EU AI Act Compliance

Your business is in scope for the EU AI Act.
The deadline is 2 August 2026.

The EU AI Act applies to any business — anywhere in the world — with EU employees, EU customers, or EU operations. Not just EU companies. If you use AI tools that produce outputs EU users see, you have compliance obligations. Most businesses don't know this yet.

EU AI Act obligations apply from 2 August 2026

See the full enforcement timeline →

Important

The transparency duties land on one date, they apply to you at any size, and there is no "wait and see" option.

From 2 August 2026, deployer obligations are enforceable. Businesses that interact with EU customers or employees using AI — regardless of size, regardless of country — are in scope on day one. The Act does make allowances for smaller firms elsewhere: simplified technical documentation (Article 11), priority sandbox access (Article 62), lighter quality-management duties for microenterprises (Article 63), and fines capped at the lower figure (Article 99(6)). None of them delays the transparency duties above, and none of them applies automatically — you have to have done the work. If you haven't started, you are already behind.

Not sure if you're in scope? Answer 7 questions and get your free EU AI Act exposure report — instant, no sign-up.

Take the Free Check →
Scope

Most businesses think the EU AI Act doesn't apply to them. They're wrong.

The EU AI Act has the same extra-territorial reach as GDPR. You don't need to be based in the EU to be in scope. You need to have a connection to the EU.

🇪🇺
EU customers or users

If your website, product, or service is used by people in EU member states, you're in scope.

👥
EU employees or contractors

Any AI used in HR decisions, performance reviews, or hiring that affects EU-based staff triggers deployer obligations.

🤝
EU suppliers or business partners

Supply chain obligations mean your AI practices may need to meet EU standards even in B2B contexts.

📊
AI outputs reaching EU citizens

Article 50 transparency obligations apply whenever an AI system — chatbot, recommendation engine, content generator — produces outputs that EU citizens interact with.

Fines for non-compliance: up to €35 million or 7% of global annual turnover, whichever is LOWER for a small or medium business — in practice 7% of turnover.

Timeline

The EU AI Act is already in force. Here's what's live.

August 2024
Act enters into force

The EU AI Act becomes law. The clock starts.

February 2025
Prohibited practices banned — live now

Unacceptable-risk AI systems (social scoring, certain biometric uses) are prohibited. Any business using these practices is already non-compliant.

August 2025
General-purpose AI rules + fines enforceable — live now

Rules for general-purpose AI models (including ChatGPT, Copilot, Claude) are now in force. Enforcement and fines are active.

2 August 2026
Enforcement begins — transparency and deployer obligations

Article 50 transparency disclosures and deployer obligations (Article 26) become enforceable, and national regulators gain their enforcement powers. This is the deadline that affects most businesses.

2 December 2026
Synthetic content marking

New prohibitions take effect and the transitional period for marking AI-generated content under Article 50(2) closes.

2 December 2027
High-risk AI systems (Annex III)

Obligations for stand-alone high-risk systems — recruitment, credit scoring, education, essential services — apply. Deferred from August 2026 by the Digital Omnibus, adopted 29 June 2026.

2 August 2028
AI in regulated products

High-risk AI embedded in regulated products (medical devices, machinery, vehicles) comes into scope under Annex I.

What's in scope

Using ChatGPT, Copilot, or any AI tool with EU users? You're already in scope.

Most businesses think the EU AI Act only affects AI developers. It doesn't. It affects any business that deploys or uses AI systems — which means almost every business today.

  • ChatGPT or Copilot used to produce content that EU customers see
  • AI chatbot or virtual assistant interacting with EU users (Article 50 disclosure required)
  • AI-assisted hiring, performance review, or HR decisions involving EU employees
  • AI recommendation engines showing products or content to EU customers
  • AI credit scoring, insurance pricing, or financial decision-making affecting EU citizens
  • Any AI system making or influencing decisions about education, housing, or legal services for EU persons
What's Inside Your Pack
01
AI Literacy Policy
02
Prohibited AI Use Register
03
Article 50 Transparency Assessment and Disclosures
04
AI Tool Inventory
05
Employee AI Guidelines — Practical Dos and Don'ts
06
EU AI Act Risk Tier Classification
07
Human Oversight Procedures
08
Deployer Obligations Checklist
09
AI Staff Training Documentation
10
AI Impact Assessment Template
11
Fundamental Rights Impact Assessment (FRIA)
12
AI Incident Response Procedure
13
Data Governance Documentation for AI Systems
14
Monitoring and Logging Procedures
14
separate documents
EU AI Act

14 dates that decide whether you are compliant.
8 of them have already passed.

