Updated August 5, 2026. The EU AI Act's implementation timeline is still moving, so we'll keep updating this page as new deadlines and guidance are confirmed.
TL;DR: EU AI Act compliance is a rolling set of obligations, not a single deadline, and several are already in force. This guide breaks down what applies today, what high-risk AI systems must do to comply, and the practical steps to take now, including how to make your training data and model evaluation process defensible if a regulator asks who built it and under what oversight.
Most companies we talk to know the EU AI Act applies to them in theory but haven't worked through what that means for a specific system they've already deployed. Which is understandable, considering the Act asks for things that take time to build, like being able to show who trained your model, under what credentials, and with what oversight, and those aren't answers you want to be assembling for the first time when a regulator asks. This guide is meant to demystify the EU Act. We'll share what's enforceable today, what a high-risk system is and what it needs to hold up, and where to put your effort first.
What the EU Act actually is
EU AI Act compliance starts with knowing where your systems fall among four risk tiers: unacceptable, high, limited, and minimal. Unacceptable-risk practices, such as social scoring or manipulative subliminal techniques, are banned outright. The Act applies strongest to companies that fall into the high-risk systems category.
Going deeper on high-risk systems
Most compliance work under the Act comes down to whether a system counts as high-risk, and getting that classification right is its own process. Our companion guide breaks down the two paths to high-risk status, what falls under Annex III, and how to document your reasoning either way. Read: what is a high-risk AI system under the EU AI Act?
High-risk systems can still operate, but they carry a series of obligations: documented risk management, documented data governance, technical documentation, and human oversight built into the system before it goes live. If your system doesn't fall into high-risk territory, you're not off the hook. You need to document the assessment as part of the compliance process.
For a Head of AI or a COO at a growth-stage company, the practical question is rarely "does the law apply to us." Most companies running hiring tools, performance evaluation software, or any AI that touches credit, insurance, or biometric data already have at least one system in scope. The real question is whether that system's documentation would survive a regulator's review today, and for most companies, it would not yet.
What's already enforceable
If you have been putting off EU AI Act compliance because the big deadline felt distant, most of it already applies now. This is the part of the EU AI Act news cycle that tends to get lost.
Since February 2, 2025, prohibited AI practices and baseline AI literacy obligations have been in force. Since August 2, 2025, the governance rules and obligations for general-purpose AI (GPAI) models have applied, including the requirement for GPAI providers to publish training data summaries and comply with copyright disclosure rules. And since August 2, 2026, Article 50 transparency obligations have applied too, covering disclosure requirements for chatbots, deepfakes, and AI-generated content. These apply broadly, not just to high-risk systems.
High-risk obligations under Annex III, the category covering hiring tools, credit scoring, and similar stand-alone use cases, were also originally set to apply from August 2, 2026. That deadline moved: the EU formally adopted the Digital Omnibus on AI in June 2026, pushing Annex III obligations to December 2, 2027, and Annex I obligations to August 2, 2028. For the full status of that timeline shift and what it means for your compliance planning, see our companion piece on what is a high-risk AI system under the EU AI Act.
What high-risk AI systems must comply with
This is where the compliance requirements get specific, and where most of the practical work begins.
High-risk systems need a documented risk management system covering the system's full lifecycle. They need technical documentation detailed enough for a regulator to assess compliance without reverse-engineering the model. They need automatic logging that records events relevant to identifying problems after deployment. They need to be designed so a human can exercise oversight over what the model outputs, with the authority to challenge or override it.
Then there is Article 10, on data and data governance. This is the requirement most companies underestimate. Training, validation, and testing data must be relevant, sufficiently representative, and as free of errors as possible for the system's intended purpose. Data governance practices have to address design choices, collection, preparation, labeling, and bias examination, and that documentation has to name how the data was produced, including who did the work and under what process.
A regulator is not just going to ask what data trained your model. They are going to ask who labeled it, under what credentials, with what oversight, and how you tested for bias. Anonymous crowd annotation, sourced through a platform with no visibility into who did the work, does not hold up under that standard. Credentialed domain experts who can be re-engaged, and whose outputs are documented and traceable, do.
Beyond documentation, most high-risk systems also need a conformity assessment, a formal check confirming the system meets the Act's requirements, before deployment, plus registration in the EU's public database for high-risk AI systems. It's easy to assume that concluding your system is exempt means there's nothing left to file. In practice, the Act still requires you to document that conclusion and complete a simplified registration step. Skipping it entirely isn't an option, even with a documented exemption.
Here's how all of these requirements map against who they apply to and when they take effect.
