The EU Artificial Intelligence Act is no longer something companies can treat as a future compliance project. Its requirements are already taking effect, and for CTOs, product owners, and engineering teams, EU AI Act compliance is becoming a practical question of how existing AI systems are designed, documented, monitored, and controlled.
The timeline has also changed. Article 50 transparency requirements have applied since August 2, 2026, including disclosure obligations for certain AI interactions and AI-generated or manipulated content. At the same time, the main requirements for standalone high-risk AI systems listed in Annex III have been moved to December 2, 2027, while the deadline for high-risk AI embedded in regulated products under Annex I is now August 2, 2028.
For companies already using AI, this does not automatically mean rebuilding applications from scratch. In many cases, the first step is much more practical: audit the system you already have, determine which EU AI Act requirements apply, identify the real technical and organizational gaps, and then add only the controls that are missing. These may include better logging, human-review workflows, access controls, monitoring, transparency mechanisms, data governance, or technical documentation.
In this guide, we explain how to classify AI systems by risk, determine whether high-risk or transparency requirements apply, assess an existing application for compliance gaps, and turn the findings into a realistic remediation roadmap. We will also look at human oversight, conformity assessment readiness, AI literacy, monitoring, and the technical safeguards companies can introduce without unnecessary redevelopment.
For organizations that need to keep existing products competitive while preparing for the next stages of EU AI Act enforcement, the goal is not compliance for compliance’s sake. It is to understand what actually needs to change, what can remain as it is, and where targeted modernization can make an AI system safer, more transparent, and easier to govern.
How the EU AI Act Works and Why It Matters for Businesses
The EU AI Act is a European law that regulates the use of artificial intelligence based on the level of risk a particular AI system may create for people, businesses, and society. This approach is known as risk-based regulation: the greater the potential impact of the system, the stricter the requirements that may apply to its development, deployment, and operation.
This means the EU AI Act does not apply the same rules to every AI-powered tool. An internal assistant used for working with text and a system that automatically evaluates job applicants may rely on similar technologies, but from a regulatory perspective, they create very different levels of risk.
For higher-risk systems, the requirements may cover:
- risk management;
- data quality and governance;
- technical documentation;
- logging and audit trails;
- cybersecurity;
- continuous monitoring;
- transparency;
- human oversight;
- and, in some cases, conformity assessment and post-market monitoring.
This is why EU AI Act compliance is not only a legal issue. Many of its requirements directly affect product architecture, data flows, user interfaces, decision-making processes, access control, monitoring, and the work of engineering teams.
In practice, companies first need to answer several basic questions:

Five questions before EU AI Act classification
Only after that can the applicable EU AI Act requirements be determined.
Who Needs to Comply With the EU AI Act?
The EU AI Act does not apply only to European AI companies. Depending on how and where an AI system is used, its requirements may also apply to organizations outside the EU.
The scope of the Act may include:
- providers that place AI systems or general-purpose AI models on the EU market;
- deployers located in the EU and using AI in their business activities;
- certain providers and deployers from third countries if the output of their AI systems is used in the EU;
- importers and distributors of AI systems;
- product manufacturers that place an AI system on the market or put it into service together with their product.
For US and other non-EU companies, this is particularly important. Not having an office or legal entity in the European Union does not automatically mean that the EU AI Act is irrelevant to your business.
For example, if a US software company offers an AI-enabled product to European customers or the outputs of its AI system are used in the EU, the company should assess whether that activity falls within the scope of the Act. The regulation specifically covers certain situations in which providers and deployers established outside the EU may still be subject to its requirements.
That is why one of the first stages of an EU AI Act compliance audit should be a scope assessment, not risk classification. A company needs to understand where the system operates, who provides it, who uses its outputs, and where the users or business processes affected by the system are located.
Provider vs. Deployer: Why Your Role Matters
Once a company determines that the EU AI Act may apply to its AI system, the next question is what role the organization plays in relation to that system.
For most companies, the two most important roles are provider and deployer.
A provider is a company that develops an AI system or general-purpose AI model – or commissions its development – and then offers or deploys it under its own name or brand.
For example, if a company develops an AI-powered recruitment platform and sells it to enterprise customers under its own brand, it will typically act as the provider of that system.
A deployer is an organization that uses an AI system under its authority as part of its professional activities.
For example, a company may purchase a third-party AI tool for resume screening, customer support, fraud detection, or internal analytics. In that case, it may not have developed the technology itself, but it can still have its own responsibilities as a deployer.
