FRAMEWORKS

EU Artificial Intelligence Act (AI Act)

EU regulation establishing risk-based rules for AI systems covering development, market placement, and use, with obligations for providers and deployers of high-risk AI.

Section 01 · The regulation

What an EU AI Act audit has to determine

Regulation (EU) 2024/1689 sets harmonised rules for placing AI systems on the Union market and using them, together with a separate regime for general-purpose AI models. It entered into force on 1 August 2024 and was amended on 27 July 2026 by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which rescheduled several obligations and added others.

The Act regulates by risk and by role rather than by technology. Article 5 bans a defined set of practices outright. Article 6, read with Annexes I and III, identifies high-risk systems that carry the full compliance regime. Article 50 imposes transparency duties on certain systems regardless of risk class. Everything outside those categories is largely unregulated, which makes classification the decisive step rather than a formality.

Obligations attach to the role an organisation holds, and Article 3 defines six: provider, deployer, importer, distributor, authorised representative, and product manufacturer. The boundary is easier to cross than most organisations expect. Under Article 25, putting your own name or trademark on a high-risk system, modifying it substantially, or changing its intended purpose so that it becomes high-risk transfers the full set of provider obligations to you.

The penalty structure follows the same hierarchy. Breaching an Article 5 prohibition reaches EUR 35 million or 7% of total worldwide annual turnover, whichever is higher; other obligations reach EUR 15 million or 3%; supplying incorrect information reaches EUR 7.5 million or 1%. The Omnibus added capped tiers for smaller companies and room for non-monetary measures.

2024/1689
Regulation, as amended by 2026/1744
2 Dec 2027
Annex III high-risk obligations apply
2 Dec 2026
Two further Article 5 prohibitions apply
7%
Upper fine tier, global annual turnover
6
Regulated operator roles
What the Regulation actually enumerates

Classification is made against the text of the Regulation, not against a private taxonomy. Each cell represents one entry; point at a group to see the entries that decide most classifications. Counts reflect the Regulation as amended by Regulation (EU) 2026/1744.

Article 5 bans: eight since Feb 2025, two more from Dec 2026

10 of 31
  • Subliminal or purposefully manipulative techniques
  • Exploitation of vulnerabilities due to age or disability
  • Social scoring leading to unjustified detrimental treatment
  • Predicting criminal offences from profiling alone
  • Untargeted scraping of facial images for recognition databases
  • Emotion inference in the workplace and in education
  • Biometric categorisation to deduce sensitive attributes
  • Real-time remote biometric identification for law enforcement
  • Non-consensual intimate imagery — new, from 2 December 2026
  • AI-generated child sexual abuse material — new, from 2 December 2026
Section 02 · Readiness drivers

Why an EU AI Act audit starts with classification

Most organisations discover their AI Act position through someone else: a customer questionnaire asking which role they hold, a supplier that has added a model to an existing product without saying so, or a use case that turns out to sit squarely inside an Annex III area. Until role and risk class are settled, no obligation can be assigned an owner, a budget, or a deadline — which is why programmes that start with a policy rather than an inventory usually have to start again.

  1. 01 Role and risk classification Every other duty follows from it, and Article 25 can move an organisation into the provider role without a line of code changing. Strength 5 of 5
  2. 02 Deployment in an Annex III area Employment, credit, education and essential-service uses carry the full regime from 2 December 2027. Strength 4 of 5
  3. 03 Customer and procurement scrutiny Buyers ask for role classification, model provenance and oversight arrangements before signature. Strength 4 of 5
  4. 04 Opaque AI supply chain Vendor claims have to become contractual duties, deployment limits and change notifications. Strength 3 of 5
  5. 05 Penalty exposure Article 5 breaches reach 7% of worldwide turnover; most other breaches reach 3%. Strength 2 of 5
Indicative strength on a 1–5 scale, based on Up Secure engagement patterns.
Providers placing AI on the EU market

Developing a system, or rebranding and materially modifying one already on the market, brings the full provider regime including conformity assessment and registration.

Deployers using AI under their own authority

The prohibitions in Article 5 restrict use, not only supply, and the AI literacy duty in Article 4 has applied to every operator since February 2025.

Providers of general-purpose AI models

Chapter V obligations have applied since 2 August 2025, and models placed on the market before that date must be brought into compliance by 2 August 2027.

Section 03 · The timeline

Statutory application dates by role

These are the dates set by the Regulation itself, as amended by the Digital Omnibus on 27 July 2026 — not planning estimates. Select a role to see which tranche of obligations applies and when. Where the Omnibus deferred a date, it moved the deadline without reducing what has to be built by then.

