Solutions

EU AI Act Readiness

Find out exactly what the AI Act requires of you — before you build the wrong thing.

Scope check, role determination, risk-tier classification and an obligation map with your real deadlines — a documented answer to “does the EU AI Act apply to us, and what do we owe?”

The most expensive AI Act mistake is answering the wrong question first

Most teams meet the AI Act backwards. They hear “high-risk obligations,” open Article 9, and start drafting a risk-management framework — for a system that may not be high-risk, under a role they may not hold, against a deadline that may not be theirs. Then an enterprise customer’s questionnaire, or a regulator’s inquiry, asks the questions that should have come first: Is this an AI system within the Act’s meaning? Are you its provider or its deployer? Which tier is it in? Which dates bind you?

Everything in the Act hangs off those four answers. Get them wrong and every downstream document is built on sand — confidently, expensively wrong. Get them right, documented, and most companies discover their obligations are narrower, later, or cheaper than they feared. And a minority discover the opposite in time to do something about it.

One more thing worth saying plainly, because the 2026 amendments confused it: the deadlines moved; the questions didn’t. The Digital Omnibus pushed the high-risk conformity dates out — it did not change whether your system is high-risk, and it did not quiet the customers, works councils and investors who ask about it long before any regulator will.

This assessment answers the four questions for your actual product, in writing, with the reasoning documented — the piece almost every team skips and the one everything else depends on.

Question 1 — Is it even in scope?

Not everything with a model in it is an “AI system” under the Act, and not every AI system is in scope. The Act’s definition turns on machine-based systems that operate with a degree of autonomy and infer from inputs how to generate outputs — and the Commission has published guidelines on that definition, because the boundary is genuinely contested at the edges (rule-based automation, classical statistics, simple scoring). There are carve-outs that matter in practice: activity outside the EU with no EU-market placement and no EU-used output, scientific research and pre-market development, certain free and open-source release scenarios, and — since the Omnibus — AI in products governed by the Machinery Regulation, which now takes its AI safety requirements through that regime instead.

And the reach cuts the other way too: the Act is extraterritorial. If you place a system on the EU market, or its output is used in the EU, it can apply regardless of where your company sits — and a non-EU provider of a high-risk system must appoint an authorised representative established in the EU before placing it on the market. We check both directions.

Question 2 — What role do you hold?

The Act assigns duties by role, and role is where careful companies get surprised. Provider (you develop it, or have it developed, and place it on the market under your name), deployer (you use it under your authority), importer, distributor, authorised representative — each carries a different obligation set, and one group can hold several roles at once across different systems.

The trap is Article 25: roles flip. Put your name or trademark on a system someone else built — you’re now its provider. Substantially modify a high-risk system — provider. Take a general-purpose system and repurpose it for a high-risk use — provider. White-labelling, fine-tuning and integration deals routinely move companies into provider obligations they never priced. We map every system you touch to the role you actually hold in it, entity by entity.

Question 3 — Which tier is it in?

Four tiers, wildly different consequences:

PROHIBITED

Article 5. Practices banned outright since February 2025 — with new prohibitions added by the Omnibus in 2026 (notably nudifier-style applications generating non-consensual intimate imagery). Penalties at the top of the Act’s scale: up to €35M or 7% of worldwide turnover. If anything you run is near this line, it’s the first thing to know.

HIGH-RISK

Article 6. Two routes in: AI as a safety component of products regulated under Annex I, or a use case listed in Annex III (employment, education, credit, biometrics, critical infrastructure, essential services and more — though not everything in those sectors qualifies). Two 2026 refinements matter for classification: the “safety component” definition was narrowed (assistance- and optimisation-only functions don’t qualify unless failure endangers health or safety), and the Commission’s draft Classification Guidelines add interpretive detail — including closer scrutiny of agentic systems.

TRANSPARENCY

Article 50. Live since 2 August 2026 for systems that interact with people, generate content, or run emotion recognition or biometric categorisation — regardless of risk class.

MINIMAL

Minimal risk. Most systems, most of the time. The value of classification is being able to prove that’s where you sit.

The Article 6(3) filter — handle with care. An Annex III use case can escape high-risk classification where the system doesn’t pose a significant risk to health, safety or fundamental rights — the Act names four grounds: a narrow procedural task, improving the result of a previously completed human activity, detecting decision patterns without replacing human assessment, or purely preparatory tasks. One hard exception: a system that profiles natural persons is high-risk regardless — no filter. Tempting — and now formalised: the Omnibus kept the duty to register that self-assessment in the EU database (the Commission proposed dropping it; Parliament and Council refused, though the information requirements were streamlined). Relying on 6(3) means a documented, reasoned assessment that sits in a public database and can be challenged — not an internal memo. We draft it to survive that.

Question 4 — Which dates actually bind you?

2 Feb 2025
LIVE

Prohibited practices; AI-literacy duty.

2 Aug 2025
LIVE

GPAI model obligations (models on the market before that date: full compliance by 2 Aug 2027).

2 Aug 2026
LIVE

Article 50 transparency (in-market systems: machine-readable marking by 2 Dec 2026).

2 Dec 2027
AHEAD

High-risk obligations for Annex III systems.

2 Aug 2028
AHEAD

High-risk obligations for Annex I product-embedded AI.

Your dates depend on your systems, roles and tiers — which is why the deliverable is an obligation map, not a generic timeline.

