 08
Penalties scale to EUR 35 million or 7% of global annual turnover for prohibited practices - large enough to reprice entire product lines.
Action Items for Governance and Compliance
Six moves that put providers and deployers on the right side of every phase.
Build a living AI system inventory
A01Name an accountable owner per system and keep one central register covering intended purpose, model versions, downstream dependencies, and jurisdiction exposure.
Classify every system against Annex III use cases and the prohibited-practices list; register qualifying high-risk systems in the EU database before market placement.
Operate a lifecycle risk management file
A02Adopt a board-approved AI policy and a recurring risk-review cadence with documented sign-off at defined gates.
Maintain the continuous, iterative risk process required of high-risk providers, including residual-risk evaluation, acceptance decisions, and updates after every material change.
Enforce training and validation data governance
A03Assign dataset provenance and bias-examination responsibilities to data owners with review authority over new sources.
Document relevance, representativeness, and bias-mitigation measures for training, validation, and test sets to the standard examiners will expect in 2027.
Produce technical documentation and logs
A04Treat the technical file as a release criterion: no ship without current documentation, owned by engineering leadership.
Keep Annex IV technical documentation automatically generated where possible, and retain automatic event logs for at least six months.
Design human oversight into decision flows
A05Define oversight roles, escalation authority, and AI-literacy competency requirements across affected teams.
Implement oversight measures that let trained humans understand outputs, intervene, override, or halt operation - and evidence the usability of those controls.
Stand up post-market monitoring and incident reporting
A06Establish an incident taxonomy, severity thresholds, and a named regulator-liaison accountability before enforcement begins.
Operate a post-market monitoring plan proportionate to each system's risk and report serious incidents within mandated windows once Chapter III applies in December 2027.
Engineering Translation
How each obligation above maps onto delivery-pipeline capabilities.
>_Centralized system-of-record service cataloguing every model-backed feature with owner, purpose, risk tier, and release state.
>_Release gates that block deployments until risk files, evaluation results, and approvals are complete.
>_Structured, tamper-evident event logging with guaranteed retention windows wired into inference paths.
>_Human-in-the-loop approval steps embedded directly into consequential decision endpoints.
>_Content provenance tagging applied to generated media before it leaves your pipeline.
>_Continuous evaluation harnesses measuring bias, drift, and factuality feeding monitoring dashboards auditors can read.
Delivered as capabilities, not paperwork
Each obligation above is translated into product-level engineering capabilities. The underlying stack and internal tooling are intentionally abstracted here; they are covered in technical briefings.
Educational summary only. This is not legal advice. Confirm obligations with qualified counsel for your jurisdiction.
Get Ahead of the December 2027 High-Risk Deadline
Book a technical briefing to map your AI estate against EU AI Act tiers and encode the controls directly into your pipeline.