Modulos Named in the Inaugural Gartner® Magic Quadrant™ for AI Governance PlatformsRead the

Press Release

EU regulations · EU AI Act

Annex III high-risk obligations land 2 December 2027

EU AI Act Compliance,
End to End

Everything you need to know about EU AI Act compliance: obligations, the four-gates risk model, conformity assessments, penalties, and how Modulos accelerates the process. The Act is generally applicable since August 2026, and the high-risk deadlines land in December 2027 and August 2028.

The EU tech law stack:EU AI ActGDPRNIS2DORACyber Resilience Act

What you need to know

  1. Article 2 reaches beyond the EU: providers placing AI on the EU market, deployers established in the EU, and non-EU providers and deployers whose system's output is used in the Union.
  2. The Act is generally applicable since 2 August 2026, with GPAI model fines enforceable today; the high-risk tranches land 2 December 2027 and 2 August 2028.
  3. Four independent gates decide what you owe: prohibited practices, high-risk, transparency, and general-purpose AI, and the obligations stack. Exposure runs to €35M or 7% of worldwide turnover.
Owners: AI product, legal, complianceRead the framework docs →
01

What the EU AI Act is

The EU AI Act (Regulation 2024/1689) is the world’s first comprehensive law on artificial intelligence: a horizontal AI regulation built on product-conformity machinery, treating high-risk AI the way EU law has long treated machinery and medical devices, with obligations scaled to risk. A short list of practices is banned outright. High-risk systems must pass a conformity assessment before reaching the market and keep evidence that they stay safe. Most other systems carry transparency duties or none at all.

It reaches providers placing AI on the EU market, deployers established in the EU, and non-EU providers and deployers whose system's output is used in the Union, and its penalties scale with global turnover. The goal is to make AI products trustworthy enough to ship, the way CE marking did for physical products.

02

The road ahead

Four dates decide your plan. Everything already in force is history you inherit, and only the dates ahead need managing.

Today

  1. 2 Aug 2026

    now in effect

    General application and GPAI fines

  2. 2 Dec 2026

    in 3 months

    New Article 5 prohibitions apply and watermarking grace ends

  3. 2 Dec 2027

    in 15 months

    Annex III standalone high-risk obligations

  4. 2 Aug 2028

    in 23 months

    Annex I product-embedded high-risk obligations

Behind us: in force since 1 August 2024, prohibitions and AI literacy since February 2025, GPAI model rules since August 2025. These are the current statutory dates: the July 2026 amendment (Regulation (EU) 2026/1744) retained 2 August 2026 and set or moved the later ones.

The runway is shorter than it looks

December 2027 reads like distance, but the enforcement machine is already running.

01

GPAI enforcement is live since 2 August 2026

Model-provider fines under Article 101 are enforceable today.

02

The new bans land 2 December 2026

The NCII and CSAM prohibitions apply, and the Article 50 marking grace for systems predating August 2026 runs out; newer systems already carry the duties.

03

December 2027 is a start date in disguise

Inventory, classification, control design, and evidence collection take 12 to 18 months at enterprise scale.

04

The AI Office has teeth

Investigation powers, on-site inspections, and fines of its own for the systems under its exclusive competence.

03

Does it apply to you?

Article 2 gives the Act extraterritorial reach: non-EU providers are bound when they place a system on the EU market, and non-EU providers and deployers are bound where the system’s output is used in the Union. Follow SYS-04, the credit-scoring system on the map. Neither company is European; both are in scope.

Loading map...

A non-EU provider builds an AI credit-scoring model. A US fintech licenses it. EU customers receive credit decisions from it. Article 2 brings both the non-EU provider and the non-EU deployer into scope here, because the system is placed on the EU market and its outputs are used in the Union.

Which role are you?

Provider, deployer, importer, distributor: four of the commercial roles defined in the EU AI Act. The definitions are easy; the trap sits in recognising which role you hold. Most companies guess wrong, and the difference can be six figures of compliance work.

1
Article 25(1)(b)–(c)You become a Provider

You become a provider when you turn a system into a high-risk one.

