EU AI Act compliance consulting
Find out where the EU AI Act reaches you — and prove what isn't high risk.
Most AI systems in a normal business are minimal risk. We classify each one under Article 6, with written reasoning for the Act's regulator (the market surveillance authority), and build only what its tier requires. Some duties already apply; the next date is 2 December 2026.
- One classification memo per system
- We say so when nothing is high risk
- We reply within one working day.
In brief
- What it is
- A risk tier for each AI system you build or use, and your role: provider (it goes out under your name) or deployer (you only use it).
- Why it matters
- The Act reaches you once your system's output is used in the EU; the tier decides what you owe.
- What you get
- A classification memo per system, plus technical-file evidence for any high-risk one.
Start here
Classify first. One decision sets the bill.
The Act runs to 113 articles across 13 chapters, and almost none will touch your internal document search or demand forecasting model. A chatbot in the transparency tier needs a disclosure line and machine-readable marking of synthetic output. A system in one of Annex III's eight high-risk use areas, such as recruitment, needs the long list below.
When a listed system is not high risk
Under Article 6(3), an Annex III system is not high risk if all it does is:
- A narrow procedural task.
- Improving a prior human activity.
- Detecting decision patterns without replacing the human assessment.
- Purely preparatory work.
A CV tool that only formats and routes applications may pass. None of these applies if the system profiles people.
Passing costs a documented assessment under Article 6(4) and a registration under Article 49(2), instead of a year of engineering rework.
Risk tiers
What each risk tier requires, and from when.
On 2 December 2026, two new prohibitions apply, on AI-generated non-consensual intimate imagery and child sexual abuse material (Article 5(1)(ba) and (bb), at the 7% tier). The Article 111(4) grace also ends, so AI content generators on the market before 2 August 2026 must meet the Article 50(2) marking and detection duties.
| Tier | What puts you there | What you owe | Applies from |
|---|---|---|---|
| Prohibited | Article 5, now ten listed practices | Stop. There is no compliance route. | 2 February 2025; two new practices from 2 December 2026 |
| High risk, Annex III | Article 6(2): eight listed use areas, unless Article 6(3) takes you out | Articles 9 to 15, including risk management, data governance, logging, human oversight, and accuracy, robustness and cybersecurity; Annex IV technical file, Article 17 quality management system (QMS), conformity assessment, CE mark, Article 49 registration | 2 December 2027 for Sections 1 to 3 |
| High risk, Annex I | Article 6(1): AI in, or as a safety component of, a product already under EU sectoral law | The same set, merged with the existing sectoral conformity route | 2 August 2028, because two conformity regimes must merge |
| Transparency risk | Article 50: systems that interact with people or generate content | Provider discloses AI interaction and marks synthetic output; deployer labels deepfakes, public-interest text, emotion recognition and biometric categorization | 2 August 2026; Article 50(2) marking grace ends 2 December 2026 |
| Minimal risk | Everything else: most of what you run | Article 4 literacy measures. Nothing further. | 2 February 2025 |
| General-purpose AI model provider (outside the tiers) | Chapter V, including when you fine-tune a model and ship it as your own | Annex XI documentation, Annex XII downstream information, copyright policy with a text and data mining reservation mechanism, public training-content summary | 2 August 2025, with governance and the national penalty regime |
Key dates under the 2026 amendment, Regulation (EU) 2026/1744
The amendment entered into force on 27 July 2026, signed on 8 July after the Parliament's position of 16 June and the Council's decision of 29 June.
- 2 August 2027. General-purpose models placed on the market before 2 August 2025 must comply; Member States must have at least one regulatory sandbox running, pushed back from 2026.
- 2 December 2027. Chapter III Sections 1, 2 and 3, the only sections that moved, begin to apply to standalone (Annex III) high-risk systems. Section 5, the conformity assessment and CE marking rules in Articles 40 to 49, was never deferred, and Section 4 on notified bodies has applied from August 2025.
Penalty ceilings. EUR 35 million or 7% of worldwide annual turnover for an Article 5 breach, EUR 15 million or 3% for most other operator duties, EUR 7.5 million or 1% for misleading information given to authorities. For an SME the lower figure is the cap.
No certificate, no legal advice. We are not a notified body, certification body or law firm.
Related: AI governance, AI model risk for banks, NIST AI RMF, AI vendor risk, AI security and all our compliance work.
How an engagement runs
Six documents, each with a named owner.
Steps 03 to 06 apply only to a high-risk system you provide; if nothing is high risk, we stop after step 02.
Inventory and operator role
Every AI system you build or use, and your role for each. Article 25(1) can make you the provider.
