LinkedIn analytics tracking pixel for AIDOLS AI consulting website performance measurement

EU AI Act · Compliant-by-design

EU AI Act Compliance Consulting

The EU AI Act (Regulation (EU) 2024/1689) binds both providers and deployers — including non-EU firms whose AI output is used inside the EU. If you build, buy, or operate AI that touches the EU market, you are in scope. AIDOLS designs, builds, and deploys production AI that is compliant-by-design — mapped to the EU AI Act and NIST AI RMF with documented evidence, in a fixed-fee 90-day engagement backed by a 100% ROI guarantee.

Verified 28 July 2026 — reflects the Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026), which deferred the high-risk deadlines to December 2027 and August 2028. The transparency and 2025 obligations are unchanged.

What is the EU AI Act, and who must comply?

The EU AI Act is a binding, risk-based regulation that classifies AI systems by the harm they can cause and imposes obligations accordingly — from outright bans to full conformity assessment. It entered into force on 1 August 2024 and applies in phases through 2028. It is enforceable EU law, not a voluntary framework, with penalties comparable to GDPR. You are in scope if you are:

  • Providers — you develop an AI system or general-purpose AI (GPAI) model and place it on the EU market under your own name.
  • Deployers — you use an AI system under your authority in a professional capacity. Most enterprises buying AI are deployers, and deployers carry real obligations.
  • Importers, distributors, product manufacturers — you bring third-party AI into the EU or embed it in your products.
  • Non-EU firms — the Act applies extraterritorially: if the output of your AI system is used within the EU, you must comply. A Toronto, New York, or Singapore company with EU users or EU-facing outputs is covered.

The practical takeaway: “we don't have an EU office” is not an exemption.

EU AI Act risk tiers explained

The Act sorts every AI system into one of four risk tiers, and the tier determines your entire obligation set. Classify first; everything else follows.

Risk tierExamplesCore obligation
Unacceptable
(banned)
Social scoring; manipulative/exploitative systems; untargeted facial-image scraping; workplace/school emotion recognition; AI-generated non-consensual intimate imagery (“nudifier” apps, banned from Dec 2026); certain real-time remote biometric ID in public spacesProhibited — cannot be placed on the market or used
High riskCritical infrastructure, medical devices, recruitment/HR, credit & creditworthiness scoring, education/exam scoring, essential services, law enforcement, migration/border control; permitted emotion-recognition & biometric-categorisation systems (Annex III)Full regime — risk management, data governance, technical documentation, human oversight, logging, conformity assessment, registration, post-market monitoring
Limited riskChatbots and conversational agents; AI-generated or manipulated content (deepfakes)Transparency — users must be told they are interacting with, or viewing, AI (Article 50)
Minimal riskSpam filters, inventory optimisation, recommendation engines, AI in gamesNo mandatory obligations — voluntary codes encouraged

Most enterprise value — and most legal exposure — sits in the high-risk tier. GPAI models carry a separate, parallel obligation set (technical documentation, training-data summaries, copyright policy; plus model evaluation and incident reporting for models posing systemic risk).

EU AI Act timeline and deadlines (as of the Digital Omnibus)

The Act applies in staged waves. On 27 July 2026 the Digital Omnibus (Reg (EU) 2026/1744) deferred the high-risk deadlines — but left the transparency and 2025 duties untouched. The current schedule:

DatePhaseWhat applies
1 Aug 2024Entry into forceThe Regulation is legally in force; the compliance clock starts.
2 Feb 2025Prohibitions + AI literacyBans on unacceptable-risk practices apply; staff AI-literacy duty. Already in force.
2 Aug 2025GPAI + governance + penaltiesGPAI model obligations; governance bodies; the penalty regime. Already in force.
2 Aug 2026Transparency (Article 50)Disclosure duties for chatbots, deepfakes, and AI-generated content. The near-term deadline the Omnibus did NOT move.
2 Aug 2027Pre-2025 GPAI complianceGPAI models placed on the market before Aug 2025 must be brought into full compliance.
2 Dec 2027High-risk — Annex III (standalone)Recruitment, credit, critical infrastructure, education, essential-services AI. Deferred from Aug 2026 by the Digital Omnibus.
2 Aug 2028High-risk — Annex I (product-embedded)High-risk AI that is a safety component of a regulated product. Deferred from Aug 2027.

The Omnibus gave high-risk builders more runway — but it did not change the engineering reality: a conformity file, tamper-evident logging, and human-oversight design must exist in the system, and cannot be produced overnight. The extra time is for building compliance in, not deferring it.

What must high-risk AI providers and deployers actually do?

High-risk compliance is not paperwork bolted on at the end — it is a set of engineering and governance controls (Articles 9–15) designed into the system.

Provider checklist (high-risk):

  1. Risk management system — continuous, documented, lifecycle-wide.
  2. Data governance — relevant, representative, bias-examined datasets with documented provenance.
  3. Technical documentation — a complete conformity file, prepared before market placement.
  4. Record-keeping & logging — automatic, tamper-evident logging over the system's lifetime.
  5. Transparency & instructions for use — enable deployers to interpret output correctly.
  6. Human oversight — designed so humans can monitor, intervene, and override.
  7. Accuracy, robustness & cybersecurity — resilient to error, manipulation, and attack.
  8. Quality management system — documented policies and accountability.
  9. Conformity assessment & CE marking — before market entry.
  10. Registration — in the EU database before go-live.
  11. Post-market monitoring — ongoing, with a plan to act on findings.
  12. Serious-incident reporting — to the relevant authority.

Deployer checklist (high-risk):

  • Use the system per the provider's instructions; assign trained humans to oversight.
  • Monitor operation, suspend use if risks emerge, and report serious incidents.
  • Keep the automatically generated logs under your control.
  • Inform affected workers and, where required, conduct a fundamental-rights impact assessment before deployment.