Modify the intended purpose of an AI system already on the market, a general-purpose model included, so that it becomes high-risk under Article 6, and Article 25(1)(c) makes you the provider. Substantially modify an already-high-risk system and Article 25(1)(b) does the same, and building your own system on top of a model can make you an Article 3 provider outright. Provider obligations are heavy: technical documentation, conformity assessment, the Articles 9 to 15 stack.

2
Article 25(1)(a)You become a Provider

You become a provider when you rebrand a high-risk system.

White-label a third-party high-risk AI system and put your name or trademark on it, and Article 25(1)(a) says you are now the provider. You inherit all provider obligations, even if the system was built by someone else; Article 25(2) obliges the initial provider to hand over the information and technical access you reasonably need, but the responsibility is yours.

3
Annex III, Article 50You are a Deployer

You become a deployer the moment you use AI under your authority.

Article 3(4) makes you a deployer whenever you use an AI system under your authority. Internal HR screening tool? Deployer of a high-risk system under Annex III. Emotion recognition or deepfake generation in your product? Deployer transparency duties under Article 50(3) and 50(4); the chatbot disclosure duty in Article 50(1) sits with the provider. “We just bought it from a vendor” is not a defence.

4
Articles 23, 24Importer or Distributor

You become an importer or distributor without realising.

Reselling a non-EU high-risk AI system into the EU market? Importer obligations under Article 23, including verifying the provider has done the conformity assessment. Acting as a SaaS reseller or marketplace in a value chain for high-risk AI? Probably distributor obligations under Article 24. The high-risk qualifier matters: these duties attach specifically to high-risk systems rather than to AI in general.

Misclassification is the most expensive mistake on this page. The default assumption that “we just use AI” rarely survives contact with the Act’s definitions. Get the role right before you scope the program: every other obligation flows from it.

Not sure where you stand?

The risk calculator classifies your likely EU AI Act role and puts a number on your exposure in about three minutes.

Run the risk calculator

Which of the five reach you?

Answer for your company, and see the stack you actually manage. Most teams arrive here for one regulation and leave managing three.

Likely on your desk:EU AI ActGDPRNIS2DORACyber Resilience Act

You came for the EU AI Act. Tick what else is true and watch the stack grow.

A one-question check gives orientation only; actual scope turns on each regime's territorial, entity-size, and product tests.

04

What do you owe, and by when?

The Act does not sort systems into tidy risk tiers. It runs four independent checks, and the obligations stack. Here is how that plays out for SYS-04, then the full stack article by article.

Pick a system

Follow the system · SYS-04 · credit-scoring model · non-EU provider, US fintech deployer, EU customers

SYS-04 enters the four checks
  1. 1

    Gate 1 · Article 5

    Prohibited practices

    Does it manipulate, socially score, or fall under the new NCII and CSAM bans?

    SYS-04 · NOpasses

    If yes: Banned. The new NCII and CSAM bans apply by 2 December 2026.

  2. 2

    Gate 2 · Article 6, Annex I and III

    High-risk classification

    Is it a safety component of a regulated product, or standalone in an Annex III domain?

    SYS-04 · YESfires

    Result: Creditworthiness assessment is Annex III point 5(b). Full high-risk stack by 2 December 2027.

  3. 3

    Gate 3 · Article 50

    Transparency duties

    Does it interact with people directly or generate synthetic content?

    SYS-04 · NOpasses

    If yes: Disclosure and marking duties, applicable since 2 August 2026; systems on the market before then have until 2 December 2026.

  4. 4

    Gate 4 · Chapter V

    General-purpose AI

    Is it a general-purpose model, or built on one you also provide?

    SYS-04 · NOpasses

    If yes: Model-level duties, in force since August 2025.

Obligations tray

Everything SYS-04 accumulated, all of it from Gate 2

  • Art. 9 risk management
  • Art. 10 data governance
  • Art. 11 technical file
  • Art. 12 logging
  • Art. 14 human oversight
  • Art. 17 QMS
  • Art. 43 conformity assessment
  • Art. 49 EU database registration
  • by 2 Dec 2027

Four checks, different stacks. Pick a system above, or run your own through all four gates.

Compliance Requirements

The Act lays out a range of requirements for high-risk AI systems. Tap any card for a plain-language summary and a link to the article.

