EU AI Act Compliance Audit: How Companies Can Prepare Their AI Systems

EU AI Act Compliance Audit: How Companies Can Prepare Their AI Systems

The EU Artificial Intelligence Act is no longer something companies can treat as a future compliance project. Its requirements are already taking effect, and for CTOs, product owners, and engineering teams, EU AI Act compliance is becoming a practical question of how existing AI systems are designed, documented, monitored, and controlled.

The timeline has also changed. Article 50 transparency requirements have applied since August 2, 2026, including disclosure obligations for certain AI interactions and AI-generated or manipulated content. At the same time, the main requirements for standalone high-risk AI systems listed in Annex III have been moved to December 2, 2027, while the deadline for high-risk AI embedded in regulated products under Annex I is now August 2, 2028.

For companies already using AI, this does not automatically mean rebuilding applications from scratch. In many cases, the first step is much more practical: audit the system you already have, determine which EU AI Act requirements apply, identify the real technical and organizational gaps, and then add only the controls that are missing. These may include better logging, human-review workflows, access controls, monitoring, transparency mechanisms, data governance, or technical documentation.

In this guide, we explain how to classify AI systems by risk, determine whether high-risk or transparency requirements apply, assess an existing application for compliance gaps, and turn the findings into a realistic remediation roadmap. We will also look at human oversight, conformity assessment readiness, AI literacy, monitoring, and the technical safeguards companies can introduce without unnecessary redevelopment.

For organizations that need to keep existing products competitive while preparing for the next stages of EU AI Act enforcement, the goal is not compliance for compliance’s sake. It is to understand what actually needs to change, what can remain as it is, and where targeted modernization can make an AI system safer, more transparent, and easier to govern.

How the EU AI Act Works and Why It Matters for Businesses

The EU AI Act is a European law that regulates the use of artificial intelligence based on the level of risk a particular AI system may create for people, businesses, and society. This approach is known as risk-based regulation: the greater the potential impact of the system, the stricter the requirements that may apply to its development, deployment, and operation.

This means the EU AI Act does not apply the same rules to every AI-powered tool. An internal assistant used for working with text and a system that automatically evaluates job applicants may rely on similar technologies, but from a regulatory perspective, they create very different levels of risk.

For higher-risk systems, the requirements may cover:

  • risk management;
  • data quality and governance;
  • technical documentation;
  • logging and audit trails;
  • cybersecurity;
  • continuous monitoring;
  • transparency;
  • human oversight;
  • and, in some cases, conformity assessment and post-market monitoring.

This is why EU AI Act compliance is not only a legal issue. Many of its requirements directly affect product architecture, data flows, user interfaces, decision-making processes, access control, monitoring, and the work of engineering teams.

In practice, companies first need to answer several basic questions:

Five questions before EU AI Act classification

Five questions before EU AI Act classification

Only after that can the applicable EU AI Act requirements be determined.

Who Needs to Comply With the EU AI Act?

The EU AI Act does not apply only to European AI companies. Depending on how and where an AI system is used, its requirements may also apply to organizations outside the EU.

The scope of the Act may include:

  • providers that place AI systems or general-purpose AI models on the EU market;
  • deployers located in the EU and using AI in their business activities;
  • certain providers and deployers from third countries if the output of their AI systems is used in the EU;
  • importers and distributors of AI systems;
  • product manufacturers that place an AI system on the market or put it into service together with their product.

For US and other non-EU companies, this is particularly important. Not having an office or legal entity in the European Union does not automatically mean that the EU AI Act is irrelevant to your business.

For example, if a US software company offers an AI-enabled product to European customers or the outputs of its AI system are used in the EU, the company should assess whether that activity falls within the scope of the Act. The regulation specifically covers certain situations in which providers and deployers established outside the EU may still be subject to its requirements.

That is why one of the first stages of an EU AI Act compliance audit should be a scope assessment, not risk classification. A company needs to understand where the system operates, who provides it, who uses its outputs, and where the users or business processes affected by the system are located.

