Complete Guide EU AI Act ⚠ August 2 2026 Deadline

EU AI Act Compliance Guide for Small & Mid-Market Businesses

The EU AI Act — Regulation (EU) 2024/1689 — is the world's first comprehensive horizontal AI law. It reaches companies on an extraterritorial basis, so any AI system whose output affects a natural person in the EU is in scope regardless of where you are headquartered. By August 2 2026 every deployer of a high-risk system must produce a risk management record, a conformity assessment, human oversight, transparency notices, and post-market monitoring. Use this guide to walk the scope test, classify your AI against the five risk tiers, satisfy GPAI obligations if you fine-tune at scale, deliver the Art. 50 transparency notices, and avoid penalties up to €35M / 7% of global turnover. Start with the free AI compliance assessment, or skim a sample compliance plan first.

Create a workspace → Guided intake → See Sample Plan

12 questions · 5 minutes · Instant score · No account required

TL;DR — Three Things You Must Know
Scope & Applicability

Does the EU AI Act apply to you? The three-question scope test

The EU AI Act assigns obligations by role (provider, deployer, importer, distributor, product manufacturer) and by risk class. If you can answer yes to the three questions below with respect to a given AI system in your stack, the system is in scope and you have to determine which of the five risk tiers applies to it.

The five roles under Article 3 of Regulation (EU) 2024/1689 (the official EU AI Act text):

🏗️
Provider (Art. 3(1))
Develops or has the AI system developed and places it on the market under its own name
👤
Deployer (Art. 3(4))
Uses an AI system under its own authority — most SMBs are deployers
📦
Importer (Art. 3(2))
Places an AI system from a non-EU provider on the EU market
🏪
Distributor (Art. 3(3))
Makes an AI system available besides the provider or importer
🛠️
Product Manufacturer (Art. 3(5))
Places a product with an embedded AI system on the EU market
🧬
Affected Persons
Natural persons exposed to an AI system in the EU — the test for extraterritorial reach

Use these three questions to determine whether the EU AI Act applies to a given AI system:

01

Is the AI system's output used in the EU?

Is the system's output — a credit decision, a screening result, a piece of generated content, a biometric inference — consumed by a natural person located in the EU, regardless of where you as the deployer are headquartered? Pure internal analytics with no EU consumer or employee touchpoint is typically out of scope.

Yes → Proceed to Question 2   No → EU AI Act obligations do not apply to this system (verify with counsel)
02

Are you a provider, deployer, importer, distributor, or product manufacturer?

Do you operate the AI under your own authority, place it on the EU market, import it, distribute it, or manufacture a product with embedded AI? Buying and using a vendor's tool makes you a deployer; fine-tuning or substantially modifying a high-risk model can make you a provider too.

Yes → Proceed to Question 3 No → No role assigned; obligations may still apply if you integrate the AI downstream
03

Does the use case fall under Article 5 (prohibited), Annex III (high-risk), or Article 50 (transparency)?

Article 5 prohibits specific practices outright. Annex III enumerates eight high-risk categories. Article 50 imposes transparency duties on AI that interacts with natural persons, generates synthetic content, performs emotion recognition, or produces deepfakes. If your AI is in any of these three categories, the EU AI Act applies to that system.

Yes → EU AI Act applies. Determine the risk tier and apply the corresponding obligations.

The extraterritorial reach rule under Article 2 — what counts

Article 2 of the EU AI Act applies the regulation to (a) providers placing AI systems on the EU market, (b) deployers established in the EU, and (c) providers and deployers outside the EU where the AI system's output is used in the EU. Buying and using a vendor's AI tool does not shield you from the Act when the output crosses into EU territory. The test is where the output is used, not where your servers sit or where your company is incorporated. Source: Regulation (EU) 2024/1689, Article 2 — EUR-Lex.

Risk Classification

The five EU AI Act risk tiers — what each one demands

Every in-scope AI system falls into exactly one of five tiers. The tier drives the obligations: the higher the risk, the more documentation, oversight, and operational practice the Act requires. Below is the full operational framework for each tier as it applies to SMBs.

🚫

A. Prohibited (Art. 5)

Article 5 prohibits specific AI practices outright. These are not high-risk — they are not permitted in any context, with narrow exceptions for law enforcement in certain listed cases. Deployers cannot use these systems for any purpose; providers cannot place them on the EU market.

