Hael
Book a meeting
EU AI Act · Compliance

EU AI Act compliance

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 9 min read
Key takeaways
  • A compliance programme runs in five stages: inventory, classification, gap assessment, build, and ongoing monitoring.
  • Classification is the decision everything else depends on, and it is where most programmes go wrong.
  • Article 50 transparency duties are live now. High-risk duties arrive 2 December 2027 and 2 August 2028.
  • Typical first programmes run £15,000 to £50,000 depending on system count and how many are high risk.
  • The Act is not a one-off. Post-market monitoring and serious incident reporting continue for the life of the system.

The programme in outline

EU AI Act compliance is a programme with five stages: find every AI system, classify each one, assess the gap against the duties that classification attaches, build what is missing, and monitor for the life of the system. This overview covers each stage, the confirmed dates, and the numbers attached.

If you want the plain explanation of what the Act is rather than how to comply with it, that is in EU AI Act Explained.

Stage 1: Inventory

You cannot classify what you have not found. The inventory should list every AI system your organisation provides or uses, including systems bought as features inside other software, which is where most of the omissions occur.

For each system record: what it does, who owns it, what data it uses, whether it touches personal data, whether it makes or supports decisions about people, which markets it reaches, and whether it is offered under your name.

Systems bought rather than built are frequently missed, and they are the ones most likely to make you a deployer with duties you have not assessed.

Stage 2: Classification

Two determinations per system.

Your role. Provider or deployer, or both. Check whether you have put your own name on a third-party system, substantially modified it, or used it for a purpose the original provider did not intend, because any of those can move provider duties to you.

The tier. Prohibited, high risk under Annex III or Annex I, subject to Article 50 transparency duties, or minimal. Record the reasoning, not just the conclusion. A classification with no recorded basis is not defensible when someone asks.

This stage is where programmes most often go wrong, in both directions. Over-classification produces expensive obligations you did not owe. Under-classification produces a gap discovered late.

Stage 3: Gap assessment

Compare each system against the duties its classification attaches, and state what is met, what is not, and what closes each gap.

For high-risk systems the list is long: risk management system, data governance, Annex IV technical documentation, automatic logging, instructions for deployers, human oversight design, accuracy and robustness, quality management system, conformity assessment, EU database registration, post-market monitoring.

For Article 50 systems it is short but immediate, and it is live now.

Our readiness and gap assessment delivers this requirement by requirement for a fixed fee.

Stage 4: Build

Writing the technical documentation, establishing the risk management process, designing human oversight that a real person can actually perform, setting up logging that retains what the Act requires, and putting the disclosures in place where Article 50 applies.

The heaviest single item for a high-risk system is the Annex IV technical file. It is not a policy document. It describes the system, how it was developed, how it is monitored, what data trained it, how it is governed and how it performs, and it has to be kept current as the system changes.

Stage 5: Monitor

The Act does not end at a submission. Post-market monitoring runs for the life of a high-risk system, serious incidents must be reported to the relevant authority within defined windows, and the technical documentation must reflect the system as it currently is rather than as it was at launch.

This is the part that makes AI Act compliance a standing function rather than a project, and it is what our continuous governance and assurance service covers.

The confirmed timetable

DateWhat applies
2 February 2025Prohibited practices; AI literacy duty
2 August 2025General purpose AI model obligations; governance; penalties framework
2 August 2026Article 50 transparency obligations, except Article 50(2) for systems already on the market
2 December 2026Article 50(2) for those legacy systems; new prohibitions on nudifier and CSAM-generating AI
2 August 2027National AI regulatory sandboxes in operation
2 December 2027High-risk obligations, stand-alone Annex III systems
2 August 2028High-risk obligations, AI embedded in Annex I regulated products

These dates reflect the Digital Omnibus on AI, endorsed by the European Parliament on 16 June 2026, approved by the Council on 29 June 2026, and in force since July 2026.

What it costs

ComponentTypical range
Inventory and classification, small system estate£5,000 to £15,000
Gap assessment£5,000 to £20,000
Full readiness and build programme£15,000 to £50,000
Annex IV technical documentation, per high-risk system£8,000 to £25,000
Independent practitioner day rate£700 to £1,600
Ongoing monitoring and upkeepRetainer, scope dependent

Cost is driven by how many systems you have and how many are high risk, not by headcount. A company with forty employees and three high-risk systems costs more than one with four hundred employees and none.

Where programmes go wrong

Classification decided quickly and never written down, so nobody can reconstruct the reasoning a year later.

Bought systems left out of the inventory, so deployer duties go unassessed.

Human oversight designed as a sentence in a policy rather than as something a named person can actually do, with the time and the authority to intervene.

Technical documentation written once for launch and never updated, so it describes a system that no longer exists.

And treating the deferral as a pause, which leaves the live Article 50 duties unaddressed and the December 2026 prohibitions unnoticed.

What to do next

Inventory and classify. Every later obligation depends on those two, no deadline changes them, and they are the work the deferral gives you time to do properly.

Our free AI impact assessment gives an immediate first view, and the EU AI Act service page sets out how we run the full programme.

References

FAQ

How long does an EU AI Act compliance programme take?

Inventory and classification typically two to six weeks. A full build for a company with high-risk systems commonly three to six months, depending on how many technical files are required.

How much does EU AI Act compliance cost?

Commonly £15,000 to £50,000 for a first programme, driven by system count and how many are high risk rather than by company size.

Do we need to do anything before December 2027?

Yes. Article 50 transparency duties are live now, new prohibitions arrive on 2 December 2026, and classification takes long enough that starting late is the main risk.

Who enforces the EU AI Act?

National market surveillance authorities in each Member State, with the European AI Office coordinating on general purpose AI models.

Does the Act apply if we only sell to the UK and US?

Not unless your system is placed on the EU market or its output is used in the EU. That second limb catches more companies than expected, so it is worth checking rather than assuming.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across the EU AI Act, ISO/IEC 42001, SOC 2 and ISO 27001. Every engagement has a named practitioner and an agreed scope, timetable and fee. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not legal advice on your particular circumstances.

Free check

See where you stand on EU AI Act, free.

Answer a short set of questions and see what EU AI Act expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether EU AI Act applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to EU AI Act.

Or speak to us about your deadline. Book a meeting.