Provider vs. Deployer: Why Your Role Matters

Once a company determines that the EU AI Act may apply to its AI system, the next question is what role the organization plays in relation to that system.

For most companies, the two most important roles are provider and deployer.

A provider is a company that develops an AI system or general-purpose AI model – or commissions its development – and then offers or deploys it under its own name or brand.

For example, if a company develops an AI-powered recruitment platform and sells it to enterprise customers under its own brand, it will typically act as the provider of that system.

A deployer is an organization that uses an AI system under its authority as part of its professional activities.

For example, a company may purchase a third-party AI tool for resume screening, customer support, fraud detection, or internal analytics. In that case, it may not have developed the technology itself, but it can still have its own responsibilities as a deployer.

The same organization can also act as both a provider and a deployer at the same time.

For example, an enterprise company may:

  • develop AI functionality for customers and act as a provider;
  • use third-party AI tools internally across HR, support, or engineering teams and act as a deployer.

This is why the role must be determined for each AI system separately, rather than once for the organization as a whole.

This distinction matters because providers and deployers have separate compliance responsibilities. Providers generally have a broader set of responsibilities related to system design, documentation, risk management, testing, and other compliance requirements.

Deployers, in turn, are responsible for how the system is used in real business processes, including applicable human oversight, monitoring, and compliance with the provider’s instructions.

A company’s role may also change after an AI system has been deployed. In particular, for high-risk AI systems, certain substantial modifications, rebranding, or changes to the system’s intended purpose may result in a deployer, importer, distributor, or another party being treated as the provider and assuming the corresponding obligations.

Therefore, it is not enough to ask:

“Did we build this AI system ourselves, or did we buy it?”

A proper assessment should also determine:

who developed the system, under whose brand it is used or sold, how it has been modified, what purpose it currently serves, and who controls its use.

This combination of scope + company role + system use case determines which EU AI Act requirements should be assessed next.

EU AI Act Update 2026: What Changed and What’s Next

As of August 2026, the EU AI Act is already being implemented in stages, but the deadlines for the main requirements applicable to high-risk AI systems have been postponed. Article 50 transparency requirements have applied since August 2, 2026, while the rules for standalone high-risk systems listed in Annex III will now apply from December 2, 2027, and the requirements for high-risk AI embedded in regulated products under Annex I will apply from August 2, 2028.

This change is especially important for companies that had been preparing for the original August 2, 2026 high-risk deadline. Following the adoption of Regulation (EU) 2026/1744, also known as the Digital Omnibus on AI, European lawmakers gave organizations additional time to prepare high-risk systems. The Regulation was published on July 24, 2026, and entered into force on July 27, 2026.

However, the postponement of the high-risk deadlines does not mean that companies can delay EU AI Act compliance as a whole. Some requirements are already in force, while preparing high-risk systems takes time. Companies need to classify AI use cases, review data governance, establish logging and monitoring, define human oversight, prepare technical documentation, and address architectural or organizational gaps well before the final deadline.

What Changed for High-Risk AI Systems?

The most significant change in 2026 concerns the implementation timeline for high-risk AI.

For Annex III, which covers standalone AI systems used in areas such as employment, education, access to essential services, and other sensitive use cases, the original deadline of August 2, 2026 was moved to December 2, 2027.

For Annex I – AI systems considered high-risk because they are part of, or serve as a safety component of, a regulated product – the relevant requirements will now apply from August 2, 2028.

The postponement is intended, among other things, to give companies and regulators more time for the development of the standards, common specifications, guidance, and other implementation tools needed to apply high-risk requirements consistently.

For businesses, this additional time should be treated not as a reason to postpone preparation, but as an opportunity to conduct a proper compliance audit and introduce changes gradually instead of redesigning a system immediately before the deadline.

Article 50 Transparency Requirements Have Not Been Postponed

The revised high-risk deadlines did not change Article 50. Its transparency requirements started applying on August 2, 2026. This date also marks the beginning of broader EU AI Act enforcement at both national and EU level.