  • Subliminal manipulation or deception causing harm
  • Exploitation of vulnerabilities (age, disability, social/economic situation)
  • Social scoring by public authorities leading to detrimental treatment
  • Predictive policing based solely on profiling or personal characteristics
  • Untargeted scraping of facial images to build facial recognition databases
  • Emotion recognition in workplace and education (with limited exceptions)
  • Biometric categorisation inferring sensitive attributes (race, religion, etc.)
  • Real-time remote biometric identification in publicly accessible spaces (law enforcement only)
⚠️

B. High-Risk Annex III

AI systems in the eight Annex III categories, plus AI safety components of products covered by Annex I EU harmonisation legislation (medical devices, machinery, toys, etc.). High-risk obligations become enforceable on August 2 2026 and include the full provider + deployer stack: risk management, data governance, technical documentation, conformity assessment, transparency, human oversight, accuracy/robustness/cybersecurity, post-market monitoring.

  • Biometric identification and categorisation of natural persons
  • Management and operation of critical infrastructure
  • Education and vocational training (admissions, assessment, proctoring)
  • Employment, HR, worker management, access to self-employment
  • Access to essential private and public services and benefits
  • Law enforcement (predictive risk, profiling, evidence evaluation)
  • Migration, asylum, and border control management
  • Administration of justice and democratic processes
🪧

C. Limited Risk / Art. 50 Transparency

AI that interacts with natural persons, generates synthetic content, performs emotion recognition or biometric categorisation, or produces deepfakes. Article 50 imposes transparency duties: tell people they are interacting with AI, mark synthetic content in a machine-readable manner, and disclose deepfake manipulation. These obligations apply in addition to whatever other tier the system also falls into.

  • Disclose AI interaction to natural persons (unless obvious from context)
  • Mark AI-generated or AI-manipulated content in machine-readable format
  • Inform exposed persons of emotion recognition systems in operation
  • Notify persons subject to biometric categorisation systems
  • Disclose deepfake content as artificially generated or manipulated
  • Apply disclosure at the point of interaction, not buried in a privacy policy

D. Minimal Risk

AI systems outside the prohibited, high-risk, transparency, and GPAI categories. The EU AI Act applies no mandatory obligations beyond voluntary best-practice codes of conduct. The vast majority of consumer-grade AI features — spam filters, content recommenders, navigation tools — sit here. Voluntary codes are encouraged; the Commission publishes model codes for self-assessment.

  • No mandatory obligations under the EU AI Act
  • Voluntary best-practice codes of conduct encouraged
  • Recommend documenting the AI use and category rationale
  • AI literacy training under Article 4 still applies to staff
  • GDPR, IP, and consumer protection law may still apply parallelly
  • Track regulatory status — re-evaluate if the use case shifts
🧠

E. GPAI Models (Art. 51–55)

General-Purpose AI models — the foundation models that can be integrated into many downstream systems. A separate obligation stack applies to GPAI providers under Articles 51–55, with additional systemic-risk obligations for models trained above 10²⁵ FLOPs of compute. SMBs are unlikely to train GPAI from scratch but may inherit obligations if they fine-tune or significantly modify such models.

  • Technical documentation per Annex XI
  • Public training-data summary per Annex XI (co-developed with AI Office)
  • Copyright compliance policy under Article 53(1)(c)
  • Downstream cooperation duty with GPAI integrators
  • Systemic-risk obligations if trained above the 10²⁵ FLOPs threshold
  • Model evaluation, adversarial testing, serious-incident reporting if systemic
📚

F. AI Literacy Training (Art. 4)

Article 4 applies to every provider and deployer in scope of the Act, regardless of which risk tier the system falls into. Providers and deployers must ensure, to the best of their ability, a sufficient level of AI literacy of their staff and any other person handling the operation and use of AI systems on their behalf. For SMBs this is typically documented training, role-based competency expectations, and refresher cadence.

  • Applies regardless of which tier your system sits in
  • Technical knowledge, experience, education, training, and context
  • Documented training program with attendance records
  • Role-based competency expectations for AI operators
  • Refresher cadence aligned with deployments and regulatory updates
  • Operator-level sign-off on AI systems before handling them
GPAI Obligations

GPAI obligations under Articles 51–55 — when SMBs become a model provider

The EU AI Act carves out a separate obligation stack for General-Purpose AI model providers under Articles 51–55. Most SMBs will be GPAI integrators, not providers — but a non-trivial fine-tuning or downstream modification can shift your role. Here is what each path looks like.