Role Provider Span Aug 2024 – Aug 2028
  1. 01 Regulation enters into force Regulation (EU) 2024/1689
    1 Aug 2024
  2. 02 Prohibited practices and AI literacy Article 5 bans and the Article 4 AI literacy duty
    2 Feb 2025
  3. 03 Governance, penalties and GPAI rules Chapter V, notifying authorities and the penalty regime
    2 Aug 2025
  4. 04 General applicability Most remaining provisions, including Article 50 transparency
    2 Aug 2026
  5. 05 Two further Article 5 prohibitions Non-consensual intimate imagery and AI-generated CSAM
    2 Dec 2026
  6. 06 Annex III high-risk obligations Deferred from 2 Aug 2026 by Regulation (EU) 2026/1744
    2 Dec 2027
Entry into force Already applying Applying from 2026 Still to come
Role Product manufacturer Span Aug 2024 – Aug 2028
  1. 01 Regulation enters into force Regulation (EU) 2024/1689
    1 Aug 2024
  2. 02 Prohibited practices and AI literacy Applies regardless of product sector
    2 Feb 2025
  3. 03 Governance and penalties Notifying authorities and the penalty regime
    2 Aug 2025
  4. 04 General applicability Most remaining provisions become applicable
    2 Aug 2026
  5. 05 Annex I high-risk obligations Deferred from 2 Aug 2027 by Regulation (EU) 2026/1744
    2 Aug 2028
Entry into force Already applying Applying from 2026 Still to come
Role GPAI provider Span Aug 2024 – Aug 2028
  1. 01 Regulation enters into force Regulation (EU) 2024/1689
    1 Aug 2024
  2. 02 Prohibited practices and AI literacy Article 5 bans and the Article 4 AI literacy duty
    2 Feb 2025
  3. 03 GPAI model obligations Technical documentation, copyright policy and training-data summary
    2 Aug 2025
  4. 04 Systemic-risk model duties Model evaluation, adversarial testing and serious-incident reporting
    2 Aug 2025
  5. 05 Article 50 transparency Disclosure and marking duties across the value chain
    2 Aug 2026
  6. 06 Legacy models must comply Transitional deadline in Article 111(3) for models placed before 2 Aug 2025
    2 Aug 2027
Entry into force Already applying Applying from 2026 Still to come
Role Deployer Span Aug 2024 – Aug 2028
  1. 01 Regulation enters into force Regulation (EU) 2024/1689
    1 Aug 2024
  2. 02 Prohibited uses end Article 5 restricts use, not only supply
    2 Feb 2025
  3. 03 AI literacy duty Article 4: sufficient AI literacy among staff operating systems
    2 Feb 2025
  4. 04 Transparency towards affected people Article 50 disclosure for chatbots, deepfakes and synthetic content
    2 Aug 2026
  5. 05 Marking grace period ends Article 50(2) marking for systems already on the market before 2 Aug 2026
    2 Dec 2026
  6. 06 High-risk deployer duties Article 26 operating duties and the Article 27 fundamental rights impact assessment
    2 Dec 2027
Entry into force Already applying Applying from 2026 Still to come
Section 04 · How Up Secure helps

Where you will get supported

The areas we work in, and where each one falls across the readiness lifecycle. The services that deliver them are listed further down.

Areas of support across AI Act readiness
AI Act support by readiness stage
Area of support InventoryClassifyImplementMonitor
Advisory & leadership
AI governance operating model Covered during Inventory Covered during Classify Covered during Implement Covered during Monitor
Role and value-chain analysis Covered during Inventory Covered during Classify Covered during Implement Not covered during Monitor
Management reporting and escalation Not covered during Inventory Covered during Classify Covered during Implement Covered during Monitor
Assessment & assurance
AI use-case inventory Covered during Inventory Covered during Classify Not covered during Implement Not covered during Monitor
Risk classification against Annex III Covered during Inventory Covered during Classify Not covered during Implement Not covered during Monitor
Fundamental rights impact assessment Not covered during Inventory Covered during Classify Covered during Implement Not covered during Monitor
Supplier and model provenance review Covered during Inventory Covered during Classify Covered during Implement Covered during Monitor
Engineering & documentation
Technical documentation and logging Not covered during Inventory Covered during Classify Covered during Implement Covered during Monitor
Human oversight and control design Not covered during Inventory Covered during Classify Covered during Implement Covered during Monitor
Enablement & tooling
AI literacy and role-based training Not covered during Inventory Covered during Classify Covered during Implement Covered during Monitor
Section 05 · Related services

Services supporting AI Act readiness

The catalogue below is selected from the live service graph and grouped by area of expertise. Most engagements begin with inventory and role classification, because the applicable obligations — and therefore the cost of the programme — cannot be established before that.

Audits and Assessments

Systematic compliance audits, security assessments, and maturity evaluations across GDPR, ISO 27001, NIS 2, SOC 2, and AI Act frameworks for organizations in regulated industries.