Article 50 covers a range of transparency scenarios, including cases where people must be informed that they are interacting with an AI system, as well as certain requirements related to synthetic or manipulated content.

In practical terms, companies using chatbots, virtual assistants, content-generation features, deepfake technologies, or other relevant AI functionality should already be checking whether the required disclosure and labeling mechanisms are properly implemented.

It is important to separate these two areas:

Article 50

high-risk compliance deadlines have been postponed, but transparency compliance is already a current requirement.

New Prohibited AI Practices Apply From December 2, 2026

The next important milestone is December 2, 2026.

From this date, additional prohibitions will apply to AI systems that generate certain non-consensual sexual and intimate content, including non-consensual sexual deepfakes, as well as child sexual abuse material.

In addition, December 2, 2026 is a transition deadline for certain providers of AI systems, including general-purpose AI systems that generate synthetic audio, images, video, or text and were placed on the market before August 2, 2026. These providers must bring the relevant systems into compliance with Article 50(2).

EU AI Act Timeline: 2025–2028

The key dates companies should now plan around are:

Date What Applies What It Means for Companies
February 2, 2025 Prohibited practices, definitions, and AI literacy provisions begin to apply Review AI use cases for prohibited practices and start introducing measures that support AI literacy
August 2, 2025 Governance provisions and GPAI requirements take effect Providers of general-purpose AI models must address the applicable GPAI requirements
August 2, 2026 Article 50 transparency requirements apply; broader enforcement begins Review chatbots, AI-generated content, disclosure, and transparency mechanisms
December 2, 2026 New prohibited practices, and the Article 50(2) transition apply Review relevant generative AI use cases and existing synthetic-content systems
December 2, 2027 Annex III high-risk AI requirements apply Standalone high-risk systems must be ready for applicable risk management, documentation, human oversight, and other requirements
August 2, 2028 Annex I high-risk AI requirements apply High-risk AI used as part of regulated products becomes subject to the applicable requirements

EU AI Act Timeline

The AI Act is being rolled out in phases, with key implementation milestones extending to August 2, 2028.

For CTOs and product teams, the main takeaway from the 2026 EU AI Act update is practical: the revised high-risk deadlines provide more time, but they do not reduce the amount of preparation required.

If an existing AI system may fall under Annex III or Annex I, companies now have an opportunity to audit it before the relevant requirements become mandatory: determine its risk category, review the architecture and data flows, identify missing safeguards, and build a remediation roadmap.

This is especially important for existing enterprise applications. Instead of rushing into a full rebuild immediately before a deadline, companies can identify in advance which parts of the system actually need to change – such as logging, monitoring, human oversight, access control, transparency mechanisms, or documentation – and modernize them gradually.

The Four Main AI Risk Categories Under the EU AI Act

The EU AI Act divides AI systems into four main risk categories. The greater a system’s potential impact on people’s safety, rights, or opportunities, the stricter the requirements that may apply.

Unacceptable Risk: Prohibited Uses

Certain AI applications are not permitted under the EU AI Act. These include certain forms of behavioral manipulation, social scoring, exploitation of vulnerable groups, and specific uses of biometric categorization and emotion recognition.

High Risk: Strict Requirements, Revised Deadlines

High-risk systems are allowed, but they are subject to the strictest controls. They may include AI used in recruitment, employee management, education, creditworthiness assessment, and access to essential services.

These systems may be subject to requirements related to risk management, documentation, logging, human oversight, security, and monitoring. For Annex III systems, the relevant requirements apply from December 2, 2027, while Annex I requirements apply from August 2, 2028.

Limited Risk: Transparency Duties Apply

For some AI systems, the main regulatory focus is transparency. For example, users may need to be informed that they are interacting with AI or that certain content was generated or manipulated by an AI system.

The relevant Article 50 transparency requirements have applied since August 2, 2026.

Minimal Risk: Few Additional Requirements

Most low-impact AI applications are not subject to the strict requirements that apply to high-risk systems. However, companies should still know which AI tools are being used, what data they process, and whether their original use case has changed.