Article 53, applicable to GPAI providers regardless of systemic-risk status, requires four operational deliverables:

Article 55 imposes additional obligations on GPAI models with systemic risk — a presumption that applies to any model trained on more than 10²⁵ FLOPs of compute. Practical obligations:

When does an SMB become a GPAI provider?

Training a foundation model from scratch above the 10²⁵ FLOPs threshold is computationally infeasible for an SMB. However, fine-tuning can shift your role. If your downstream modification materially changes the model's capabilities, capabilities profile, or intended purposes, you may become a provider yourself — inheriting Article 53 obligations for the modified model. The trigger is functional, not merely technical: it is whether the modifications "materially change" the model. If you only perform light-weight customisation (prompt-tuning, retrieval-augmented generation on a closed model without retraining weights, low-rank adapters with negligible capability change), you typically remain an integrator. Source: Regulation (EU) 2024/1689, Articles 51–55 — EUR-Lex.

Transparency Duties

Article 50 transparency — what deployers must tell users

Article 50 imposes specific transparency duties on deployers of AI systems that interact with natural persons, generate synthetic content, perform emotion recognition, or generate deepfakes. These duties apply in addition to whatever tier the system sits in — even a limited-risk AI carries Art. 50 obligations where the listed triggers apply.

Article 50 covers four deployer-side transparency scenarios:

💬

1. AI Interaction

Article 50(1): Deployers of an AI system that interacts directly with natural persons must inform those persons that they are interacting with an AI system, unless this is obvious to a reasonably well-informed natural person having regard to the circumstances and context of use.

  • Disclose at the point of first interaction
  • Plain language, not buried in a privacy policy
  • If using a chatbot, the disclosure can be inline at the top of every conversation
  • If the system is obvious from context (a visible robotic arm on a manufacturing line), no separate disclosure is required
🧾

2. Synthetic Content (Art. 50(4))

Deployers of an AI system that generates synthetic audio, image, video, or text content must mark that content in a machine-readable format and detectable as artificially generated or manipulated. Providers must enable this through technical solutions effective at the point of first generation.

  • Watermark or metadata visible to the consumer
  • Machine-readable marker detectable by tooling of the AI Office
  • Effective at the time of first generation, not retrofitted
  • Applies to text as well as audio/image/video content
🙂

3. Emotion Recognition

Deployers of emotion recognition systems must inform the exposed natural persons of the operation of the system, and process the personal data in compliance with GDPR. Limited exceptions apply for law enforcement, medical, or safety purposes with appropriate safeguards.

  • Notice before the system operates on a person
  • Identify the categories of emotion being inferred
  • Apply appropriate GDPR safeguards for biometric data
  • Documented legal basis for any emotion data processed
🎭

4. Deepfakes

Deployers who generate or manipulate image, audio, or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated. The disclosure must be clear, prominent, and provided at the latest when the content is first presented.

  • Disclose clearly that content is artificially generated or manipulated
  • Disclosure must be prominent at first presentation
  • Artistic, creative, satirical, or fictional contexts retain the disclosure obligation
  • Failure to disclose is enforceable by Member State authorities
🪪

5. Biometric Categorisation

Deployers of biometric categorisation systems that infer sensitive attributes (race, political opinions, religious beliefs, etc.) must inform exposed natural persons and obtain appropriate consent where required. Categorisation systems inferring sensitive attributes are generally prohibited under Article 5(1)(g) outside limited exceptions.

  • Notify exposed persons of the categorisation operation
  • Categorisation to infer sensitive attributes is generally prohibited
  • Document lawfulness basis and exceptions
  • Link to Art. 9 GDPR for special-category personal data
📈

6. Provider-Side Disclosure (Art. 50(2)–(3))

Provider-side obligations also apply: providers of AI systems generating synthetic content must ensure their outputs are machine-readable and detectable as artificially generated, effective at the point of first generation. Providers of general-purpose AI models must enable downstream deployers to comply with their Art. 50 duties through technical solutions.

  • Provider enables technical watermarking at generation time
  • Provider cooperates with AI Office detection tooling
  • Provider supports deployer-side compliance with technical documentation
  • Both deployer disclosure and machine-readable marking required

FAQ answers below include Art. 50 specifics: jump to the FAQ → or read the full Regulation on EUR-Lex.

