AxiLayer AI crestAxiLayerAI
Regulation (EU) 2024/1689

The EU AI Act, read as an auditor reads it.

The world's first comprehensive AI law is now in its decisive phase: since 2 August 2026, the core obligations for high-risk AI systems apply. This guide sets out who is in scope, what must be evidenced, and how AxiLayer AI's independent readiness assessments turn those obligations into documentation that survives scrutiny.

Instrument
Regulation (EU) 2024/1689
High-risk obligations
From 2 Aug 2026
Maximum penalty
€35M / 7% turnover
Scope

Who the Act reaches — including outside Europe

The EU AI Act is extraterritorial by design. It binds providers who place AI systems on the EU market or put them into service there, deployers established in the EU, and — critically — providers and deployers located anywhere in the world when the output of their AI system is used in the EU. Importers, distributors, and authorized representatives carry their own duties.

Obligations scale with risk. A small set of practices — social scoring, exploitative manipulation, most real-time remote biometric identification in public spaces — is prohibited outright. High-risk systems, listed in Annex III (employment, credit, education, essential services, law enforcement, migration, justice) or embedded as safety components in regulated products under Annex I, carry the Act's full requirements. General-purpose AI models have their own transparency and, for systemic-risk models, evaluation regime. Everything else faces lighter transparency duties or none.

What a high-risk provider must evidence

  • A documented, continuously maintained risk-management system (Article 9)
  • Data governance for training, validation, and testing sets — relevance, representativeness, error handling, bias examination (Article 10)
  • Technical documentation per Annex IV, kept current for ten years (Article 11)
  • Automatic event logging across the system's lifetime (Article 12)
  • Transparency and instructions for use that let deployers meet their own duties (Article 13)
  • Effective human oversight measures (Article 14)
  • Demonstrated accuracy, robustness, and cybersecurity (Article 15)
  • A quality management system, conformity assessment, CE marking, EU database registration, and post-market monitoring with serious-incident reporting

Deployers are not spectators: they owe fundamental-rights impact assessments in defined cases, oversight staffing, input-data controls, and log retention. Most enforcement stories so far begin with a deployer who assumed the provider had it covered.

Enforcement timeline

The deadlines, as they stand

  1. 1 August 2024
    Entry into force
    Regulation (EU) 2024/1689 enters into force twenty days after publication in the Official Journal.
  2. 2 February 2025
    Prohibitions and AI literacy
    Prohibited AI practices become unlawful; providers and deployers must ensure adequate AI literacy in their staff.
  3. 2 August 2025
    General-purpose AI and governance
    GPAI model obligations apply — technical documentation, copyright policy, training-data summaries, and for systemic-risk models, adversarial testing and incident reporting. The AI Office and national authorities take their posts, and penalties become applicable.
  4. 2 August 2026
    High-risk obligations (Annex III) — now in application
    The Act's core: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, quality management, conformity assessment, registration, and post-market monitoring for Annex III high-risk systems.
  5. 2 August 2027
    High-risk in regulated products (Annex I)
    AI safety components in machinery, medical devices, vehicles, and other Annex I product regimes come fully into scope, as do GPAI models placed on the market before August 2025.
How AxiLayer AI helps

From statutory text to defensible evidence

A readiness engagement is scoped to your portfolio and runs through four movements, each producing artifacts you keep.

Classification & scoping

Every AI system in the portfolio is classified against the Act's risk tiers — including the borderline cases where classification is genuinely contestable — with a written rationale you can show a market-surveillance authority. Extraterritorial exposure is mapped for non-EU entities.

Gap assessment against Articles 9–15

Independent, evidence-based testing of the high-risk requirements: we examine the risk-management file, sample the data-governance record, exercise the logging, and evaluate human-oversight measures as implemented, not as described.

Evidence preparation

Annex IV technical documentation, quality-management records, FRIA support for deployers, and the conformity-assessment file — assembled to the standard an examiner expects, with every claim traceable to a tested control.

Continuous compliance

Post-market monitoring is a standing legal duty, not a binder. Clients running AxiSentinel keep obligations, controls, and evidence synchronized as models retrain and harmonized standards land — continuously, between point-in-time assessments.

Questions we hear weekly

EU AI Act — asked and answered

Does the EU AI Act apply to companies outside the European Union?
Yes. It applies to any provider placing an AI system on the EU market or putting it into service in the EU, and to providers and deployers located outside the EU when the output of their AI system is used in the EU. A US or Asia-Pacific company serving EU customers — or whose model outputs reach EU users — is in scope.
When do the high-risk obligations take effect?
They already have, for most systems: Annex III high-risk obligations apply from 2 August 2026. Prohibitions applied from 2 February 2025 and general-purpose AI obligations from 2 August 2025. High-risk AI embedded in Annex I regulated products follows on 2 August 2027.
What are the penalties for non-compliance?
Up to €35 million or 7% of global annual turnover for prohibited practices; up to €15 million or 3% for breaching other obligations, including the high-risk requirements; up to €7.5 million or 1% for supplying misleading information to authorities.
What is a readiness assessment, and why do it before a conformity assessment?
A readiness assessment is an independent review of your systems against the Act's requirements, done before a regulator or conformity-assessment body examines them. Gaps get found and fixed on your schedule. It also produces the technical documentation and tested evidence that the formal process — internal-control or notified-body — will demand.
Is AxiLayer AI a notified body?
No — notified bodies are designated by EU member states. AxiLayer AI is an independent assessment firm that prepares organizations for those examinations, and for the majority of high-risk cases that use internal-control conformity assessment, with testing and evidence aligned to ISO/IEC 17020 inspection-body requirements.

The Annex III deadline has passed. Is your evidence ready?

A scoping briefing maps your portfolio to the Act's risk tiers and tells you exactly what an examiner would ask for — before one does.