On August 2, 2026, the European Union AI Act stops being a compliance memo you forwarded to nobody and starts being enforceable law with teeth. That is the date the Annex III high-risk obligations kick in — the rules covering AI used in hiring, credit scoring, education, essential services, and worker management. EU AI Act high-risk compliance is not just a vendor problem: if you deploy an off-the-shelf resume screener, a credit-decision model, or an AI proctoring tool, you are a “deployer” with your own logging, human-oversight, and monitoring duties. Non-compliance runs up to 15 million euros or 3% of global annual turnover, whichever is higher, and the clock has run out on “we’ll look at it next quarter.”
What’s actually new about EU AI Act high-risk compliance
The AI Act entered into force on August 1, 2024 and phases in over several years. Prohibited-practice bans and AI literacy duties landed in February 2025. General-purpose AI (GPAI) model obligations landed in August 2025. August 2, 2026 is the big one: the general applicability date. It switches on the Annex III high-risk regime plus the Article 50 transparency rules for chatbots, synthetic media, and emotion-recognition systems.
Annex III is a list, not a vibe. It designates eight categories of high-risk use: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services (including creditworthiness and life/health insurance pricing), law enforcement, migration and border control, and administration of justice. If your AI touches employment decisions or credit scoring, you’re in scope. High-risk AI embedded in regulated products under Annex I — medical devices, machinery, vehicles — gets a longer runway to August 2, 2027.
Most business owners miss the split in duties between “providers” (whoever develops or brands the system) and “deployers” (whoever uses it under their own authority in a professional capacity). Providers carry the heavy load: risk management systems, data governance, technical documentation, conformity assessment, CE marking, EU database registration. But deployer obligations are real and independent. Article 26 requires you to use the system according to instructions, assign human oversight to a competent and trained person with authority to override, ensure input data is relevant and sufficiently representative, keep automatically generated logs for at least six months, monitor for anomalies, notify the provider and market surveillance authority of serious incidents, and inform workers’ representatives before deploying a high-risk system in the workplace. Public bodies and providers of public services also owe a fundamental rights impact assessment (FRIA) under Article 27. Article 86 gives individuals subject to a high-risk decision the right to demand a meaningful explanation.
One more trap: Article 25 says a deployer can become a provider. Put your own name or trademark on a high-risk system, substantially modify it, or repurpose a general-purpose system into a high-risk use, and you inherit the full provider obligations — conformity assessment and all. Fine-tuning a general model into an automated candidate-ranker is exactly this scenario.
Why it matters
- Territorial reach is extraterritorial. The Act applies if you’re established in the EU, or if the output of your AI system is used in the EU. A US or UK company screening applicants for an EU-based role is in scope. There is no local-entity loophole.
- EU AI Act fines and penalties scale to hurt. Prohibited practices: up to 35 million euros or 7% of global turnover. Most other breaches, including high-risk obligations: up to 15 million euros or 3%. Supplying incorrect or misleading information to authorities: up to 7.5 million euros or 1%. SMEs get the lower of the two figures rather than the higher, which softens the blow but does not remove it.
- Your HR and finance stack is the exposure, not your engineering team. Applicant tracking systems with AI ranking, automated CV parsing that filters candidates, productivity-monitoring tools that inform promotion or termination, and credit-decision scoring are the four places SMBs most commonly cross into Annex III without a single line of in-house model code.
- Enforcement is national and fragmented. Each member state designates market surveillance authorities, and several missed the August 2025 deadline to name them. Expect uneven early enforcement — and complaint-driven investigations, because Article 85 gives any person the right to file a complaint.
- The harmonised standards aren’t finished. CEN-CENELEC’s technical standards, which would give providers a presumption of conformity, have slipped. That means more bespoke documentation work and more reliance on your vendor’s own claims — claims you should be contractually pinning down now.
- Workers get notified either way. Article 26(7) requires informing workers and their representatives before putting a high-risk system into service at work. If your first conversation about the AI monitoring tool happens because of a compliance trigger, that’s a culture problem on top of a legal one.
How to use it today: a working AI conformity assessment checklist
Do these in order. A focused afternoon gets you 80% of the way to defensible.
-
Inventory every AI system touching your business. Include SaaS features you didn’t buy as “AI” — LinkedIn Recruiter filters, HR platform scoring, fraud models in your payments provider. Start a register:
system_name,vendor,business_function,annex_iii_category,role,eu_data_subjects,decision_impact,logs_available,owner GreenhouseAI Ranking,Greenhouse,Recruiting,"Annex III 4(a) - employment",deployer,yes,shortlisting,unknown,head_of_people ScoreFlow,Acme Fintech,Lending,"Annex III 5(b) - creditworthiness",deployer,yes,approve/decline,yes,cfo Support Copilot,Intercom,Customer service,none,deployer,yes,drafting only,yes,cx_lead -
Triage each system against Annex III. For every row, answer three questions: does the use case land in one of the eight categories; does it profile natural persons; does it do more than a narrow procedural task. Article 6(3) offers a derogation — if the system only performs a narrow procedural task, improves the result of prior human activity, detects decision patterns without replacing human judgment, or does preparatory work — but the derogation does not apply if it profiles natural persons. Document the reasoning; you must be able to show it to a regulator.