Enforcement Timeline

Key dates for EU AI Act compliance

The EU AI Act's enforcement rolls in phases. Two phases already complete; the third — high-risk — is now live. Here are the milestones every SMB should have on its compliance calendar.

February 2 2025 — Done

Prohibited Practices Enforceable (Art. 5)

Article 5 prohibitions became enforceable. AI systems engaged in subliminal manipulation, exploitation of vulnerabilities, social scoring by public authorities, predictive policing based on profiling, untargeted facial scraping, workplace emotion recognition (with limited exceptions), and real-time remote biometric identification in publicly accessible spaces (law enforcement only) are now prohibited. Member State authorities enforce.

August 2 2025 — Done

GPAI Obligations Enforceable (Art. 51–55)

Articles 51–55 became enforceable for GPAI model providers placed on the EU market. Technical documentation under Annex XI, public training-data summary co-developed with the AI Office, copyright compliance policy under Article 53(1)(c), and the downstream cooperation duty are now live. Models above 10²⁵ FLOPs of compute presumed to carry systemic risk and carry the additional Article 55 obligations.

LIVE
August 2 2026 — Now Live

High-Risk Obligations Enforceable (Annex III + Annex I)

High-risk AI systems — Annex III categories and Annex I safety components — become fully enforceable. Deployers must complete and maintain their compliance record: risk management system across the lifecycle, data governance with relevant and representative datasets, technical documentation per Annex IV, conformity assessment on file, transparency notices and instructions for use, human oversight operational, appropriate accuracy/robustness/cybersecurity, and post-market monitoring. The major operational milestone for SMBs.

LIVE
August 2 2026 — Now Live

Existing High-Risk AI Embedded in Regulated Products

AI systems that are safety components of products covered by Annex I EU harmonisation legislation (e.g. medical devices, machinery, in-vitro diagnostics, toys) and were placed on the market before the relevant high-risk deadline must complete the conformity assessment and re-register. This transition rule exists to accommodate long product cycles in regulated industries — but it is not a deferral of the substance of the obligations.

MS
Ongoing — Member State Designation

National Penalties + Competent Authority Designation

Member States designate national competent authorities responsible for enforcement of the EU AI Act, and publish their penalty-design rules. Penalties are enforced at Member State level; the EU AI Act sets the upper bounds (€35M, €15M, €7.5M) and Member States determine the actual application, including any lower tiers for SMEs. Article 99 specifically caps the percentage-of-turnover amounts at the absolute euro figures for small and micro enterprises.

Downloadable Checklist

The EU AI Act compliance checklist — print or save as HTML

The five risk-tier obligation sets are reproduced below in checklist form for easy operational use. A separate print-friendly HTML version is also available for download — it strips out styling chrome and renders cleanly on letter-size paper or as a saved reference document for your compliance team.

🚫

A. Prohibited Practices (Art. 5)

  • Confirm no subliminal manipulation in deployed systems
  • Confirm no exploitation of vulnerability use cases
  • Confirm no social scoring by or for public authorities
  • Confirm no predictive policing based on profiling
  • Confirm no untargeted facial scraping for recognition databases
  • Confirm no workplace or education emotion recognition
  • Confirm no sensitive-attribute biometric categorisation
  • Confirm no real-time remote biometric ID (law enforcement only)
⚠️

B. High-Risk Annex III / Annex I

  • Risk management system across lifecycle (Art. 9)
  • Data governance: relevant and representative datasets (Art. 10)
  • Technical documentation per Annex IV (Art. 11)
  • Event logging capabilities (Art. 12)
  • Transparency to deployers: instructions for use (Art. 13)
  • Human oversight measures effective (Art. 14)
  • Accuracy, robustness, cybersecurity appropriate (Art. 15)
  • Conformity assessment completed and CE marking affixed
  • EU database registration (Art. 49 / Art. 71)
  • Post-market monitoring system per Art. 72 live
  • Serious-incident reporting procedure documented
  • Quality management system in place (Art. 17)
🪧

C. Limited Risk / Art. 50 Transparency

  • AI-interaction disclosure to natural persons (Art. 50(1))
  • Synthetic content marked in machine-readable format (Art. 50(4))
  • Emotion recognition exposed-person notice (Art. 50(3))
  • Biometric categorisation notice (Art. 50(3))
  • Deepfake disclosure at first presentation (Art. 50(4))
  • Disclosures in plain language at the point of interaction
  • Provider enables machine-readable markers at generation time

