EU AI Act compliance for enterprises
Comply with the EU AI Act Without the Hassle
Modulos connects 10+ AI governance frameworks in a single platform, giving you complete visibility of your obligations and the controls you need to meet them.
Map AI risks to organisational and technical controls across 10+ frameworks.
Build an audit-ready evidence trail that holds up under scrutiny.
Demonstrate AI governance to your board, your auditors and your customers.
Based in the UK or US? The EU AI Act still applies if you offer AI-enabled products or services in the EU, or your AI's output is used there.
Running a business with 50 to 500 employees? EU AI Act compliance for smaller businesses
Request a Demo
Takes 30 seconds. We reply within 24 hours.

ISO/IEC 42001 Product Conformity · SOC 2 Type 2 compliant
Trusted by over 200 organizations


Timeline and Compliance Milestones
Key dates for EU AI Act compliance.
The EU AI Act entered into force.
Prohibitions on unacceptable-risk AI practices apply, along with AI literacy requirements.
Obligations for general-purpose AI models and EU governance rules apply.
High-risk AI obligations under Annex III (biometrics, critical infrastructure, law enforcement) apply. This is the next major deadline.
High-risk AI obligations under Annex I (AI in regulated products requiring third-party conformity assessment) apply.
The EU AI Act entered into force.
Prohibitions on unacceptable-risk AI practices apply, along with AI literacy requirements.
Obligations for general-purpose AI models and EU governance rules apply.
High-risk AI obligations under Annex III (biometrics, critical infrastructure, law enforcement) apply. This is the next major deadline.
High-risk AI obligations under Annex I (AI in regulated products requiring third-party conformity assessment) apply.
The EU AI Act entered into force.
Prohibitions on unacceptable-risk AI practices apply, along with AI literacy requirements.
Obligations for general-purpose AI models and EU governance rules apply.
High-risk AI obligations under Annex III (biometrics, critical infrastructure, law enforcement) apply. This is the next major deadline.
High-risk AI obligations under Annex I (AI in regulated products requiring third-party conformity assessment) apply.
Deadlines reflect the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force from 27 July 2026.
EU AI Act: How Compliance Really Works
The EU AI Act introduces four independent gates, and obligations stack. A single AI system can trigger multiple gates simultaneously.
Prohibited Practices
Does this AI practice cross a red line?
High-Risk Systems
Is this AI deployed in a high-risk domain?
Transparency
Does this AI interact with people, detect emotions, or generate synthetic media?
General-Purpose AI
Are you providing a foundation model or GPAI?
Obligations stack: A single system can trigger multiple gates
Real-World Examples
High-risk (essential services) + Transparency (human interaction)
Transparency only: disclose that it is AI
All three: high-risk + transparency + GPAI obligations
Why AI Act Compliance Is Complex
Most organizations underestimate the effort required for EU AI Act compliance.
Complex Regulation
The regulation spans over 450 pages with interconnected technical and legal requirements.
Manual Assessments
Manual control assessments require 2-4 hours per system.
Multiple Frameworks
Multiple frameworks (EU AI Act, ISO 42001, NIST AI RMF) triple the implementation effort.
Inadequate Risk Matrices
Qualitative risk matrices are insufficient for board and auditor scrutiny.
Lack of Visibility
Organizations lack centralized visibility across all AI systems.
Siloed Teams
Disconnected teams (data, legal, compliance, business) work independently.
Modulos
Your AI Governance Platform
Manage governance, risk management, and compliance from a single platform, with AI agents that optimize your work.
Governance
Manage AI governance like an operating system
Project dashboards, AI lifecycle monitoring, accountability workflows, and complete traceability. Manage your entire AI portfolio from a single panel.
- Project and enterprise dashboards
- AI lifecycle monitoring
- Accountability and responsibility workflows
- Complete audit traceability