Article 6 classification memo
One per system: the Annex I and Annex III routes and a reasoned Article 6(3) assessment, kept for authorities under Article 6(4).
Article 10 data governance dossier
Provenance, representativeness, bias examination and the Article 10(5) justification for special-category data used to correct bias, built with your data team.
Annex IV technical file and Article 17 QMS
We draft them, and your engineering and quality owners sign.
Article 15 robustness and cybersecurity
We check the Article 15(5) measures against data poisoning, model poisoning, adversarial examples and model evasion, and confidentiality attacks. For a language model we verify them with LLM security testing mapped to the OWASP Top 10 for LLM Applications and MITRE ATLAS, retest included, and the findings become technical-file evidence. Accuracy metrics come from your own evaluation.
Declaration of conformity and CE mark
You sign the declaration (Article 47). Most Annex III systems use Annex VI internal control, with no outside body. On the Annex VII route, a notified body's certificate lasts four years for Annex III and five for Annex I (Article 44(2)).
FAQ
Questions about whether the Act reaches you.
No, and nobody can sell you one. A high-risk system ends with a conformity assessment under Article 43, an EU declaration of conformity you sign as the provider, a CE mark under Article 48, and a registration in the EU database under Article 49. For most Annex III systems that assessment is Annex VI internal control: you assess yourself and no third party signs anything. A third-party certificate exists only on the Annex VII route, from a notified body designated by a Member State. Designation is incomplete across most Member States, and the AI Act listing has been effectively empty. SecWiz can build and test the file, but can't certify it.
It has passed, and part of it landed. The general application date, the Article 50 transparency duties, Chapter IX market surveillance and the Commission's Article 101 power to fine model providers all took effect. The high-risk obligations in Chapter III Sections 1 to 3 did not: Regulation (EU) 2026/1744 moved them to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I.
Probably, but not automatically. Annex III point 4 covers recruitment and selection, so a tool that ranks or filters candidates sits inside it. Article 6(3) can take it back out in narrow cases, but never if it profiles people, and most CV screening does. The reasoning has to be written down and held under Article 6(4).
Article 2(1)(c) catches you once your system's output is used in the Union, wherever the model runs. Building to a client's name and specification usually leaves the client as the provider. Shipping under your own brand, substantially modifying a system or changing its intended purpose makes you the provider under Article 25(1). If you're the provider of a high-risk system, Article 22 requires a written mandate with an authorized representative established in the Union before it reaches the market. India has no AI statute, and the India AI Governance Guidelines of 5 November 2025 from MeitY (the Ministry of Electronics and Information Technology) are voluntary, so the binding obligation here is the foreign one.
Only part of Article 17. ISO/IEC 42001 certifies an organizational AI management system, and only an accredited certification body can issue that certificate. The AI Act imposes duties per system, and Article 40 gives presumption of conformity only to harmonized standards cited in the Official Journal, of which there are currently none. EN 18286:2026, ratified on 12 July 2026 and made available on 22 July, is not cited yet, but is worth reading against Article 17. A 42001 certificate typically saves a couple of months of management-system scaffolding and none of the per-system work, and no market surveillance authority will take it in place of a declaration of conformity. SecWiz isn't ISO 27001 or ISO/IEC 42001 certified itself.
For a single system in a mid-sized company, plan 9 to 15 months from kickoff to a defensible CE-marked state. Only about 4 to 6 months of that is documentation. The rest is engineering rework and evidence generation, and the Article 10 data governance work usually takes longest, because dataset provenance, representativeness and bias examination can't be reconstructed afterwards. A deployer scope under Articles 26 and 27 is much smaller, closer to 6 to 10 weeks.
Yes, if the tool is high risk. Article 26 gives deployers duties: use the system according to the instructions, assign human oversight to competent people with the authority to act, keep input data relevant, retain the automatically generated logs for at least six months, tell affected workers, and suspend use and report when a risk emerges. Article 27 adds a fundamental rights impact assessment for public bodies, private entities providing public services, and deployers of creditworthiness or life and health insurance risk assessment, and the result goes to the market surveillance authority. None of that is your vendor's job.
We won't certify anything, because no AI Act certificate exists. We won't act as your notified body, which requires designation by a Member State. We won't take the Article 22 authorized representative mandate, a ten-year custody role that belongs with a party established in the Union. We won't sign your declaration of conformity, since Article 47 puts that on the provider. If every system comes back minimal risk, we'll say so and the engagement ends there.
Let's talk
Start with the classification, not the program.
Send a list of the AI systems you build or use and where their output goes. You'll get a first view of which are in scope, which likely fall out under Article 6(3), and what a classification file would cost. We reply within one working day.