Europe is one line of 6. The EU AI Act is the busiest line, and not the only one. Yours is marked. The others reach the same business through its customers, its staff and its suppliers, wherever it is established.

Europe this page

  • in force Obligations for general-purpose AI models.
  • in force Article 50 transparency duties, deployer obligations, and enforcement powers for national regulators.
  • coming New prohibitions, and Article 50(2) marking of synthetic content.
  • coming Every Member State must have an AI regulatory sandbox running.
  • coming High-risk obligations for Annex III systems — including AI used in recruitment, credit scoring, education and essential services.
  • coming High-risk obligations for Annex I systems — AI embedded in products already covered by EU product safety law.

United Kingdom

  • in force Most Part 5 data protection provisions of the Data (Use and Access) Act 2025, including the wider lawful bases for solely automated decisions and the safeguards that come with them.
  • in force The duty on controllers to operate a complaints procedure and respond to data protection complaints within set time limits.

United States

  • in force Texas HB 149, the Responsible Artificial Intelligence Governance Act — prohibited uses, government AI disclosure, and Attorney General enforcement.
  • in force California SB 942, the AI Transparency Act — free AI detection tool and latent provenance disclosure for large generative AI providers. Delayed from 1 January 2026 by AB 853.
  • coming Colorado SB 26-189 — developer and deployer duties for automated decision-making technology used in consequential decisions. It repealed and reenacted SB 24-205, which never took effect.

Canada

  • in force Ontario ESA / O. Reg. 476/24 — a publicly advertised job posting must disclose the use of AI to screen, assess or select applicants. Employers of 25 or more, including where a third party screens on their behalf.

Australia

  • coming Privacy Act 1988 (Cth), APP 1.7 — a privacy policy must say what kinds of personal information a computer program uses to make decisions that could reasonably be expected to significantly affect a person, and what kinds of decisions those are.

United Arab Emirates

  • in force DIFC Data Protection Regulation 10 — a business deploying an autonomous or semi-autonomous system that processes personal data must tell users, on first use, what the system decides for itself, what it was built to do and what it does with the output.
The strategy

The Act arrives in phases, and the phases have already moved once.

A framework built for one deadline is out of date at the next. The obligations land in stages — transparency duties, then the high-risk regimes for recruitment, credit and essential services — and those stages have already been rescheduled once, by the Digital Omnibus. Anyone who papered over the original dates now holds a document describing a timetable that no longer exists.

What does not move is what the Act asks you to be able to show: which AI systems you run, what each one is used for, who is accountable for it, what you assessed before deploying it, and how a person can query a decision it made. Build to that and a date change is an update rather than a rewrite. That is what the annual renewal is for: when Brussels shifts a phase, your framework shifts with it, and you are not paying to start again.

Not sure which phase catches you first? Seven questions, no sign-up.

Take the free check →

Your customers decide which law
applies to you. Not your address.

Where your customers are, where your staff are and where your AI has effect — those decide, not where the business is registered. We write frameworks to four legal systems, and serve four more on request.

United Kingdom UK GDPR in force · DUAA from 5 Feb 2026 European Union AI Act · enforcement 2 Aug 2026 United States State by state · Texas from 1 Jan 2026 Canada PIPEDA · no federal AI statute UAE DIFC Reg 10 since 1 Sep 2023 Singapore Japan AI Act in force · no penalties Australia Automated decisions 10 Dec 2026 New Zealand
Full coverage — frameworks written to this law Also served, on request
  • United Kingdom UK GDPR, in force now. The Data (Use and Access) Act added automated-decision duties from 5 February 2026.
  • European Union The EU AI Act. General-purpose AI obligations already apply; enforcement begins 2 August 2026.
  • United States State by state, not federal. Texas from 1 January 2026, California from 2 August 2026, Colorado from 1 January 2027.
  • Canada PIPEDA plus provincial law. Ontario's AI hiring disclosure rules applied from 1 January 2026.
Pricing

EU AI Act Compliance Packages.

Every package builds a documented compliance position for your business before the August 2026 deadline. Prices in GBP — approximate equivalents shown. Stripe accepts all major cards from any country.