AI System Privacy & Ethical Risk Audit

AI system audit covering data protection, ethical risks, bias assessment, and GDPR/AI Act compliance gaps.

AI ActISO 42001
Read more

AI Act Compliance Audit

EU AI Act compliance audit — risk classification, gap analysis, and conformity assessment for AI systems.

AI ActISO 42001
Read more

Consultancy and Advisory

Strategic consultancy and implementation advisory across GDPR, AI Act, ISO 27001, NIS 2, and cybersecurity for organizations building compliance programs or making security architecture decisions.

US Software Review for EU Regulatory Compliance

Review of US-built software against EU privacy and cybersecurity regulations — GDPR, NIS 2, and AI Act compliance.

AI ActNIS 2 DirectiveGDPR
Read more

Compliance and Risk Assessment Workshops

Compliance and risk assessment workshops — DPIA facilitation, risk analysis, and team capability building.

AI ActGDPR
Read more

AI Act Implementation Consultancy

AI Act implementation consulting — governance framework, policies, roles, and conformity roadmap for AI deployers.

AI ActISO 42001
Read more

Role Outsourcing

Dedicated specialist roles including DPO, Privacy Engineer, Security Engineer, vCISO, and AI Compliance Officer available on a fractional or full-time outsourced basis.

AI Security Officer

Outsourced AI Compliance Officer — AI Act oversight, risk monitoring, and governance coordination for AI deployers.

AI ActISO 42001
Read more
Start the conversation

Scope an AI Act engagement with people who have read the Regulation and the Omnibus that amended it.

The first conversation settles the two questions everything else depends on: which role you hold, and which of your systems fall inside Annex III. It produces an honest view of what applies before 2 December 2027 — and what does not apply at all, which is often the more valuable half.

Why Up Secure
Role before roadmap Article 25 can move you from deployer to provider without a line of code changing. That is settled first, because every obligation follows from it.
Current, not as-drafted Advice reflects Regulation (EU) 2026/1744, in force since 27 July 2026, rather than the original timetable that most published guidance still describes.
One inventory, three regimes The same records serve AI Act, GDPR and ISO 42001 work instead of being rebuilt for each.
Section 06 · Frequently asked

AI Act questions for product and compliance teams

Frequently asked questions

Was the AI Act delayed?
Partly. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It defers obligations for stand-alone high-risk systems under Annex III from 2 August 2026 to 2 December 2027, and for high-risk AI embedded in products under Annex I from 2 August 2027 to 2 August 2028. Nothing else was postponed: the prohibitions, the AI literacy duty, the general-purpose AI model obligations, the Article 50 transparency duties, and the governance and penalty provisions all continue to apply on their original dates.
What did the Omnibus add rather than delay?
Two new prohibitions enter Article 5 from 2 December 2026: AI systems that generate or manipulate non-consensual intimate imagery of an identifiable person, and systems that generate child sexual abuse material. Both sit in the top penalty tier of EUR 35 million or 7% of worldwide turnover. The amendment also gave the AI Office direct investigative powers, introduced simplified documentation and reduced fine caps for SMEs and small mid-caps, and moved the regulatory sandbox deadline to 2 August 2027.
When does a deployer become a provider?
Article 25 sets three triggers: putting your own name or trademark on a high-risk system already placed on the market, making a substantial modification to it, or changing its intended purpose so that a system not previously classified as high-risk becomes one. Any of these transfers the full provider obligations, including conformity assessment and registration. In practice this is the most commonly missed exposure, because rebranding a purchased tool feels commercial rather than regulatory.
What does an Annex III high-risk system actually require?
Articles 9 to 15 set seven requirements: a risk management system, data and data governance, technical documentation, record-keeping and logging, transparency and information for deployers, human oversight, and accuracy, robustness and cybersecurity. On top of those sit a quality management system, conformity assessment, registration in the EU database, and post-market monitoring. The December 2027 date is the deadline for having all of it in place, not for starting.
Do the transparency duties apply even outside the high-risk category?
Yes. Article 50 applies on the basis of what the system does rather than its risk class, and has applied since 2 August 2026. People must be told when they are interacting with an AI system, deepfakes must be labelled, and AI-generated text published to inform the public on matters of public interest must be disclosed. The machine-readable marking duty in Article 50(2) carries a grace period to 2 December 2026 for systems already on the market before 2 August 2026.
How do ISO 42001 and the GDPR relate to AI Act work?
They overlap without substituting for one another. ISO 42001 certifies a management system through its 38 Annex A controls and is credible evidence of governance maturity, but it is not a conformity assessment under the AI Act. The GDPR continues to apply wherever personal data is processed, and Article 22 on automated decisions and Article 35 impact assessments frequently cover the same systems as the AI Act. One inventory and one set of decision records can serve all three; running them separately tends to produce inconsistent answers about the same system.