Where do you land? A first approximation

Select your role, see the typical obligation set

LIVE

Prohibited-practices screen & AI literacy everyone, since Feb 2025

LIVE

Article 50 transparency interaction disclosure, content marking, labels (since Aug 2026)

LIVE

GPAI documentation, copyright policy, training-content summary since Aug 2025; legacy models by Aug 2027

BEFORE MARKET

EU authorised representative required before placing a high-risk system on the EU market

DEC 2027

High-risk conformity (Annex III) Articles 9–17, conformity assessment, registration

IF RELIED ON

Article 6(3) assessment documented, reasoned, registered in the public EU database

DEC 2027

Deployer duties for high-risk systems use per instructions, oversight, logs, worker information; FRIA where required

WATCH

Article 25 role-flip risk rebranding, substantial modification, repurposing into high-risk use

A first approximation for orientation only — the assessment replaces this with your actual systems, roles and dates. Not legal advice.

What the 2026 Omnibus changed — and what it didn’t

The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026) is the first amendment to the Act. What moved: the high-risk dates above; Machinery Regulation products out of direct scope; the safety-component definition narrowed; Annex VIII registration information streamlined; the AI-literacy duty softened; and meaningful accommodations for SMEs and the new “small mid-cap” category — simplified technical documentation and proportionate quality-management requirements that can decide whether high-risk compliance is a rounding error or a quarter of your legal spend.

What didn’t move: the prohibitions (extended, in fact), GPAI obligations, Article 50, the Article 6(3) registration duty — and the classification questions themselves. Part of this assessment is telling you which side of each change you’re on.

What you get

A classification report you can hand to a board, an investor, or an enterprise customer running diligence:

System inventory

Every AI system you provide, deploy, import or resell, mapped.

Role determination

Per system and entity, with the Article 25 flip-risks flagged.

Tier classification with the reasoning documented

Including, where you rely on Article 6(3), an assessment drafted to registration standard.

Obligation map with your real dates

What applies now, what’s next, what the Omnibus moved for you specifically.

Gap analysis and a prioritised roadmap

Sequenced in plain language, deadline- and enforcement-risk items first.

And a clean handoff: the roadmap’s build items map one-to-one onto our AI Governance & Documentation service — same framework, no re-discovery, no paying twice for the same analysis.

Our approach

1

Intake

Tell us what your AI does and where it operates. A short structured intake, no long discovery call.

2

Scope check

Whether each system is an AI system within the Act’s meaning, and whether any carve-out applies.

3

Role determination

Provider, deployer, importer, distributor, representative — per system, per entity, flip-risks included.

4

Tier classification

Against Article 5, Annexes I and III, the 6(3) filter and the Commission’s guidelines — reasoning documented.

5

Obligation map and roadmap

Your duties, your dates, your sequence — with the report delivered in an agreed timeframe.

Who it’s for

AI-native startups and SaaS products adding AI features

That have never formally classified their systems — the step most teams skip and the one everything else depends on.

US and global teams selling into the EU

Extraterritorial scope plus the authorised-representative question answered in one pass.

Teams tempted by the Article 6(3) exemption

Who need an assessment that survives a public, challengeable database entry.

Companies mid-fundraise or mid-enterprise-deal

Where “are you AI Act compliant?” just appeared in a questionnaire and the honest current answer is “we don’t know.”

Deployers, not just builders

Banks, HR platforms, insurers using third-party AI, who carry their own duties and their own flip-risks.

Running autonomous agents in consumer funnels? That has its own lane → Compliance for AI Agents.

FAQ

Does the EU AI Act apply to companies outside the EU?

Often, yes. If you place an AI system on the EU market or its output is used in the EU, the Act can apply regardless of where you sit — and non-EU providers of high-risk systems must appoint an EU-established authorised representative before market placement. Both questions are part of the scope check.

The high-risk deadline moved to December 2027. Can we wait?

The conformity deadline moved; nothing about your classification did. Prohibitions, AI-literacy, GPAI duties and Article 50 transparency are already live, and customers ask classification questions today. Waiting also compresses the build: the high-risk artifacts are sequential, and December 2027 is closer than it looks for a company that hasn’t yet done step one.

How do I know if my AI is high-risk?

Two routes: safety components of Annex I products, or Annex III use cases — employment, education, credit, biometrics, critical infrastructure and others, though not everything in those sectors qualifies, and the 2026 changes narrowed the safety-component route. There’s also the Article 6(3) filter for narrow procedural uses — but relying on it now means a reasoned assessment registered in a public database. Classification with documented reasoning is exactly what this assessment produces.

We only use AI tools — we don’t build anything. Does this concern us?

Yes, twice over. Deployers carry their own obligations for high-risk systems (use per instructions, human oversight, logging, worker information). And deployers flip into providers more easily than expected — rebranding, substantial modification, or repurposing a system for high-risk use all trigger Article 25. The role map covers both.

We fine-tune an open model. Are we a GPAI provider?

Possibly — it depends on what you modify and how you place the result on the market. Fine-tuning and integration can create provider obligations at the system level, the model level, or both. This is one of the most common surprises in the assessment, and one of the most consequential.

What happens if something we run turns out to be prohibited?

You want to know that from us, not from a regulator — the Article 5 penalties reach €35M or 7% of worldwide turnover, and the list grew in 2026. If anything sits near the line, the report says so first and plots the redesign or shutdown path.

What’s the difference between this and your AI Governance service?

Sequence. Readiness tells you what you owe — scope, role, tier, dates — and hands you the roadmap. Governance & Documentation builds the artifacts the roadmap names. Most clients do them in that order; nobody should do them in reverse.

Find out what the AI Act means for your product

One structured intake. A classification report with the reasoning documented. A roadmap in plain language. Then — and only then — build.

Get a Readiness Assessment

Next steps: AI Governance & Documentation · Horizon regulatory-change monitoring

General information about the EU AI Act. It is not legal advice, and a readiness assessment is not a guarantee of compliance.