The same organization can also act as both a provider and a deployer at the same time.
For example, an enterprise company may:
- develop AI functionality for customers and act as a provider;
- use third-party AI tools internally across HR, support, or engineering teams and act as a deployer.
This is why the role must be determined for each AI system separately, rather than once for the organization as a whole.
This distinction matters because providers and deployers have separate compliance responsibilities. Providers generally have a broader set of responsibilities related to system design, documentation, risk management, testing, and other compliance requirements.
Deployers, in turn, are responsible for how the system is used in real business processes, including applicable human oversight, monitoring, and compliance with the provider’s instructions.
A company’s role may also change after an AI system has been deployed. In particular, for high-risk AI systems, certain substantial modifications, rebranding, or changes to the system’s intended purpose may result in a deployer, importer, distributor, or another party being treated as the provider and assuming the corresponding obligations.
Therefore, it is not enough to ask:
“Did we build this AI system ourselves, or did we buy it?”
A proper assessment should also determine:
who developed the system, under whose brand it is used or sold, how it has been modified, what purpose it currently serves, and who controls its use.
This combination of scope + company role + system use case determines which EU AI Act requirements should be assessed next.
EU AI Act Update 2026: What Changed and What’s Next
As of August 2026, the EU AI Act is already being implemented in stages, but the deadlines for the main requirements applicable to high-risk AI systems have been postponed. Article 50 transparency requirements have applied since August 2, 2026, while the rules for standalone high-risk systems listed in Annex III will now apply from December 2, 2027, and the requirements for high-risk AI embedded in regulated products under Annex I will apply from August 2, 2028.
This change is especially important for companies that had been preparing for the original August 2, 2026 high-risk deadline. Following the adoption of Regulation (EU) 2026/1744, also known as the Digital Omnibus on AI, European lawmakers gave organizations additional time to prepare high-risk systems. The Regulation was published on July 24, 2026, and entered into force on July 27, 2026.
However, the postponement of the high-risk deadlines does not mean that companies can delay EU AI Act compliance as a whole. Some requirements are already in force, while preparing high-risk systems takes time. Companies need to classify AI use cases, review data governance, establish logging and monitoring, define human oversight, prepare technical documentation, and address architectural or organizational gaps well before the final deadline.
What Changed for High-Risk AI Systems?
The most significant change in 2026 concerns the implementation timeline for high-risk AI.
For Annex III, which covers standalone AI systems used in areas such as employment, education, access to essential services, and other sensitive use cases, the original deadline of August 2, 2026 was moved to December 2, 2027.
For Annex I – AI systems considered high-risk because they are part of, or serve as a safety component of, a regulated product – the relevant requirements will now apply from August 2, 2028.
The postponement is intended, among other things, to give companies and regulators more time for the development of the standards, common specifications, guidance, and other implementation tools needed to apply high-risk requirements consistently.
For businesses, this additional time should be treated not as a reason to postpone preparation, but as an opportunity to conduct a proper compliance audit and introduce changes gradually instead of redesigning a system immediately before the deadline.
Article 50 Transparency Requirements Have Not Been Postponed
The revised high-risk deadlines did not change Article 50. Its transparency requirements started applying on August 2, 2026. This date also marks the beginning of broader EU AI Act enforcement at both national and EU level.
Article 50 covers a range of transparency scenarios, including cases where people must be informed that they are interacting with an AI system, as well as certain requirements related to synthetic or manipulated content.
In practical terms, companies using chatbots, virtual assistants, content-generation features, deepfake technologies, or other relevant AI functionality should already be checking whether the required disclosure and labeling mechanisms are properly implemented.
It is important to separate these two areas:

high-risk compliance deadlines have been postponed, but transparency compliance is already a current requirement.
New Prohibited AI Practices Apply From December 2, 2026
The next important milestone is December 2, 2026.
From this date, additional prohibitions will apply to AI systems that generate certain non-consensual sexual and intimate content, including non-consensual sexual deepfakes, as well as child sexual abuse material.
In addition, December 2, 2026 is a transition deadline for certain providers of AI systems, including general-purpose AI systems that generate synthetic audio, images, video, or text and were placed on the market before August 2, 2026. These providers must bring the relevant systems into compliance with Article 50(2).