Translation at no extra cost — included with EU AI Foundation and EU AI Complete.
EU AI Essentials
£497 one-off

~$630 · ~€580

  • AI literacy policy (Article 4 compliance)
  • Prohibited AI use register
  • Article 50 transparency disclosures for customer-facing AI
  • AI tool inventory template
  • Plain-English employee guidelines

Best for: businesses using only low-risk AI tools (ChatGPT for internal notes, basic automation) with limited EU customer interaction.

In your inbox by the end of the business day

Buy now — £497 →
EU AI Complete
£1,997 /year

~$2,530 · ~€2,330 per year

  • Everything in EU AI Foundation
  • Full Fundamental Rights Impact Assessment (FRIA)
  • Incident response procedure
  • Data governance documentation for AI systems
  • Monitoring and logging procedures
  • Document delivered in your language (see below)

Best for: regulated businesses, businesses using high-risk AI, or any business that wants a fully auditable compliance position.

In your inbox by the end of the business day · Covers you for 12 months, renews yearly

Renews yearly — policy updates applied as new guidance is issued throughout your cover.

Book a scoping call → or buy directly — £1,997/yr

Foundation and Complete are annual — your fee covers 12 months of protection, with policy updates applied as the Act evolves and new guidance is issued, and renews yearly so your cover never lapses.

Documents delivered in your language

Every document is delivered in English as standard. Need it in French, Spanish, German, Italian, Dutch, Polish, or Portuguese? Just let us know at checkout — we'll deliver your full compliance framework in your language at no extra cost.

No extra charge Included with EU AI Foundation and EU AI Complete
The Process

Four steps to EU AI Act compliance.

01

Scope

We identify which parts of the EU AI Act apply to your business — which AI systems you use, which risk tier they fall into, and which obligations apply.

02

Classify

Every AI tool in use is classified — minimal risk, limited risk, or high risk. This determines your documentation and oversight obligations.

03

Document

We build your full compliance framework — policies, procedures, disclosures, and impact assessments — tailored to your specific tools and operations.

04

Certify

You receive a complete, auditable compliance pack. If you've opted for translation, your documents arrive in your language alongside the English originals.

Questions

Straight answers.

Does the EU AI Act apply to a UK or US business?

Yes — if your products, services, or AI outputs reach EU residents or employees, the Act applies to you regardless of where your business is based. This mirrors how GDPR works: it's based on where your users are, not where you are. A UK business with French customers, or a US SaaS company with German users, is in scope.

What is Article 50 and do I need to comply?

Article 50 requires you to tell people when they're interacting with an AI system — chatbots, automated content, AI-generated images, and emotion recognition tools all require disclosure. If any EU user interacts with AI on your platform, this applies from 2 August 2026.

What counts as "high-risk" AI under Annex III?

Annex III lists specific high-risk categories: AI used in employment decisions (CV screening, performance scoring), AI in education (automated student assessment), AI in financial services (credit scoring), AI in essential services (insurance, healthcare), and AI used in law enforcement or border control. If you use AI in any of these areas and your decisions affect EU citizens, you face the strictest compliance obligations.

I only use ChatGPT for internal notes — am I in scope?

If the outputs never reach EU customers or employees, and you're not making consequential decisions with it, your obligations are minimal — an AI literacy policy and a prohibited use register covers you. That's the EU AI Essentials tier. If you're using it to draft customer-facing content, emails, or support responses that EU users see, Article 50 transparency obligations apply.

What are the fines for non-compliance?

They are set in three tiers. Using a prohibited AI practice: €35M or 7% of global annual turnover. Breaching high-risk obligations, and most other duties: €15M or 3%. Supplying incorrect information to a regulator: €7.5M or 1%.

Which of the two figures applies depends on your size, and this is the part most summaries get backwards. For a large undertaking it is whichever is higher. For a small or medium business Article 99(6) makes it whichever is lower — so in practice the percentage of turnover, never the headline euro ceiling. Enforcement sits with national market surveillance authorities alongside the European AI Office.

Is this legal advice?

No. We produce compliance documentation frameworks and policy documents — we are not EU legal advisers. For businesses in regulated sectors (financial services, healthcare, legal) with high-risk AI systems, we recommend reviewing your documentation with EU-qualified legal counsel. For most SMBs using standard AI tools, our frameworks provide a solid, well-evidenced compliance position.

Enforcement begins 2 August 2026.
Get compliant now.

Most businesses in scope haven't started yet. Getting your documentation in place now means you're protected before enforcement begins — and you won't be scrambling when it does.

See the Packages →

Or book a free 20-minute call to discuss your specific situation — hello@opsintel.io

Call Now Claim Your Free Audit