Key requirements at a glance
| Requirement | Who it applies to | Effective date |
| Risk management system | Providers of high-risk AI systems | Dec 2, 2027 (Annex III stand-alone systems); Aug 2, 2028 (Annex I embedded systems) |
| Data governance (Article 10) | Providers of high-risk AI systems that use trained models | Dec 2, 2027 (Annex III); Aug 2, 2028 (Annex I) |
| Technical documentation | Providers of high-risk AI systems | Dec 2, 2027 (Annex III); Aug 2, 2028 (Annex I) |
| Record-keeping and automatic logging | Providers of high-risk AI systems | Dec 2, 2027 (Annex III); Aug 2, 2028 (Annex I) |
| Human oversight | Providers and deployers of high-risk AI systems | Dec 2, 2027 (Annex III); Aug 2, 2028 (Annex I) |
| Transparency (Article 50) | Providers and deployers of chatbots, deepfakes, and AI-generated content | Aug 2, 2026 for general disclosure obligations; Dec 2, 2026 for AI-content marking on systems already on the market |
| Registration in the EU database | Providers of high-risk AI systems, including those claiming an exemption | Dec 2, 2027 (Annex III); Aug 2, 2028 (Annex I) |
| Penalties framework (Article 99) | All operators in scope of the Act | In force since Aug 2, 2025; fines apply once the corresponding obligation becomes enforceable |
How this compares to US AI regulation
Companies operating in both markets benefit from seeing the contrast plainly. The EU AI Act is a single, binding, risk-tiered framework with fixed obligations and fixed penalties, and a timeline that's now settled after this summer's Digital Omnibus update. The United States has no equivalent federal law. What exists instead is a patchwork of executive orders, sector rules from agencies like the FTC and EEOC, and a growing list of state laws, including New York City's Local Law 144 and Illinois's HB 3773.
That difference changes how compliance work gets prioritized. In the EU, the work is mapping your systems against one law's categories and deadlines. In the US, it is tracking several fronts at once, since a change in federal enforcement priorities does not touch state-level obligations, and vice versa. For the full breakdown of what applies where and when, see our companion piece on US AI regulations.
What your business should do now
The delay in the Annex III deadline gives you runway. Regulators have said the extra time exists to support the harmonized standards still being finalized, and companies still need to do the underlying work within that window.
- Inventory every AI system you use or deploy, including purchased tools, not just ones you built in-house. The Act's rules apply whether you built the system, making you a "provider," or you're simply the company using it, making you a "deployer." The Act's obligations can apply to either role.
- Classify each system by risk tier, and document that assessment even if you conclude a system is not high-risk. That documentation is itself a requirement.
- Build data governance and provenance records now. If you cannot say today who annotated your training data and under what process, keep in mind that that gap takes time to close, and it only gets harder to reconstruct the longer you wait.
- Identify where human oversight is thin. A model reviewed by a narrow, homogeneous team is harder to defend as “free of bias”, and that gap will be highly apparent in your Article 10 documentation.
- Confirm your registration status, even for systems you believe are exempt from high-risk classification.
- Use the runway deliberately. December 2027 and August 2028 sound like a long way from now, but the standards and conformity assessment infrastructure the Act depends on are still catching up. So, don’t focus so much on the deadlines themselves, and shift your attention to building high quality documentation.
Most of this work comes down to one thing: knowing who touched your data and being able to prove it.
How PowerToFly AI helps
When we talk to clients about the EU AI Act, we point them straight to the data governance and human oversight requirements, because that's where credentialed, representative review teams matter most. We connect companies with domain-qualified professionals across our network of 380K+ experts for model evaluation, bias testing, and annotation work, so every dataset comes with a documented, traceable record of who built it and under what qualifications. That's the difference between a data pipeline that looks compliant and one built to hold up under real regulatory scrutiny.
See how PowerToFly's domain experts provide auditable training data and model evaluation that meets EU AI Act standards.
FAQ
What is the EU AI Act?
The EU AI Act is the European Union's risk-based framework for regulating AI systems. It sorts systems into four tiers, unacceptable, high, limited, and minimal risk, and applies escalating obligations based on that classification.
What is a high-risk AI system?
A high-risk AI system either serves as a safety component in an already-regulated product, such as a medical device, or falls into one of the specific high-risk use cases the Act lists, known as Annex III, including hiring, credit scoring, biometric identification, and law enforcement tools.
What is the Digital Omnibus on AI?
The Digital Omnibus on AI is the EU's legislative package simplifying the AI Act's rollout. Adopted by Parliament and Council in June 2026, its most significant change delays high-risk obligations under Annex III to December 2, 2027, and Annex I to August 2, 2028.
What does the EU AI Act require for training data?
Under Article 10, training, validation, and testing data for high-risk systems must be relevant, sufficiently representative, and as free of errors as possible. Companies must document how the data was collected, prepared, labeled, and examined for bias.
What happens if a company doesn't comply?
Penalties depend on the violation. Breaches of most high-risk obligations, including Article 10 data governance, can reach 15 million euros or three percent of global annual turnover, whichever is higher.
Does the EU AI Act apply to companies outside the EU?
Yes. It applies to any company placing an AI system on the EU market or putting one into service there, and to companies based elsewhere if the system's output is used within the EU.