General-Purpose AI (GPAI) Models

General-purpose AI models, or GPAI, should be considered separately from the four risk tiers rather than treated as a fifth risk category.

These models are designed to perform a wide range of tasks and can serve as the foundation for many downstream AI applications. For this reason, the EU AI Act introduces a separate set of obligations for GPAI providers, including requirements related to documentation, information for downstream providers, and other governance measures.

GPAI requirements have been in effect since August 2, 2025. For companies that use third-party general-purpose models in their own products, it is important to assess not only the requirements that apply to the underlying model, but also the risk level of the final AI system built on top of it.

What Are the Risks of an AI System That Is Not Compliance-Ready?

Insufficient readiness for the EU AI Act can create not only legal risks but also practical business problems. Companies may face delayed product launches in the EU market, urgent redesign of existing components, additional requirements from enterprise customers or procurement teams, and higher costs for compliance and technical modernization.

The later a compliance gap is discovered, the more expensive it may be to fix. At a late stage, companies may need to change architecture, data flows, user interfaces, access controls, logging, monitoring, or internal workflows in a product that is already in use.

The EU AI Act also provides for significant financial penalties. The most serious breaches, including prohibited AI practices, may result in penalties of up to €35 million or 7% of a company’s total worldwide annual turnover, whichever amount is greater. For certain other breaches covered by Article 99, the maximum penalty can reach €15 million or 3% of global annual turnover, again depending on which figure is higher.

Financial penalties are not the only consequence of non-compliance. Companies may also face:

  • delayed product launches in the EU;
  • urgent redesign and higher remediation costs;
  • increased regulatory scrutiny;
  • reputational damage;
  • compliance issues during procurement or enterprise sales;
  • blocked or delayed enterprise adoption;
  • additional legal and operational costs.

For companies already using AI in existing products, the most practical approach is to identify these gaps early. An early audit helps determine which changes are actually necessary and implement them gradually instead of making expensive last-minute changes before launch or a regulatory review.

How AI Systems Are Classified Under the EU AI Act

Classifying an AI system under the EU AI Act answers one key question: which rules and requirements apply to this particular system? A simple decision tree can help structure the process.

Identify the AI System and Its Purpose

Start by defining what the system does, what it is used for, who its users are, what outputs it produces, and which decisions or workflows it affects.

Determine Whether the System and Company Are in Scope

Next, check whether the system falls within the scope of the EU AI Act: where it is offered or used, where its outputs are used, and whether any relevant exclusions apply.

Define the Company’s Role

Determine whether the company acts as a provider, deployer, importer, distributor, or product manufacturer. For most businesses, the key distinction is between provider and deployer, as their obligations differ.

Analyze the Business Context and Impact

Pay particular attention to AI used in recruitment, employment, credit, education, insurance, healthcare, essential services, and other areas where system outputs may significantly affect a person’s rights or opportunities.

Check for Prohibited and High-Risk Use Cases

First, rule out prohibited practices. Then determine whether the system falls under Annex I, Annex III, or other high-risk criteria, taking into account any applicable conditions and exceptions.

Check Transparency and GPAI Requirements

Even if a system is not classified as high-risk, Article 50 transparency duties or separate requirements for general-purpose AI models may still apply.

The final classification should identify whether the system is prohibited, high-risk, transparency/limited-risk, minimal/non-high-risk, or subject to GPAI-related obligations. Once this is clear, the company can move on to a readiness audit and assess which controls and processes are still missing.

EU AI Act Risk Classification Process

EU AI Act Risk Classification Process

How to Audit an AI System for EU AI Act Readiness

Once an AI system has been classified, the next step is to check whether it has the controls, processes, and evidence needed to meet the applicable requirements. A readiness audit helps identify the gap between formal compliance and the system’s actual technical and operational state, which is also a key focus of AI governance consulting.

AI System Purpose, Scope, and Ownership

Start by comparing the system’s intended purpose with how it is actually used today. Review current use cases, the system owner, the business owner, and the company’s role as a provider or deployer.