The uncomfortable truth: you cannot reliably retrofit logging, oversight, and data governance into a black-box system a vendor did not design for it. Compliance has to be an architectural decision.

What are the EU AI Act penalties?

Fines reach the higher of €35 million or 7% of total worldwide annual turnover for prohibited-practice violations — a ceiling designed, like GDPR, to be felt at board level.

ViolationMaximum fine
Prohibited (unacceptable-risk) practices€35M or 7% of global turnover (higher)
Non-compliance with high-risk, transparency, or other obligations€15M or 3% (higher)
Misleading information to authorities€7.5M or 1% (higher)

For SMEs and start-ups the fine is capped at the lower of the fixed amount or the percentage. Beyond fines, non-compliant systems can be ordered off the market — often a bigger cost than the fine.

How AIDOLS makes your AI compliant-by-design

AIDOLS is an AI-native, engineering-first firm that ships working, compliant production systems — not slide decks. We treat EU AI Act conformity as an engineering property built in from day one, evidenced with documentation as we go.

  • The AI Governance Charter 2026. Every engagement is mapped to EU AI Act and NIST AI RMF requirements with documented evidence — risk classification, data-governance records, technical documentation, human-oversight design, and logging produced as the system is built.
  • Compliant-by-design 90-day builds. A small senior team (typically 3–5 engineers) designs, builds, and deploys a production system in 90 days with the Article 9–15 control set architected in, not appended.
  • Outcome accountability, not billed hours. The Build tier targets a 40%+ efficiency improvement and carries a 100% ROI guarantee: if it does not generate ROI exceeding its fee within 90 days, the fee is refunded in full.
  • Physical & industrial-AI depth. Through a signed-MOU consortium with WONTECH Worldwide and Polytechnique Montréal on an Agentic AI Asset Intelligence Platform, AIDOLS brings governance rigour to the hardest, most safety-critical AI domains.
TierInvestmentTimeframeOutcome
Sprint$15K–$25K2–3 weeksDiagnostic + risk-tier classification of your AI footprint (not a deployed system)
Build$75K–$150K90 daysA compliant-by-design production system, 100% ROI guarantee
Scale$25K/monthOngoingOperation, monitoring & post-market obligations, prorated-refund guarantee

Next: our governance evidence model · assess your maturity · how fixed-fee works

Know exactly which obligations apply to you

A Sprint classifies your full AI footprint by risk tier and maps the obligations in 2–3 weeks — so you build compliance in, not scramble for it later.

Book a call →

Frequently asked questions

Does the EU AI Act apply to non-EU companies?

Yes. The EU AI Act applies extraterritorially to any provider or deployer whose AI system's output is used in the EU, regardless of where the company is located. A firm headquartered in Toronto, New York, or anywhere else is in scope if EU residents use its AI or its AI-generated outputs are consumed in the EU. Having no EU office is not an exemption.

What is the difference between a provider and a deployer under the EU AI Act?

A provider develops an AI system or GPAI model and places it on the EU market under its own name, while a deployer uses an AI system under its authority in a professional capacity. Both carry obligations. Most enterprises buying AI are deployers and must ensure human oversight, monitor operation, keep logs, and — in some cases — conduct a fundamental-rights impact assessment.

What are the EU AI Act deadlines in 2026 and 2027?

As of the Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026), the pivotal 2 August 2026 deadline is the Article 50 transparency duty — disclosure for chatbots, deepfakes, and AI-generated content. The high-risk obligations originally due in August 2026 were deferred: standalone high-risk systems (Annex III) now apply from 2 December 2027, and high-risk AI embedded in regulated products (Annex I) from 2 August 2028. The February 2025 prohibitions/AI-literacy and August 2025 GPAI/governance rules already apply.

What are the penalties for violating the EU AI Act?

Penalties reach the higher of €35 million or 7% of global annual turnover for prohibited-practice violations. Other breaches, including high-risk and transparency failures, carry fines up to €15 million or 3% of turnover, and supplying misleading information to authorities up to €7.5 million or 1%. Non-compliant systems can also be ordered off the market.

How do I know if my AI system is high-risk under the EU AI Act?

Your system is high-risk if it falls within the Act's defined categories — including AI used in recruitment and HR, credit and creditworthiness assessment, critical infrastructure, medical devices, education scoring, essential services, law enforcement, or migration — or if it is a safety component of a regulated product. AIDOLS' Sprint engagement classifies your full AI footprint by risk tier in 2–3 weeks so you know exactly which obligations apply.

How do I comply with the EU AI Act?

Comply by first classifying each AI system by risk tier, then implementing the tier's obligations — for high-risk systems, that means a risk management system, data governance, technical documentation, logging, human oversight, robustness and cybersecurity, conformity assessment, registration, and post-market monitoring. AIDOLS builds these controls into the system by design and documents evidence against both the EU AI Act and NIST AI RMF as the system is engineered.

Can EU AI Act compliance be built into an AI system instead of added afterward?

Yes, and it should be. Logging, human oversight, and data governance cannot be reliably retrofitted into a black-box system, which is why AIDOLS architects EU AI Act controls into the system from day one under its AI Governance Charter 2026. Compliant-by-design engineering produces the conformity file as a by-product of the build, not a post-hoc scramble.

Why choose AIDOLS for EU AI Act compliance consulting?

AIDOLS is an AI-native, engineering-first firm that deploys compliant production AI in a fixed-fee 90 days, backed by a 100% ROI guarantee — you get a working, compliant system and a measurable return, or the fee is refunded. Unlike advisory firms that deliver reports, AIDOLS ships systems with EU AI Act and NIST AI RMF evidence documented throughout, targeting a 40%+ efficiency improvement.