EU AI Act
EU AI Act compliance, built in from day one.
The AI Act isn’t a risk. It’s a filter — the one that tells you which AI ideas are worth building at all, and what each one costs to run properly. The high-risk deadline moved to December 2027; the engineering it asks for did not get easier, and the systems people are building right now are the ones that will have to answer for it. Every agent we build is classified, documented and governed before it goes anywhere near production.
The short answer
The EU AI Act regulates AI systems placed on the EU market or used in the EU — including systems you build in-house for your own staff. What you owe depends on the risk tier your system falls into, and that classification is the first thing to establish, because everything else follows from it.
Two minutes of certainty beats a quarter of guessing: take the free three-step check. It returns an applicability answer, a risk classification and the duties attached to it. It runs on AI-Agentree, our own EU-AI-Act platform.
The dates that matter
- 02.02.2025 Prohibited practices · AI literacy
- 02.08.2025 General-purpose AI rules · penalties
- 02.08.2026 Transparency (Art. 50) · Act generally applies
- 02.12.2026 Synthetic-content marking · new Art. 5 prohibitions
- 02.12.2027 Annex III high-risk — deferred by the Digital Omnibus
- 02.08.2028 Annex I high-risk, embedded in regulated products
The Digital Omnibus did not cancel the AI Act. Regulation (EU) 2026/1744 came into force on 27 July 2026 and moved one thing: the Chapter III high-risk obligations, to 2 December 2027 for standalone Annex III systems and 2 August 2028 for AI embedded in regulated products. Everything else arrived on schedule. The transparency duties applied from 2 August 2026, penalties have been enforceable since August 2025, and the Art. 4 AI-literacy duty has applied since February 2025 — rewritten by the Omnibus into a duty to take measures to support AI literacy rather than to guarantee a level of it, and supervised nationally since 3 August 2026.
So the honest reading is not “you have more time.” It is that the deadline stopped being the reason. What remains is the same engineering on a longer runway: a system whose risk tier you can state, whose decisions you can reconstruct, and whose accuracy you can evidence — none of which can be produced in the week before a deadline, whichever year it lands in.
How we build it in
- Classify before you code. The risk tier decides the architecture — logging, human oversight and record-keeping are structural decisions, not features you add later.
- Log because Art. 12 expects it, in a form that is actually reviewable rather than a heap of application logs.
- Design the human oversight Art. 14 requires into the workflow, so a person can meaningfully intervene rather than rubber-stamp.
- Produce the Annex IV technical documentation as a by-product of the build — written while the decisions are being made, not reconstructed from memory a year later.
- Keep GDPR in the same pass. The Act governs the system; the GDPR governs the data, and almost every useful agent touches personal data. Doing them separately means doing them twice — see data sovereignty & GDPR.
Art. 15 — and how you actually prove it
Art. 15 requires appropriate accuracy, robustness and cybersecurity. Annex IV requires the technical documentation that evidences it. Which raises the question almost nobody has an answer to: how do you know your AI system works?
“It seemed fine in testing” is not evidence. Proving accuracy means an evaluation set built before deployment, measured on every model swap and every prompt change, with results recorded over time — so a regression is visible rather than discovered by a customer.
We run a 973-case gold set across seven corpora against our own extraction pipeline, sampled randomly rather than by convenience, as a standing regression check. That is not a product we sell you; it is why the method we bring to your system is one we already live with. Evaluation is what “documented for audit” means in S3 Into production — not a separate line item.
What this is not
It is not legal advice. Your lawyer or data-protection officer takes the legal position. What we do is engineering: classification, logging, oversight design, technical documentation and evaluation evidence — the artifacts your legal position has to rest on. Getting those wrong is an engineering failure, and that is the part we own.
Questions
Does the AI Act apply to us if we only use AI internally?
Usually yes. The Act covers systems used in the EU, not only systems sold. Internal-use tools are one of the most common places the duty is missed.
We use a third-party model. Is that not the vendor’s problem?
Only partly. The general-purpose AI rules bind the model provider, but the obligations attached to your system — how you deploy it, what it decides, who oversees it — stay with you.
What does it cost to get compliant?
Far less as part of a build than as a retrofit. The free check costs nothing and gives you an indicative tier. If you need that answer in writing — the classification, the duties that follow, and what changes at December 2027 — Classify covers one named system for a flat €2,900 inside five working days. If you have several systems, or want the build plan too, that is Clarity from €5,900, and the Classify fee comes off it in full.
We already shipped something. Too late?
No, but more expensive. Retrofitting logging and human oversight into a running system is real work, and reconstructed documentation is always weaker than documentation produced by the build.
Who is doing this work?
Dieter Stölzel — twenty years in enterprise IT including BMW and Oracle, PMP-certified, and the builder and operator of AI-Agentree, an EU-AI-Act governance platform. The compliance lifecycle here is shipped software, not a reading of a guide.
Find out where you stand.
Three steps, two minutes: whether the AI Act applies to your project, at what risk tier, and what follows from that.