The world's first comprehensive AI law is now in its decisive phase: since 2 August 2026, the core obligations for high-risk AI systems apply. This guide sets out who is in scope, what must be evidenced, and how AxiLayer AI's independent readiness assessments turn those obligations into documentation that survives scrutiny.
The EU AI Act is extraterritorial by design. It binds providers who place AI systems on the EU market or put them into service there, deployers established in the EU, and — critically — providers and deployers located anywhere in the world when the output of their AI system is used in the EU. Importers, distributors, and authorized representatives carry their own duties.
Obligations scale with risk. A small set of practices — social scoring, exploitative manipulation, most real-time remote biometric identification in public spaces — is prohibited outright. High-risk systems, listed in Annex III (employment, credit, education, essential services, law enforcement, migration, justice) or embedded as safety components in regulated products under Annex I, carry the Act's full requirements. General-purpose AI models have their own transparency and, for systemic-risk models, evaluation regime. Everything else faces lighter transparency duties or none.
Deployers are not spectators: they owe fundamental-rights impact assessments in defined cases, oversight staffing, input-data controls, and log retention. Most enforcement stories so far begin with a deployer who assumed the provider had it covered.
A readiness engagement is scoped to your portfolio and runs through four movements, each producing artifacts you keep.
Every AI system in the portfolio is classified against the Act's risk tiers — including the borderline cases where classification is genuinely contestable — with a written rationale you can show a market-surveillance authority. Extraterritorial exposure is mapped for non-EU entities.
Independent, evidence-based testing of the high-risk requirements: we examine the risk-management file, sample the data-governance record, exercise the logging, and evaluate human-oversight measures as implemented, not as described.
Annex IV technical documentation, quality-management records, FRIA support for deployers, and the conformity-assessment file — assembled to the standard an examiner expects, with every claim traceable to a tested control.
Post-market monitoring is a standing legal duty, not a binder. Clients running AxiSentinel keep obligations, controls, and evidence synchronized as models retrain and harmonized standards land — continuously, between point-in-time assessments.
A scoping briefing maps your portfolio to the Act's risk tiers and tells you exactly what an examiner would ask for — before one does.