Data Sources and Data Quality

The audit should identify where training, fine-tuning, RAG, and input data come from, whether they are relevant and of sufficient quality, whether they contain personal or sensitive information, and who can access them.

Traceability is equally important: the company should be able to understand which data was used and how it moved through the system.

Risk Category and Business Context

The company should verify that the assigned risk category still reflects the system’s actual use.

If the system has moved into a new business context or started influencing more significant decisions, reclassification, additional safeguards, or support from an AI governance consultant may be required.

Human Oversight

Human oversight should be effective rather than purely formal. The audit should check who can review AI outputs, reject or override decisions, stop automated workflows, and trigger escalation.

It is also important to record these interventions, especially when AI influences significant decisions.

Transparency and User Communication

Companies should check whether users understand when they are interacting with AI and whether the required disclosure and labeling mechanisms are in place.

For relevant synthetic or manipulated content, the audit should also review notices, labels, and whether the frontend behavior aligns with Article 50 requirements.

Logging and Audit Trails

A company should be able to reconstruct what happened within the system at a specific point in time.

Without a reliable audit trail, investigating failures or demonstrating that controls were working becomes much more difficult.

Security and Access Control

The audit should review authentication, authorization, RBAC, access to models and data, API keys, third-party integrations, and protection of sensitive information – areas commonly covered by AI governance consulting services.

If gaps are identified, SCAND can help implement the necessary safeguards, such as stronger access controls, infrastructure isolation, or more secure integration architecture.

Model Performance and Monitoring

An AI system should be evaluated not only before launch but also after deployment.

The audit should review accuracy and reliability, relevant error metrics, hallucinations, performance drift, failure scenarios, alerts, and rollback or escalation processes.

The key question is whether the team can quickly detect when model behavior changes or becomes unsafe.

Conformity Assessment Readiness

For high-risk systems, the audit should separately assess readiness for any applicable conformity assessment.

In simple terms, conformity assessment is the process of demonstrating that the system meets the applicable high-risk requirements before the relevant placing-on-the-market or putting-into-service stage.

AI consulting team

Documentation and Internal Policies

Documentation should reflect how the AI system actually works rather than exist separately from day-to-day operations.

The audit should review the AI system inventory, intended purpose, ownership, risk classification, data information, technical controls, monitoring processes, incident handling, human oversight procedures, change history, and other elements typically addressed through AI governance services.

A policy alone is not enough. Companies need technical and operational evidence showing that the documented controls actually exist and are being applied.

Prepare a Remediation Roadmap

After the audit, findings should be prioritized by severity, from critical or prohibited issues to high-priority compliance gaps, governance improvements, and long-term optimization.

The roadmap should account for regulatory deadlines, engineering complexity, business impact, dependencies, and cost. For existing products, it should also identify which gaps can be fixed through targeted modernization rather than a full rebuild. In many cases, adding logging, monitoring, human-review workflows, security controls, or documentation processes is faster and more cost-effective.

AI Act Readiness Audit

AI Act Readiness Audit

How SCAND Helps Companies Become EU AI Act Ready

SCAND can support companies on the technical side of EU AI Act readiness by helping assess and modernize existing AI-enabled applications. Depending on the system and identified compliance gaps, this may include improvements to architecture, data handling, security, access control, logging, monitoring, AI integrations, or user workflows. The goal is to help businesses adapt existing software where possible instead of automatically rebuilding the entire product from scratch, while legal and regulatory compliance decisions remain with the company and its compliance or legal advisors.

Conclusion

EU AI Act readiness starts with understanding which AI systems a company uses, where and why they are used, what role the organization plays in relation to them, and what risks each use case creates.

From there, companies need to assess the system’s scope, risk level, data flows, technical safeguards, documentation, monitoring, transparency, human oversight, and the team’s ability to work with AI safely and consistently. This approach helps reveal real compliance gaps and determine which changes are actually necessary.

SCAND can support companies on the technical side of this process by helping review existing AI-enabled applications, identify issues in architecture and workflows, and modernize specific components such as security, access control, logging, monitoring, data handling, or AI integrations.