EU AI Act Timeline: 2025–2028
The key dates companies should now plan around are:
| Date | What Applies | What It Means for Companies |
| February 2, 2025 | Prohibited practices, definitions, and AI literacy provisions begin to apply | Review AI use cases for prohibited practices and start introducing measures that support AI literacy |
| August 2, 2025 | Governance provisions and GPAI requirements take effect | Providers of general-purpose AI models must address the applicable GPAI requirements |
| August 2, 2026 | Article 50 transparency requirements apply; broader enforcement begins | Review chatbots, AI-generated content, disclosure, and transparency mechanisms |
| December 2, 2026 | New prohibited practices, and the Article 50(2) transition apply | Review relevant generative AI use cases and existing synthetic-content systems |
| December 2, 2027 | Annex III high-risk AI requirements apply | Standalone high-risk systems must be ready for applicable risk management, documentation, human oversight, and other requirements |
| August 2, 2028 | Annex I high-risk AI requirements apply | High-risk AI used as part of regulated products becomes subject to the applicable requirements |
EU AI Act Timeline
The AI Act is being rolled out in phases, with key implementation milestones extending to August 2, 2028.
For CTOs and product teams, the main takeaway from the 2026 EU AI Act update is practical: the revised high-risk deadlines provide more time, but they do not reduce the amount of preparation required.
If an existing AI system may fall under Annex III or Annex I, companies now have an opportunity to audit it before the relevant requirements become mandatory: determine its risk category, review the architecture and data flows, identify missing safeguards, and build a remediation roadmap.
This is especially important for existing enterprise applications. Instead of rushing into a full rebuild immediately before a deadline, companies can identify in advance which parts of the system actually need to change – such as logging, monitoring, human oversight, access control, transparency mechanisms, or documentation – and modernize them gradually.
The Four Main AI Risk Categories Under the EU AI Act
The EU AI Act divides AI systems into four main risk categories. The greater a system’s potential impact on people’s safety, rights, or opportunities, the stricter the requirements that may apply.
Unacceptable Risk: Prohibited Uses
Certain AI applications are not permitted under the EU AI Act. These include certain forms of behavioral manipulation, social scoring, exploitation of vulnerable groups, and specific uses of biometric categorization and emotion recognition.
High Risk: Strict Requirements, Revised Deadlines
High-risk systems are allowed, but they are subject to the strictest controls. They may include AI used in recruitment, employee management, education, creditworthiness assessment, and access to essential services.
These systems may be subject to requirements related to risk management, documentation, logging, human oversight, security, and monitoring. For Annex III systems, the relevant requirements apply from December 2, 2027, while Annex I requirements apply from August 2, 2028.
Limited Risk: Transparency Duties Apply
For some AI systems, the main regulatory focus is transparency. For example, users may need to be informed that they are interacting with AI or that certain content was generated or manipulated by an AI system.
The relevant Article 50 transparency requirements have applied since August 2, 2026.
Minimal Risk: Few Additional Requirements
Most low-impact AI applications are not subject to the strict requirements that apply to high-risk systems. However, companies should still know which AI tools are being used, what data they process, and whether their original use case has changed.
General-Purpose AI (GPAI) Models
General-purpose AI models, or GPAI, should be considered separately from the four risk tiers rather than treated as a fifth risk category.
These models are designed to perform a wide range of tasks and can serve as the foundation for many downstream AI applications. For this reason, the EU AI Act introduces a separate set of obligations for GPAI providers, including requirements related to documentation, information for downstream providers, and other governance measures.
GPAI requirements have been in effect since August 2, 2025. For companies that use third-party general-purpose models in their own products, it is important to assess not only the requirements that apply to the underlying model, but also the risk level of the final AI system built on top of it.
What Are the Risks of an AI System That Is Not Compliance-Ready?
Insufficient readiness for the EU AI Act can create not only legal risks but also practical business problems. Companies may face delayed product launches in the EU market, urgent redesign of existing components, additional requirements from enterprise customers or procurement teams, and higher costs for compliance and technical modernization.
The later a compliance gap is discovered, the more expensive it may be to fix. At a late stage, companies may need to change architecture, data flows, user interfaces, access controls, logging, monitoring, or internal workflows in a product that is already in use.
The EU AI Act also provides for significant financial penalties. The most serious breaches, including prohibited AI practices, may result in penalties of up to €35 million or 7% of a company’s total worldwide annual turnover, whichever amount is greater. For certain other breaches covered by Article 99, the maximum penalty can reach €15 million or 3% of global annual turnover, again depending on which figure is higher.
Financial penalties are not the only consequence of non-compliance. Companies may also face:
- delayed product launches in the EU;
- urgent redesign and higher remediation costs;
- increased regulatory scrutiny;
- reputational damage;
- compliance issues during procurement or enterprise sales;
- blocked or delayed enterprise adoption;
- additional legal and operational costs.