D. Minimal Risk

  • No mandatory EU AI Act obligations
  • Voluntary best-practice codes of conduct in mind
  • Document the AI use and the rationale for the risk tier chosen
  • Article 4 AI literacy training still applies to staff
  • GDPR, IP, and consumer protection law remain independent
  • Re-evaluate classification if use case shifts
🧠

E. GPAI Model Obligations (Art. 51–55)

  • Technical documentation per Annex XI
  • Public training-data summary per Annex XI
  • Copyright compliance policy under Art. 53(1)(c)
  • Directive 2019/790 Art. 4(3) opt-out compliance
  • Downstream cooperation duty with GPAI integrators
  • Determine whether model crosses 10²⁵ FLOPs systemic-risk threshold
  • If systemic: state-of-the-art model evaluation + adversarial testing
  • If systemic: serious-incident reporting to the AI Office
  • If systemic: cybersecurity protection for model + infrastructure
  • If systemic: energy-efficiency reporting methodology

Save the checklist — printable HTML version

A standalone, print-friendly version of this checklist is available at /checklists/eu-ai-act-checklist.html. It is sized for letter paper, contains no JavaScript or analytics, and is suitable for printing and including in your compliance binder or sharing with your legal team.

Regulatory Comparison

EU AI Act vs. Colorado SB 24-205 / SB 26-189 — side by side

If your company serves EU residents or deploys AI with extraterritorial reach, the EU AI Act is independent of Colorado's SB 24-205 and SB 26-189. The trigger, scope, enforcement authority, penalty structure, and disclosure rules differ. A complete multi-jurisdiction program addresses each regime with its own evidence base.

Dimension EU AI Act Colorado SB 24-205 / SB 26-189
Trigger AI system whose output is used in the EU; or provider placing AI on the EU market AI system touching Colorado consumers in a covered context (procurement, screening, finance, healthcare, etc.)
Scope Risk-tiered: prohibited / high-risk Annex III / Art. 50 transparency / GPAI / minimal risk SB 24-205: 7 consequential-decision domains; SB 26-189: 6 covered contexts (broader)
Extraterritorial reach Yes — Art. 2 covers non-EU providers and deployers where output is used in EU Yes — applies to AI interacting with Colorado consumers regardless of company HQ
AI system inventory Required for high-risk systems (Annex IV technical documentation) and database registration SB 26-189 requires documented inventory with quarterly review
Impact / risk assessment Risk management system across full lifecycle (Art. 9); not named "impact assessment" SB 26-189 impact assessment with 9 specific elements + executive sign-off
Consumer disclosures Art. 50 transparency duties; AI interaction + synthetic content + deepfake markers SB 26-189 pre-interaction + post-decision + data category disclosures
Vendor management Deployers' Art. 26 obligations on humans, input data, monitoring; provider liability under Art. 16 SB 26-189 enumerated procurement clauses with 30-day update notice
Ongoing monitoring Post-market monitoring per Art. 72 (provider); Art. 26 (deployer); serious-incident reporting SB 26-189 quarterly inventory + annual reassessment + change-trigger rules
Affirmative defense No formal affirmative defense; framework adoption supports compliance posture SB 24-205 NIST AI RMF / ISO 42001 = rebuttable presumption of reasonable care
Maximum penalty €35M / 7% (prohibited); €15M / 3% (other); €7.5M / 1% (incomplete info) $20,000 per violation under Colorado Consumer Protection Act
Private right of action Restricted; primarily Member State authority enforcement (with sector-specific carve-outs) No — AG enforcement only
Best compliance posture Run a risk-classification inventory; map each in-scope system to Article 9–15 + Art. 26 obligations; deploy Art. 50 disclosures; satisfy Art. 4 AI literacy NIST AI RMF adoption + annual review + AG reporting on incidents

Sources: Regulation (EU) 2024/1689 — EUR-Lex; Colorado SB 24-205; Colorado SB 26-189. If you're building a program that covers both, see our SB 26-189 deep dive and our existing EU AI Act SMB pillar.

How GovernIQ Helps

From this guide to an EU AI Act compliance plan in under an hour

Knowing the law is the first step. Knowing exactly which of your AI systems are in scope under the EU AI Act, which risk tier applies to each, and getting a prioritized written action plan before the August 2 2026 enforcement deadline is the second. GovernIQ automates the gap analysis — built specifically for SMBs, not enterprise GRC teams.

