EU AI Act
EU AI Act compliance, built in from day one.
The AI Act isn’t a risk. It’s a head start — for whoever builds it in. Companies that treated compliance as an afterthought will scramble; the ones who engineered it from the first line ship with confidence. Every agent we build is classified, documented and governed before it goes anywhere near production.
The short answer
The EU AI Act regulates AI systems placed on the EU market or used in the EU — including systems you build in-house for your own staff. What you owe depends on the risk tier your system falls into, and that classification is the first thing to establish, because everything else follows from it.
Two minutes of certainty beats a quarter of guessing: take the free three-step check. It returns an applicability answer, a risk classification and the duties attached to it. It runs on AI-Agentree, our own EU-AI-Act platform.
The dates that matter
- 02.02.2025 Prohibited practices · AI literacy
- 02.08.2025 General-purpose AI rules
- 02.08.2026 Main obligations apply
- 02.12.2027 Annex III high-risk — deferred by the Digital Omnibus
The deadline that catches people is not the last one. It is 2 August 2026, because that is when the bulk of the regime lands, and because the documentation it expects cannot be produced in the week before.
How we build it in
- Classify before you code. The risk tier decides the architecture — logging, human oversight and record-keeping are structural decisions, not features you add later.
- Log because Art. 12 expects it, in a form that is actually reviewable rather than a heap of application logs.
- Design the human oversight Art. 14 requires into the workflow, so a person can meaningfully intervene rather than rubber-stamp.
- Produce the Annex IV technical documentation as a by-product of the build — written while the decisions are being made, not reconstructed from memory a year later.
- Keep GDPR in the same pass. The Act governs the system; the GDPR governs the data, and almost every useful agent touches personal data. Doing them separately means doing them twice — see data sovereignty & GDPR.
Art. 15 — and how you actually prove it
Art. 15 requires appropriate accuracy, robustness and cybersecurity. Annex IV requires the technical documentation that evidences it. Which raises the question almost nobody has an answer to: how do you know your AI system works?
“It seemed fine in testing” is not evidence. Proving accuracy means an evaluation set built before deployment, measured on every model swap and every prompt change, with results recorded over time — so a regression is visible rather than discovered by a customer.
We run a 973-case gold set across seven corpora against our own extraction pipeline, sampled randomly rather than by convenience, as a standing regression check. That is not a product we sell you; it is why the method we bring to your system is one we already live with. Evaluation is what “documented for audit” means in S3 Into production — not a separate line item.
What this is not
It is not legal advice. Your lawyer or data-protection officer takes the legal position. What we do is engineering: classification, logging, oversight design, technical documentation and evaluation evidence — the artifacts your legal position has to rest on. Getting those wrong is an engineering failure, and that is the part we own.
Questions
Does the AI Act apply to us if we only use AI internally?
Usually yes. The Act covers systems used in the EU, not only systems sold. Internal-use tools are one of the most common places the duty is missed.
We use a third-party model. Is that not the vendor’s problem?
Only partly. The general-purpose AI rules bind the model provider, but the obligations attached to your system — how you deploy it, what it decides, who oversees it — stay with you.
What does it cost to get compliant?
Far less as part of a build than as a retrofit. The free check costs nothing and tells you the tier; from there an assessment scopes the actual work.
We already shipped something. Too late?
No, but more expensive. Retrofitting logging and human oversight into a running system is real work, and reconstructed documentation is always weaker than documentation produced by the build.
Who is doing this work?
Dieter Stölzel — twenty years in enterprise IT including BMW and Oracle, PMP-certified, and the builder and operator of AI-Agentree, an EU-AI-Act governance platform. The compliance lifecycle here is shipped software, not a reading of a guide.
Find out where you stand.
Three steps, two minutes: whether the AI Act applies to your project, at what risk tier, and what follows from that.