For companies already using AI in existing products, the most practical approach is to identify these gaps early. An early audit helps determine which changes are actually necessary and implement them gradually instead of making expensive last-minute changes before launch or a regulatory review.
How AI Systems Are Classified Under the EU AI Act
Classifying an AI system under the EU AI Act answers one key question: which rules and requirements apply to this particular system? A simple decision tree can help structure the process.
Identify the AI System and Its Purpose
Start by defining what the system does, what it is used for, who its users are, what outputs it produces, and which decisions or workflows it affects.
Determine Whether the System and Company Are in Scope
Next, check whether the system falls within the scope of the EU AI Act: where it is offered or used, where its outputs are used, and whether any relevant exclusions apply.
Define the Company’s Role
Determine whether the company acts as a provider, deployer, importer, distributor, or product manufacturer. For most businesses, the key distinction is between provider and deployer, as their obligations differ.
Analyze the Business Context and Impact
Pay particular attention to AI used in recruitment, employment, credit, education, insurance, healthcare, essential services, and other areas where system outputs may significantly affect a person’s rights or opportunities.
Check for Prohibited and High-Risk Use Cases
First, rule out prohibited practices. Then determine whether the system falls under Annex I, Annex III, or other high-risk criteria, taking into account any applicable conditions and exceptions.
Check Transparency and GPAI Requirements
Even if a system is not classified as high-risk, Article 50 transparency duties or separate requirements for general-purpose AI models may still apply.
The final classification should identify whether the system is prohibited, high-risk, transparency/limited-risk, minimal/non-high-risk, or subject to GPAI-related obligations. Once this is clear, the company can move on to a readiness audit and assess which controls and processes are still missing.

EU AI Act Risk Classification Process
How to Audit an AI System for EU AI Act Readiness
Once an AI system has been classified, the next step is to check whether it has the controls, processes, and evidence needed to meet the applicable requirements. A readiness audit helps identify the gap between formal compliance and the system’s actual technical and operational state, which is also a key focus of AI governance consulting.
AI System Purpose, Scope, and Ownership
Start by comparing the system’s intended purpose with how it is actually used today. Review current use cases, the system owner, the business owner, and the company’s role as a provider or deployer.
Data Sources and Data Quality
The audit should identify where training, fine-tuning, RAG, and input data come from, whether they are relevant and of sufficient quality, whether they contain personal or sensitive information, and who can access them.
Traceability is equally important: the company should be able to understand which data was used and how it moved through the system.
Risk Category and Business Context
The company should verify that the assigned risk category still reflects the system’s actual use.
If the system has moved into a new business context or started influencing more significant decisions, reclassification, additional safeguards, or support from an AI governance consultant may be required.
Human Oversight
Human oversight should be effective rather than purely formal. The audit should check who can review AI outputs, reject or override decisions, stop automated workflows, and trigger escalation.
It is also important to record these interventions, especially when AI influences significant decisions.
Transparency and User Communication
Companies should check whether users understand when they are interacting with AI and whether the required disclosure and labeling mechanisms are in place.
For relevant synthetic or manipulated content, the audit should also review notices, labels, and whether the frontend behavior aligns with Article 50 requirements.
Logging and Audit Trails
A company should be able to reconstruct what happened within the system at a specific point in time.
Without a reliable audit trail, investigating failures or demonstrating that controls were working becomes much more difficult.
Security and Access Control
The audit should review authentication, authorization, RBAC, access to models and data, API keys, third-party integrations, and protection of sensitive information – areas commonly covered by AI governance consulting services.
If gaps are identified, SCAND can help implement the necessary safeguards, such as stronger access controls, infrastructure isolation, or more secure integration architecture.
Model Performance and Monitoring
An AI system should be evaluated not only before launch but also after deployment.
The audit should review accuracy and reliability, relevant error metrics, hallucinations, performance drift, failure scenarios, alerts, and rollback or escalation processes.
The key question is whether the team can quickly detect when model behavior changes or becomes unsafe.
Conformity Assessment Readiness
For high-risk systems, the audit should separately assess readiness for any applicable conformity assessment.
In simple terms, conformity assessment is the process of demonstrating that the system meets the applicable high-risk requirements before the relevant placing-on-the-market or putting-into-service stage.
Documentation and Internal Policies
Documentation should reflect how the AI system actually works rather than exist separately from day-to-day operations.