01

12-Question Assessment

Covers AI tool inventory, data handling practices, employee training status, policy governance, vendor management, and monitoring posture. Takes 5 minutes. Generates a 0–100 compliance score and identifies up to 8 specific policy gaps — mapped to the EU AI Act risk tiers and the August 2 2026 high-risk deadline.

Take the Assessment →
02

Sample Compliance Plan

See a real example of the personalized Compliance Action Plan output for a fictional financial advisory firm facing similar EU AI Act risk-classification and conformity-assessment obligations. Understand what you'll get before you purchase.

View Sample Plan →
03

Personalized Action Plan

After a $299 one-time purchase, receive a full Compliance Action Plan specific to your company's AI stack, EU AI Act risk classification, SB 26-189 / SB 24-205 gaps, risk level, and industry — with actionable items, risk management templates, Art. 50 disclosure language, vendor contract clause library, monitoring cadence, and an August 2 2026 remediation roadmap.

See Pricing →
Frequently Asked Questions

EU AI Act compliance — the questions we hear most

Does the EU AI Act apply to my company if I am not based in the EU?
Yes, frequently. Article 2 applies the EU AI Act on an extraterritorial basis: providers placing AI systems on the EU market, deployers established in the EU, and providers and deployers outside the EU where the AI system's output is used in the EU. If your AI tool's output affects a natural person located in the EU — credit decisions served to EU residents, employment screening of EU candidates, or content delivered to EU users — the EU AI Act reaches your organisation regardless of where you are headquartered. The test is where the output is used, not where your servers sit. Source: Regulation (EU) 2024/1689, Article 2 — EUR-Lex. To understand your scope and risk tier, start with our free AI compliance assessment.
Am I a provider or a deployer under the EU AI Act?
Article 3 defines five roles — provider, deployer, importer, distributor, and product manufacturer. Most SMBs are deployers: they buy or subscribe to AI tools and use them in their business operations under their own authority. You become a provider if you develop (or have developed) an AI system and place it on the EU market under your own name, or if you fine-tune or substantially modify a model in such a way that the output materially changes its capability profile. The role matters because each role carries its own obligation stack — and if your modification is material, you may inherit provider obligations on top of your deployer ones. The distinction is functional, not contractual. Take our 12-question assessment to map your role and obligations.
When does the EU AI Act's August 2 2026 deadline start applying?
August 2 2026 is the high-risk obligations enforcement date. From that day forward, every deployer of an Annex III or Annex I high-risk AI system must have a documented risk management system, data governance evidence, technical documentation, conformity assessment, transparency notices, human oversight, appropriate accuracy/robustness/cybersecurity, and an operational post-market monitoring program. Prohibited practices have been enforceable since February 2 2025. GPAI obligations became enforceable August 2 2025. Member State penalty designations are ongoing. If you have any in-scope AI in production and have not started your compliance record, start today — most SMBs need 4–8 weeks per system assessed.
What counts as a high-risk AI use case under the EU AI Act?
Annex III enumerates eight categories: biometric identification and categorisation of natural persons; management and operation of critical infrastructure; education and vocational training; employment, workers management, and access to self-employment; access to essential private and public services and benefits; law enforcement; migration, asylum, and border control management; administration of justice and democratic processes. Separately, AI systems that are safety components of products covered by Annex I EU harmonisation legislation (medical devices, machinery, in-vitro diagnostics, toys, etc.) are also high-risk regardless of Annex III. If you do not deploy an AI in any of these categories, you may still be subject to limited-risk Art. 50 transparency duties, or — if you fine-tune at scale — to GPAI obligations. Source: Regulation (EU) 2024/1689, Annex III — EUR-Lex.
What are the EU AI Act's penalties?
Three tiers. Article 5 prohibited practices: up to €35M or 7% of global annual turnover, whichever is higher. Failure to comply with provider, deployer, importer, distributor, or notified-body obligations: up to €15M or 3% of global annual turnover. Supplying incorrect or incomplete information to notified bodies or competent authorities: up to €7.5M or 1% of global annual turnover. SMEs specifically benefit from a lower ceiling: Article 99 caps the percentage-of-turnover amounts at the absolute euro figures for small and micro enterprises. Member State authorities enforce; the EU AI Act sets the upper bound but each Member State determines the actual application. Penalties are distinct per violation per system — multiple noncompliant systems create stacking exposure.
Does AI built into vendor software create EU AI Act obligations for my business?