Penalties and Non-Compliance Risks
The EU AI Act provides a strict sanctions regime. The amount varies depending on the severity of the violation: from providing false information to implementing expressly prohibited AI practices.
For SMEs and startups, proportionate caps are provided that balance deterrent effect with business sustainability.
Penalty Details
Use of Prohibited AI Systems
Non-compliance with High-Risk Requirements
False or Incomplete Information to Authorities
Beyond financial penalties, reputational and operational impacts can be decisive: forced market withdrawal of systems, mandatory audits, operational disruptions, and significant loss of trust from customers, partners, and investors.
Even if you are based in the UK, US or elsewhere outside the EU, the EU AI Act can still apply. For example, it applies if you place an AI system on the EU market, act as a deployer established in the EU, or your AI system's output is used in the EU. Modulos helps organisations meet these obligations alongside their own evolving national AI rules.
Frequently Asked Questions
Almost certainly yes. The EU AI Act applies to any organisation that uses AI systems, not just those that build them. If your business uses AI-powered tools for hiring, customer service, credit decisions, fraud detection, content moderation or any operational process, you are likely in scope. The Act classifies AI systems by risk level, and many tools that organisations use every day, including HR software, CRM platforms and automated decision systems, fall into categories that carry compliance obligations. And if you place AI systems on the EU market, sell to EU customers, or your AI system's output is used in the EU, the Act applies regardless of where your organisation is headquartered.
Compliance is not a race, and treating it like one is how organisations end up with evidence that does not hold up. What matters is making the right risk decisions and assembling an accurate, traceable body of evidence: the kind that stands up when a regulator, auditor or court asks you to prove it. Modulos does not shortcut that work. It makes it rigorous and repeatable, structuring your AI inventory, risk assessments, controls and evidence so nothing is missed and everything is traceable to an owner and a date. How long it takes depends on the size and complexity of your AI estate. What we ensure is that what you produce is defensible, not just done.
Modulos connects AI governance frameworks in a single platform, including the EU AI Act, ISO/IEC 42001, NIST AI RMF, GDPR (where it intersects with AI), NIS2, DORA, ISO/IEC 27001 and 27701, and the OWASP Top 10 for LLMs and Agentic AI, alongside sector-specific frameworks such as MAS FEAT and UAE AI Ethics. Modulos is the first AI governance platform in Europe to hold an ISO/IEC 42001:2023 Product Conformity certificate, meaning the platform itself has been independently certified to cover 100% of the standard it helps you comply with. You can manage obligations across 10+ connected frameworks simultaneously rather than running separate processes for each.
A manual compliance process typically means spreadsheets, disconnected documents, internal workshops and external consultants reassessing your position every time something changes. It is slow, resource-intensive and leaves gaps between reviews. Modulos replaces that with a live governance environment where risks, controls, evidence and regulatory requirements are connected in one place and updated continuously. When a framework changes, or a new AI system is deployed, the platform reflects that immediately across all your compliance obligations rather than requiring a new manual assessment cycle.
Three things set Modulos apart. First, it is the only AI governance platform in Europe to hold an ISO/IEC 42001:2023 Product Conformity certificate, which means the platform has been independently verified to cover 100% of the standard it helps you achieve. Second, it connects 10+ frameworks simultaneously, so you manage the EU AI Act, ISO 42001, NIST AI RMF and others in one place rather than maintaining separate tools or processes for each. Third, it is purpose-built for the European regulatory context, developed in Switzerland with the EU AI Act and European data sovereignty requirements at its core, rather than adapted from a US-built platform.
Onboarding begins with an AI inventory that maps the AI systems your organisation builds, buys or uses, including Shadow AI surfaced through automated discovery. Each system is then risk-classified, obligations are mapped to the relevant frameworks, and controls and evidence are assigned to accountable owners. This is a genuine governance exercise, not a box-ticking one. It engages your compliance, IT and business stakeholders, with one owner, typically a compliance lead, IT manager or operations director, coordinating the work. That human ownership is deliberate. The decisions and evidence it produces are what make your compliance defensible under scrutiny. Modulos removes the busywork with structured templates, automated evidence collection and a single source of truth, so your team spends its time on judgement, not paperwork.
What Our Customers Say
Prepare Your Organization for the AI Act
Request a personalized demo and discover how Modulos can turn your EU AI Act compliance into a competitive advantage.
Request a Demo



