EuroComply
Free assessment
EU AI Act GuideHigh-risk regime from Aug 2026

EU AI Act Compliance for Tech Companies

Regulation (EU) 2024/1689 is the first comprehensive AI law. Here is what any company building or deploying AI in the EU must know: the four risk tiers, the obligations, the deadlines, and the fines.

Applies extraterritorially
Providers and deployers
Up to €35M or 7% turnover

Overview

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It entered into force on 1 August 2024 and applies a risk-based approach: the more an AI system can affect people's safety or fundamental rights, the more obligations apply to it.

The most important thing for founders and engineering teams outside the EU: the Act has extraterritorial reach. If your AI system is placed on the EU market or its output is used by people in the EU, the Act applies to you, whether you are based in San Francisco, London, or Bangalore.

In force since

1 Aug 2024

Full regime from

2 Aug 2026

Applies to

Providers + deployers

Covers

EU market + EU users

Timeline

The phased rollout

The AI Act does not apply all at once. Obligations phase in over two years:

Aug 2024

Entry into force

Regulation (EU) 2024/1689 becomes law across the EU.

Feb 2025

Prohibited practices banned

Article 5 practices, social scoring, manipulative systems, real-time biometric ID in public, become illegal.

Aug 2025

GPAI obligations apply

General-purpose AI model providers face transparency and copyright-related duties.

Aug 2026

Full high-risk regime

Conformity assessment, technical documentation, and EU database registration required for Annex III systems.

Scope

Who must comply?

The Act assigns different obligations to different roles in the AI supply chain:

Providers

Companies that develop an AI system or general-purpose AI model and place it on the EU market, under their own name or trademark. Carry the heaviest compliance burden for high-risk systems.

Deployers

Any organisation using an AI system under its authority in a professional context, including companies that integrate a third-party AI system into their product or internal process.

Importers and distributors

Must verify the provider has completed the required conformity procedures before making the system available in the EU.

Authorised representatives

Non-EU providers of high-risk systems must appoint an EU-based authorised representative, similar to the GPSR responsible person requirement.

Requirements

The core compliance checklist

Not every item applies to every system: the exact list depends on your risk tier. This is the full set a high-risk provider needs to work through.

1. Risk classification

High priority

Determine whether your system is prohibited, high-risk, limited-risk, or minimal-risk based on its purpose, sector, and the people it affects.

2. Technical documentation

High priority

For high-risk systems: a complete technical file describing the system, its intended purpose, architecture, and development process (Art. 11).

3. Risk management system

High priority

A continuous process to identify, estimate, and mitigate foreseeable risks to health, safety, and fundamental rights across the system lifecycle (Art. 9).

4. Human oversight

High-risk systems must let a person interpret outputs, intervene, and override or stop the system (Art. 14).

5. Data governance

Document how training, validation, and testing datasets were selected and checked for bias (Art. 10).

6. Transparency to users

Consumer-facing chatbots, recommenders, and generated content must disclose that users are interacting with AI (Art. 50).

7. Conformity assessment + EU registration

High-risk systems need a conformity assessment, an EU Declaration of Conformity, and registration in the public EU database before going live (Art. 43, 47, 49).

Enforcement

Fines by violation type

Fines scale with the severity of the breach and are capped at the higher of the fixed amount or the turnover percentage.

€35M / 7%

Prohibited practices

of global annual turnover

€15M / 3%

High-risk obligations

of global annual turnover

€7.5M / 1%

Incorrect information

of global annual turnover

Note: National market-surveillance authorities can also order a non-compliant AI system withdrawn from the EU market, independent of any fine.

Compliance check

How to find your risk tier

Reading the regulation directly takes hours. Answering a short questionnaire about your system takes minutes.

01

Describe your system

What it does, which sector it operates in, and whether it processes biometric data.

02

Answer 7 questions

Whether it influences decisions about people, whether it faces consumers, and how transparent you already are.

03

Get your classification

A risk tier, a compliance score, and the exact list of documents your tier requires, with the legal article for each.

Classify your AI system

EuroComply classifies your system under the EU AI Act in about 3 minutes. No signup required.

Start the assessment

FAQ

Frequently asked questions

Does the EU AI Act apply to my company?

Yes, if your AI system is placed on the EU market or its output is used by people in the EU. This applies regardless of where your company is incorporated, the same extraterritorial reach as GDPR.

When do the obligations start?

The Act entered into force in August 2024. Prohibited practices have been banned since 2 February 2025. General-purpose AI model obligations apply since 2 August 2025. The full high-risk regime applies from 2 August 2026.

What are the fines for non-compliance?

Up to €35M or 7% of global annual turnover for prohibited practices, up to €15M or 3% for breaching high-risk obligations, and up to €7.5M or 1% for supplying incorrect information to authorities.

How do I know my system's risk tier?

It depends on what the system does and who it affects. EuroComply's free assessment answers this for you in about 3 minutes, mapping your answers onto Article 5, Annex III, and Article 50.

What documents does a high-risk system need?

Technical documentation, a risk management system, data governance records, human oversight measures, instructions for deployers, a conformity assessment, an EU Declaration of Conformity, and EU database registration.

Related

Risk Levels Guide

The 4 EU AI Act risk levels explained, with examples

Prohibited, high, limited, and minimal risk, in detail

GPSR Compliance Guide

Selling physical products with AI features in the EU?

GPSR requirements, checklist, and penalties