* Required for public-law deployers and private entities providing public services, plus deployers of certain Annex III high-risk systems (creditworthiness assessment under 5(b) and life/health insurance risk assessment under 5(c)). Annex III point 2 (critical infrastructure) is excluded from the FRIA trigger.

Conformity assessment

High-risk systems must pass a conformity assessment before market entry; Annex I products follow their sectoral regimes. Self-assessed systems see no scheduled audit afterwards, while the notified-body routes bring periodic audits, and either way scrutiny arrives when a market surveillance authority requests your technical file. The record has to be ready.

Step 1 - A high-risk AI system is developed

The Article 9 risk management system runs from the start and stays live for the system’s lifetime.

Step 2 - It passes the conformity assessment

The provider demonstrates the Articles 9 to 15 requirements: most Annex III systems under the Annex VI internal-control route, the narrow third-party routes through a notified body under Annex VII.

Step 3 - It is registered in the EU database

Article 49 registration, mainly for Annex III systems, including those self-exempted from high-risk classification under Article 6(3).

Step 4 - The declaration is signed and the CE marking affixed

The EU declaration of conformity under Article 47 and the CE marking under Article 48 close the process.

CE Mark

The system can be placed on the market.

Once substantial changes happen in the AI system's lifecycle, repeat from Step 2.

System placed on market

05 · Exposure

What happens if you get it wrong?

Penalties

What non-compliance costs, drawn to scale

Article 99 sets three tiers. Pick a revenue and an entity status to draw the ceilings for an illustrative undertaking; SME and small-mid-cap status turn on headcount, balance sheet, and group structure, which turnover alone cannot decide.

Global revenue
Entity status
Prohibited practices violationsup to €35M or 7% of global turnover, whichever is higher
€140M
fixed cap €35M
Non-compliance with most other obligationsup to €15M or 3% of global turnover, whichever is higher
€60M
fixed cap €15M
Supplying incorrect or misleading informationup to €7.5M or 1% of global turnover, whichever is higher
€20M
fixed cap €7.5M

At €2B in global revenue the turnover share exceeds every fixed cap, so the percentage applies.

Article 3(14b) defines a small mid-cap by reference to Commission Recommendation (EU) 2025/1099: an undertaking beyond the SME thresholds with fewer than 750 staff and turnover at or below €150M or a balance sheet at or below €129M.

GPAI model providers face separate fines under Article 101, enforceable from 2 August 2026.

See your exposure mapped to controls and evidence, system by system.

Request a Demo
EU AI ActCBUAE Consumer AISaudi AI Risk (SDAIA)FINMA AIMAS FEATUAE AI EthicsSingapore MGFISO/IEC 42001NIST AI RMFprEN 18282prEN 18228GDPRUAE PDPLISO/IEC 27701ISO/IEC 27001NIS2DORACRAOWASP LLM Top 10OWASP Agentic Top 10Microsoft Supplier DPR

The regimes overlap where the controls live

The governance graph maps every control in the framework library to every regulation it serves. Where regimes map the same control, one implementation and one evidence record can support all of them, subject to each regime's own requirements, and most of the EU AI Act's controls already serve at least one other framework.

102 / 128EU AI Act controls already serve another framework
120controls shared among the five EU regimes

Framework library v1.0.28

06

How the work gets done

Reading the law is the easy part. The work is an inventory that stays current, classifications you can defend, controls mapped to articles, and evidence that accumulates as a side effect of normal work. That is what the platform is for: Modulos holds CertX product conformity certificate 213-001/24 against ISO/IEC 42001:2023, and took Xayn to the first ISO/IEC 42001 certification in Germany.

Risk Management
Quantitative risk assessment with Monte Carlo simulation
Documentation & Records
AI Agents auto-generate and find evidence in your repos
Human Oversight & QMS
Built-in review workflows with full audit trail
Multi-Framework Compliance
140+ controls mapped to EU AI Act, ISO 42001, NIST AI RMF

Why Modulos for the EU AI Act

Three credentials specific to the EU AI Act, ordered by weight. The links point to the public bodies the work was done with.