If AI is already part of an existing product, start with an audit of the current system before deciding on a full rebuild. This makes it easier to understand which components truly need to change and which can be retained and adapted.

Frequently Asked Questions (FAQs)

What Is the EU AI Act Compliance Deadline in 2026?

The EU AI Act does not have a single compliance date that applies to every system. By August 2026, Article 50 transparency rules are already in force. Requirements for standalone high-risk systems listed in Annex III will take effect on December 2, 2027, while the corresponding rules for high-risk AI integrated into regulated products under Annex I will apply from August 2, 2028.

What Changed in the EU AI Act in 2026?

The main 2026 update is the revised implementation timeline for high-risk AI systems, while Article 50 transparency requirements started applying on August 2, 2026. Companies now have more time to prepare Annex III and Annex I systems, but transparency compliance is already a current requirement.

What Happens If My Company Doesn’t Comply With the EU AI Act?

Failure to meet the applicable requirements can create legal, financial, operational, and commercial problems. The most serious prohibited AI practices can lead to fines of up to €35 million or 7% of worldwide annual turnover, whichever is higher. Certain other breaches may carry penalties of up to €15 million or 3% of global annual turnover.

Who Needs to Comply With the EU AI Act?

The EU AI Act may apply to providers, deployers, importers, distributors, and certain product manufacturers. It can also apply to companies outside the EU if they place AI systems or GPAI models on the EU market or if the output of their AI systems is used within the European Union.

Does the EU AI Act Affect US Companies?

Yes, the EU AI Act can apply to US companies in certain cases. For example, it may apply if a US provider places an AI system or GPAI model on the EU market, or if the output of an AI system operated by a third-country provider or deployer is used in the EU. Having no EU headquarters does not automatically place a company outside the scope of the Act.

How Do High-Risk and Limited-Risk AI Systems Differ?

High-risk AI systems face a broader set of compliance obligations because they can have a greater impact on people’s rights, safety, or access to important services. Depending on the use case, companies may need formal risk controls, technical records, logging, human review mechanisms, security measures, and conformity procedures. Limited-risk systems generally carry lighter obligations, with the main emphasis on transparency, such as telling users when AI is involved or marking certain AI-generated or altered content.

What Does Conformity Assessment Mean Under the EU AI Act?

A conformity assessment is a formal check used to verify that a high-risk AI system satisfies the relevant EU AI Act requirements before it is launched or put into service. The exact process depends on the system: in some cases, the provider may carry out the assessment internally, while other cases can require the involvement of a notified body. If a high-risk system is substantially modified later, its conformity may need to be assessed again.

Author Bio
Head of ERP Solutions Department
Vadzim Tashlikovich Head of ERP Solutions Department
Vadzim Tashlikovich is a seasoned technology leader with over 20 years of experience in software architecture, large-scale system development, and strategic IT execution.

Looking for a Custom Fix?

SCAND’s the company to call for smart solutions and easy-going consulting.

Shoot us a message
and let's get started!
Contact us
Need Mobile Developers?

At SCAND you can hire mobile app developers with exceptional experience in native, hybrid, and cross-platform app development.

Mobile Developers Mobile Developers
Looking for Java Developers?

SCAND has a team of 50+ Java software engineers to choose from.

Java Developers Java Developers
Looking for Skilled .NET Developers?

At SCAND, we have a pool of .NET software developers to choose from.

NET developers NET developers
Need to Hire Web Developers Faster?

Bring the right skills to your project from day one.

Web Developers Web Developers
Need to Staff Your Team With React Developers?

Our team of 25+ React engineers is here at your disposal.

React Developers React Developers
Searching for Remote Front-end Developers?

SCAND is here for you to offer a pool of 70+ front end engineers to choose from.

Front-end Developers Front-end Developers
Other Posts in This Category
View All Posts

This site uses technical cookies and allows the sending of 'third-party' cookies. By continuing to browse, you accept the use of cookies. For more information, see our Privacy Policy.