Embedded AI shifts provider obligations to the vendor that placed the product on the EU market — but deployer obligations remain with you. If you use a vendor product with an embedded AI system that operates as a high-risk Annex III use case inside your business, you are still the deployer and must operate the system in compliance with Article 26: assign human oversight to appropriately competent staff, ensure input data is relevant and sufficiently representative, monitor operation for risks, and inform the provider and competent authorities of serious incidents or risk of harm. You cannot transfer deployer obligations to the vendor through contract. The deployer test is use of the system under your own authority — not who wrote the model or who sold you the subscription.
What does the EU AI Act require for AI literacy training (Article 4)?
Article 4 requires every provider and deployer in scope of the Act to ensure, to the best of their ability, a sufficient level of AI literacy of their staff and any other person handling the operation and use of AI systems on their behalf. AI literacy takes into account technical knowledge, experience, education, training, and the context the AI is used in. For most SMBs, this means documented training for staff who operate AI in scope, role-based competency expectations, and a refresher cadence aligned with regulatory updates. Article 4 applies regardless of which risk tier your AI sits in — even minimal-risk AI carries the AI literacy obligation for the staff that operate it.
What are the GPAI obligations under the EU AI Act?
Articles 51–55 impose duties on providers of General-Purpose AI models. Article 53 requires: technical documentation per Annex XI; a public training-data summary per Annex XI co-developed with the AI Office; a copyright compliance policy under Article 53(1)(c) that respects opt-outs under Directive (EU) 2019/790 Article 4(3); and a downstream cooperation duty supporting GPAI integrators. Models trained above 10²⁵ FLOPs of compute carry additional Article 55 systemic-risk obligations: state-of-the-art model evaluation and adversarial testing, serious-incident reporting to the AI Office, cybersecurity protection, and energy-efficiency reporting. SMBs are unlikely to train GPAI from scratch above the threshold — but if your downstream modification materially changes a model's capabilities, you may become a provider yourself and inherit the Article 53 stack. Source: Regulation (EU) 2024/1689, Articles 51–55 — EUR-Lex.
What Article 50 transparency obligations apply to deployers?
Article 50 imposes specific deployer-side transparency duties for AI in four categories: (a) AI systems that interact directly with natural persons must inform those persons that they are interacting with AI, unless obvious from context; (b) AI that generates synthetic audio, image, video, or text content must mark it in a machine-readable format detectable as artificially generated or manipulated, and providers must enable this through technical solutions effective at the point of first generation; (c) emotion recognition systems and biometric categorisation systems must inform exposed persons of the operation; (d) deepfake deployments must disclose that the content has been artificially generated or manipulated. Failure to comply is enforceable by Member State authorities, with fines up to €15M / 3% of global turnover. Verify the Article 50 specifics against the official text on EUR-Lex.
What does ongoing post-market monitoring require under the EU AI Act?
Providers of high-risk AI must establish and document a post-market monitoring system proportionate to the nature of the system under Article 72, actively and systematically collecting, documenting, and analysing data on the AI's performance throughout its lifetime. Serious incidents must be reported to the competent authorities of the Member State where the incident occurred. Deployers must inform the provider of any serious incident or risk of harm, assign human oversight, monitor operation, and ensure input data relevance and representativeness under Article 26. The post-market monitoring file must be retained for the lifetime of the system plus an appropriate period, not exceeding ten years. The monitoring loop converts a one-time posture into a continuously defensible record — and is the evidence competent authorities request if an investigation is opened. Begin the loop with our free AI compliance assessment.
📋
Free Tool — No signup required
Need a starting policy before the August 2 2026 deadline? Get a customized AI Acceptable Use Policy in 60 seconds.
Includes AI system inventory template, EU AI Act risk-classification checklist, Art. 50 disclosure language, and reporting escalation path — generated for your org.
Build Your Policy Free →

Find out which of your AI systems are in scope — before August 2 2026.

The GovernIQ assessment maps each of your AI systems to the EU AI Act risk tiers, checks Article 4 AI literacy, Article 50 transparency readiness, and the high-risk operational framework, and tells you exactly what to fix before enforcement begins. Free. No account required.

Create a workspace → Guided intake → See a Sample Report

Free assessment · Personalized Compliance Action Plan $299 · No subscription