The audit should review the AI system inventory, intended purpose, ownership, risk classification, data information, technical controls, monitoring processes, incident handling, human oversight procedures, change history, and other elements typically addressed through AI governance services.
A policy alone is not enough. Companies need technical and operational evidence showing that the documented controls actually exist and are being applied.
Prepare a Remediation Roadmap
After the audit, findings should be prioritized by severity, from critical or prohibited issues to high-priority compliance gaps, governance improvements, and long-term optimization.
The roadmap should account for regulatory deadlines, engineering complexity, business impact, dependencies, and cost. For existing products, it should also identify which gaps can be fixed through targeted modernization rather than a full rebuild. In many cases, adding logging, monitoring, human-review workflows, security controls, or documentation processes is faster and more cost-effective.

AI Act Readiness Audit
How SCAND Helps Companies Become EU AI Act Ready
SCAND can support companies on the technical side of EU AI Act readiness by helping assess and modernize existing AI-enabled applications. Depending on the system and identified compliance gaps, this may include improvements to architecture, data handling, security, access control, logging, monitoring, AI integrations, or user workflows. The goal is to help businesses adapt existing software where possible instead of automatically rebuilding the entire product from scratch, while legal and regulatory compliance decisions remain with the company and its compliance or legal advisors.
Conclusion
EU AI Act readiness starts with understanding which AI systems a company uses, where and why they are used, what role the organization plays in relation to them, and what risks each use case creates.
From there, companies need to assess the system’s scope, risk level, data flows, technical safeguards, documentation, monitoring, transparency, human oversight, and the team’s ability to work with AI safely and consistently. This approach helps reveal real compliance gaps and determine which changes are actually necessary.
SCAND can support companies on the technical side of this process by helping review existing AI-enabled applications, identify issues in architecture and workflows, and modernize specific components such as security, access control, logging, monitoring, data handling, or AI integrations.
If AI is already part of an existing product, start with an audit of the current system before deciding on a full rebuild. This makes it easier to understand which components truly need to change and which can be retained and adapted.
Frequently Asked Questions (FAQs)
What Is the EU AI Act Compliance Deadline in 2026?
The EU AI Act does not have a single compliance date that applies to every system. By August 2026, Article 50 transparency rules are already in force. Requirements for standalone high-risk systems listed in Annex III will take effect on December 2, 2027, while the corresponding rules for high-risk AI integrated into regulated products under Annex I will apply from August 2, 2028.
What Changed in the EU AI Act in 2026?
The main 2026 update is the revised implementation timeline for high-risk AI systems, while Article 50 transparency requirements started applying on August 2, 2026. Companies now have more time to prepare Annex III and Annex I systems, but transparency compliance is already a current requirement.
What Happens If My Company Doesn’t Comply With the EU AI Act?
Failure to meet the applicable requirements can create legal, financial, operational, and commercial problems. The most serious prohibited AI practices can lead to fines of up to €35 million or 7% of worldwide annual turnover, whichever is higher. Certain other breaches may carry penalties of up to €15 million or 3% of global annual turnover.
Who Needs to Comply With the EU AI Act?
The EU AI Act may apply to providers, deployers, importers, distributors, and certain product manufacturers. It can also apply to companies outside the EU if they place AI systems or GPAI models on the EU market or if the output of their AI systems is used within the European Union.
Does the EU AI Act Affect US Companies?
Yes, the EU AI Act can apply to US companies in certain cases. For example, it may apply if a US provider places an AI system or GPAI model on the EU market, or if the output of an AI system operated by a third-country provider or deployer is used in the EU. Having no EU headquarters does not automatically place a company outside the scope of the Act.
How Do High-Risk and Limited-Risk AI Systems Differ?
High-risk AI systems face a broader set of compliance obligations because they can have a greater impact on people’s rights, safety, or access to important services. Depending on the use case, companies may need formal risk controls, technical records, logging, human review mechanisms, security measures, and conformity procedures. Limited-risk systems generally carry lighter obligations, with the main emphasis on transparency, such as telling users when AI is involved or marking certain AI-generated or altered content.
What Does Conformity Assessment Mean Under the EU AI Act?
A conformity assessment is a formal check used to verify that a high-risk AI system satisfies the relevant EU AI Act requirements before it is launched or put into service. The exact process depends on the system: in some cases, the provider may carry out the assessment internally, while other cases can require the involvement of a notified body. If a high-risk system is substantially modified later, its conformity may need to be assessed again.