CEN-CENELEC JTC 21

Highest weight

Contributed to the European AI standards that grant presumption of conformity

High-risk compliance will run through CEN-CENELEC harmonised standards: once cited in the Official Journal under Article 40, they grant a legal presumption of conformity for the requirements they cover (Articles 9 to 15). Modulos contributed to these standards through the JTC 21 working groups.

JTC 21 (CEN-CENELEC)

AESIA, Spanish AI regulatory sandbox

First EU AI Act sandbox

Supported the first EU AI Act regulatory sandbox

Spain ran the first EU AI Act regulatory sandbox, driven by SEDIA through its Directorate-General for Artificial Intelligence with the support of AESIA, Europe’s first dedicated AI supervisory agency. It produced 16 practical, non-binding compliance guides. A Modulos expert served on the sandbox as an external expert member.

AESIA

EU AI Pact

Voluntary early commitment

An EU AI Pact signatory

Modulos is a signatory of the EU AI Pact, the European Commission’s voluntary pledge to apply AI Act principles ahead of full applicability: an AI governance strategy, high-risk system mapping, and AI literacy across staff.

Public AI Pact signatory list

And the certifiable management system the proof flows into

Modulos holds CertX product conformity certification against ISO/IEC 42001 (certificate 213-001/24). ISO/IEC 42001 is not a substitute for AI Act conformity assessment, but it is the management-system spine most mature AI Act programs build on. See the ISO 42001 page.

07

How the EU AI Act stacks with other frameworks

Most organisations operate the AI Act alongside other regulations and standards rather than instead of them. Here is where the Act sits relative to the frameworks teams most often ask about.

Standard / RegulationDomainRelation to the EU AI Act
ISO/IEC 42001International AI management systemComplementary
NIST AI RMFVoluntary U.S. risk-management frameworkComplementary
GDPRBinding EU data-protection regulationDifferent layer
EU Machinery RegulationSafety-critical machinery in the EUOperational glue

EU AI Act vs ISO/IEC 42001

Complementary

ISO/IEC 42001 is the certifiable international management system standard for AI. Article 17 of the AI Act requires high-risk providers to operate a quality management system. Holding ISO 42001 certification is one of the strongest practical signals of meeting Article 17, although not formally a substitute. Most mature AI Act compliance programs land inside an ISO 42001 management system.

EU AI Act vs NIST AI RMF

Complementary

NIST AI RMF is voluntary U.S. guidance organised around four core functions (Govern, Map, Measure, Manage). The AI Act is binding EU regulation. Implementing AI RMF builds the risk-management practices Article 9 expects of high-risk providers, but it does not substitute for the Act's conformity-assessment and CE-marking requirements. See the NIST AI RMF page.

EU AI Act vs GDPR

Different layer

Both the AI Act and the GDPR are binding EU regulations, but they govern different layers. GDPR governs personal data; the AI Act governs AI systems. They overlap sharply on biometric processing, bias-testing with sensitive data, and the rights of individuals affected by automated decisions. Compliance with the GDPR does not satisfy the AI Act, and vice versa; both apply.

EU AI Act vs EU Machinery Regulation

Operational glue

Since the July 2026 amendment to the AI Act (Regulation (EU) 2026/1744), the Machinery Regulation sits in Section B of Annex I rather than Section A. The AI Act's substantive high-risk requirements stop applying directly to machinery-embedded AI, while classification, testing and market surveillance still reach it, and the AI-specific health and safety requirements are routed through delegated acts under the Machinery Regulation itself. The Canton of Zurich Innovation Sandbox for AI report still illustrates the value of running a single integrated AI management system across regimes. See the Sandbox report (PDF).

08

FAQ about the EU AI Act

The EU AI Act (Regulation 2024/1689) is the European Union’s comprehensive law on artificial intelligence, in force since 1 August 2024. It is a product safety regulation: it bans some AI practices outright, requires conformity assessments and CE marking for high-risk AI systems, imposes transparency obligations, and sets model-level obligations for general-purpose AI providers.

By industry

How this applies in your sector

See how this plays out in the sectors where it drives the most AI governance work:

Where the AI Act work goes next

Talk to an expert

Walk through your AI inventory with someone who has run the four gates on real systems.

Book an AI Act demo

Keep exploring on your own

The framework docs cover the Act requirement by requirement; the risk calculator classifies your likely role in minutes.