What Is EU AI Act Compliance?
- Compliance means holding the right role, classifying each system correctly, meeting the duties attached to that classification, and being able to evidence it.
- There is no certificate and no regulator sign-off for most systems. You self-assess, document, and stand behind it.
- Providers and deployers carry different duties for the same system. Establishing which you are comes first.
- Article 50 transparency duties are live now. High-risk duties arrive 2 December 2027 for stand-alone Annex III systems.
- National market surveillance authorities enforce it, and the evidence they ask for is documentation you should already hold.
What compliance means
EU AI Act compliance means you have identified every AI system you provide or use, established your legal role for each, classified each against the Act's risk tiers, met the duties that classification attaches, and can produce the documentation to show it.
Unlike a certification, nobody issues you a compliance status. For the majority of systems you assess yourself, record the assessment, and hold the file. That makes documentation the substance of compliance rather than a by-product of it.
Provider or deployer?
The Act attaches different duties to different roles, and one company frequently holds both for different systems.
A provider develops an AI system, or has one developed, and places it on the EU market or puts it into service under its own name or trade mark. Providers carry the bulk of the duties: risk management, data governance, technical documentation, conformity assessment, registration.
A deployer uses an AI system under its own authority in a professional capacity. Deployer duties are lighter but real: using the system according to instructions, assigning human oversight to competent people, monitoring operation, keeping logs, and in certain cases informing affected people and carrying out a fundamental rights impact assessment.
A deployer can become a provider by accident. Putting your own name on a third-party system, substantially modifying it, or using it for a purpose the original provider did not intend can transfer the provider duties to you. This is one of the most common and most expensive misclassifications, and it is worth checking deliberately rather than assuming.
What compliance requires, tier by tier
| If your system is | Compliance means |
|---|---|
| Prohibited | Not deploying it. There is no compliant version |
| High risk | A risk management system, data governance, technical documentation, automatic logging, instructions for deployers, human oversight measures, accuracy and robustness, a quality management system, conformity assessment, EU database registration, and post-market monitoring |
| Subject to Article 50 | Telling people they are interacting with AI, marking synthetic content in machine-readable form, disclosing deep fakes, and informing people subject to emotion recognition or biometric categorisation |
| A general purpose AI model | Technical documentation, information for downstream providers, a copyright policy, and a public summary of training content, with additional duties where the model presents systemic risk |
| Minimal risk | No specific obligations, though you still need to have classified it to know that |
What is live today
Prohibited practices and the AI literacy duty have applied since February 2025. General purpose AI model obligations have applied since August 2025.
The Article 50 transparency obligations applied from 2 August 2026, with one carve-out: Article 50(2), the machine-readable marking of synthetic content, does not apply to systems already on the market on that date, and reaches them on 2 December 2026 instead.
Two new prohibitions, on AI generating non-consensual intimate imagery and child sexual abuse material, apply from 2 December 2026.
High-risk obligations apply from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products under Annex I. Those dates were moved by the Digital Omnibus on AI, adopted in June 2026.
What evidence you need to hold
For a high-risk system, the technical documentation required by Annex IV is the core artefact, and it is substantial: system description, development process, monitoring and control design, risk management records, data and data governance, human oversight measures, accuracy and cybersecurity measures, and the post-market monitoring plan.
For a deployer of a high-risk system in certain public and financial contexts, a fundamental rights impact assessment is required, and it has to be a real assessment rather than a form.
For anything caught by Article 50, the evidence is simpler but must exist: what the disclosure says, where it appears, and how synthetic output is marked.
Underneath all of it sits the inventory and the classification record. Being able to show which systems you assessed, when, on what basis, and who signed it off is what turns a set of documents into a defensible position. That is the record our EU AI Act service is built around.
Who enforces it
National market surveillance authorities in each Member State, coordinated through the European AI Office for general purpose AI models. Member States were required to designate these authorities, and several were late, which was part of the reason for the deferral.
Enforcement in practice will start where the harm is visible: complaints, incidents, and sectors where an existing regulator already has a relationship with the firms it supervises. For a regulated financial services firm, the practical expectation is that your existing supervisor asks AI governance questions long before an AI-specific authority does.
Does compliance with other frameworks help?
Substantially, though none of them substitutes for it.
ISO/IEC 42001 builds the AI management system the high-risk duties assume, and doing it first makes the Act's documentation requirements a mapping exercise rather than a writing exercise. See our ISO/IEC 42001 service page.
GDPR work covers part of the data governance ground, and where a system processes personal data a data protection impact assessment and a fundamental rights impact assessment share much of their content.
SOC 2 and ISO 27001 cover the security and change management controls the Act expects, but say nothing about model risk, bias or human oversight.
What to do next
Build the inventory and classify. Everything else in the Act depends on knowing what you have and which tier it falls in, and no deadline changes that.
Our free AI impact assessment gives a first view, and our readiness and gap assessment produces the requirement-by-requirement position for a fixed fee.
References
FAQ
What does EU AI Act compliance mean?
Identifying your AI systems, establishing whether you are provider or deployer for each, classifying them against the risk tiers, meeting the duties that follow, and holding the documentation to show it.
Is there an EU AI Act certificate?
Not for most systems. You self-assess and document. Third-party conformity assessment applies only to certain high-risk categories.
Can a deployer become a provider?
Yes. Putting your own name on a system, substantially modifying it, or using it for an unintended purpose can transfer the provider duties to you.
Which duties apply right now?
Prohibited practices, AI literacy, general purpose AI model obligations, and the Article 50 transparency duties as of 2 August 2026.
Does ISO/IEC 42001 make us compliant?
No, but it builds the management system the Act's high-risk duties assume, which makes the documentation work substantially smaller.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of regulatory practice advising firms through authorisation, supervision and examination. We take companies through the EU AI Act, ISO/IEC 42001, SOC 2 and ISO 27001, and maintain the position afterwards. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.
This guide is general information and is not legal advice on your particular circumstances.