← Back to Oethos
⚠ Enforcement begins August 2, 2026

EU AI Act Compliance Guide

The EU AI Act is the world's first comprehensive AI regulation. It applies to any organization deploying AI that affects EU citizens — regardless of where you're headquartered. Here's what you need to know.

What Is the EU AI Act?

The EU AI Act (Regulation 2024/1689) is a risk-based regulatory framework for artificial intelligence. It classifies AI systems by risk level and imposes requirements proportional to that risk. Think of it as GDPR for AI — extraterritorial, penalty-heavy, and designed to force organizations to take AI governance seriously.

The Act was formally adopted in March 2024. Full enforcement begins August 2, 2026.

The Four Risk Tiers

Every AI system you deploy falls into one of four categories:

⛔ Unacceptable Risk

Banned outright. Social scoring, real-time biometric surveillance in public spaces, AI that manipulates behavior to cause harm, systems that exploit vulnerable groups.

⚠ High Risk

Heavily regulated. AI in hiring/recruitment, credit scoring, law enforcement, medical devices, critical infrastructure, education (grading/admissions). Requires conformity assessments, human oversight, audit trails.

ℹ Limited Risk

Transparency required. Chatbots must disclose they're AI. Deepfakes must be labeled. Emotion recognition systems must inform users.

✓ Minimal Risk

No specific requirements. Spam filters, video game AI, inventory management. Most AI falls here — but you still need to prove it's minimal risk. That's the trap.

Key Dates

February 2, 2025 — Already in effect

AI literacy requirements. All staff interacting with AI must have adequate training. Prohibited AI practices (social scoring, manipulative AI) are banned.

August 2, 2025 — Governance structures

Member states must designate national AI authorities. Codes of practice for general-purpose AI take effect.

August 2, 2026 — Full enforcement

All high-risk AI requirements take effect. Conformity assessments, risk management systems, data governance, technical documentation, human oversight, accuracy/robustness requirements. This is the big one.

August 2, 2027 — Extended deadline

High-risk AI systems that are components of larger regulated products (medical devices, automotive) get an extra year.

Penalties

The EU AI Act has real teeth:

Prohibited AI practices

Up to €35 million or 7% of global annual revenue (whichever is higher)

High-risk violations

Up to €15 million or 3% of global annual revenue

Supplying incorrect information

Up to €7.5 million or 1.5% of global annual revenue

For reference: 7% of Apple's revenue would be €27 billion. These are GDPR-scale penalties applied to AI.

Does This Apply to You?

Yes, if any of these are true:

• You deploy AI systems available to people in the EU

• Your AI's output is used in the EU, even if you're based elsewhere

• You're a provider or deployer of AI systems, not just a user

• You use AI in hiring, credit, healthcare, education, or law enforcement

• You develop general-purpose AI models (GPT-like systems)

The Act applies extraterritorially — just like GDPR. Being a US or UK company does not exempt you.

What You Need to Comply

For High-Risk AI Systems:

Risk management system — continuous, documented, updated

Data governance — training data quality, bias monitoring, privacy

Technical documentation — how it works, what it was trained on, known limitations

Record-keeping — automatic logging of AI decisions (audit trail)

Transparency — clear instructions for human deployers

Human oversight — humans can intervene, override, or shut down the system

Accuracy and robustness — documented performance levels, cybersecurity measures

Conformity assessment — self-assessment or third-party audit before deployment

How to Start Preparing Today

You don't need to boil the ocean. Start with these steps:

1. Inventory your AI systems. List every AI tool in use across your organization. Include shadow AI (tools employees use without IT approval).

2. Classify each by risk tier. Most will be minimal. Some will surprise you.

3. Document your policies. SOPs, decision frameworks, escalation paths, data handling rules. If it's not written down, it doesn't exist.

4. Establish human oversight. For every AI decision that matters, define who reviews it and how.

5. Build audit trails. If a regulator asks "why did your AI do X?" — you need to answer.

6. Take the self-assessment. Our free AI Readiness Kit covers all 28 checkpoints across 6 domains. Same criteria as our $2,500 professional scan.

5 weeks until enforcement.

Our governance stack has been running for 2 years. We built the tools. We wrote the rules. We can help you get ready.

Free Readiness Kit Apply for Assessment