Prompt for triage (paste into your assistant of choice, one system at a time): You are an EU AI Act compliance analyst. Assess the following AI system against Annex III of Regulation (EU) 2024/1689. System: [name] Vendor: [vendor] What it does: [2-3 sentences, concrete] Who it affects: [candidates / employees / customers / EU residents?] What decision it influences: [and whether a human reviews before action] Return: 1. Annex III category and subpoint, or "not listed" with reasoning 2. Whether the Article 6(3) derogation could apply, and why/why not 3. Our role: provider, deployer, both, or out of scope (cite Article 25 if both) 4. The specific Article 26 duties triggered 5. Top 3 evidence artifacts a market surveillance authority would ask for Flag every uncertainty explicitly. Do not fill gaps with assumptions. -
Send a vendor evidence request. Your compliance depends on artifacts only the provider holds. Ask in writing, and keep the reply.
Subject: EU AI Act Article 26 - deployer evidence request ([system name]) Ahead of the 2 August 2026 applicability date, please confirm in writing: 1. Do you classify [system] as high-risk under Annex III? Which subpoint? 2. Are you the provider under Article 3(3)? If not, who is? 3. Provide the Article 13 instructions for use, including intended purpose, known limitations, and required human-oversight measures. 4. Provide the EU declaration of conformity and CE marking status. 5. Provide your EU database registration number (Article 49). 6. How do we export the Article 12 automatic logs? What retention, what format, what API? 7. What accuracy, robustness and cybersecurity metrics are declared, and on what population were they measured? 8. What is your serious-incident notification process and SLA? 9. Confirm contractual support under Article 25(4) if we are deemed a provider through modification. Please respond by [date 14 days out]. We are documenting responses as part of our conformity file. -
Turn on and retain logs. Article 26(6) requires deployers to keep automatically generated logs for at least six months where those logs are under your control. Six months is a floor, not a target — align it to your dispute window. A minimal retention job:
# Pull deployer logs nightly and retain 400 days curl -sS -H "Authorization: Bearer $VENDOR_API_KEY" \ "https://api.vendor.example/v1/ai-logs?since=$(date -u -d '1 day ago' +%Y-%m-%dT%H:%M:%SZ)" \ | gzip > "ai-logs/$(date -u +%F).json.gz" # Prune beyond retention window find ai-logs -name '*.json.gz' -mtime +400 -delete -
Name a human overseer and give them real authority. Article 26(2) requires a natural person with the necessary competence, training, and support — and the authority to reject or reverse the output. Write it into the job description, not a wiki page. Log every override; override rate is the single most useful metric you’ll have when a regulator asks whether oversight was meaningful or decorative.
-
Handle GPAI transparency requirements at the interface. Article 50 applies to nearly everyone, high-risk or not. Users must be told they are interacting with an AI unless it’s obvious. Synthetic audio, image, video, and text must be machine-readably marked. Deepfakes and AI-generated text published to inform the public on matters of public interest must be disclosed. Two lines of markup handle most of it:
<!-- Chat surface: unambiguous notice before first interaction --> <p role="note">You are chatting with an AI assistant. A human agent is available at any time — type "agent" or email support@example.com.</p> <!-- Published AI-assisted content: machine-readable provenance --> <meta name="ai-generated" content="true"> <meta name="ai-generated-by" content="model-name; human-reviewed"> -
Write the one-page conformity file per system. Purpose, classification decision and reasoning, vendor artifacts received, named overseer, log location and retention, incident contact, review date. If you can’t produce this in under a minute during an inquiry, you don’t have it.
How it compares
Business owners keep asking whether this is “just GDPR again.” It isn’t — the obligations attach to different things, and you can be fully GDPR-compliant and squarely in breach of the AI Act.
| Dimension | EU AI Act | GDPR | Colorado AI Act (SB 24-205) | NIST AI RMF |
|---|---|---|---|---|
| Legal force | Binding EU regulation | Binding EU regulation | Binding US state law | Voluntary framework |
| Key date | Aug 2, 2026 (Annex III high-risk) | In force since 2018 | Delayed to June 30, 2026 | Adopt anytime |
| Trigger | Risk of the AI use case | Processing of personal data | Consequential decisions by AI | Self-selected scope |
| Max penalty | 35M euros / 7% (prohibited); 15M / 3% (high-risk) | 20M euros / 4% | State AG enforcement, per-violation | None |
| Deployer-specific duties | Yes — Articles 26, 27, 86 | Controller/processor split | Yes — duty of care, impact assessments | N/A |
| Conformity assessment | Required for high-risk providers | DPIA for high-risk processing | Impact assessment annually | Recommended |
| Extraterritorial | Yes — output used in the EU | Yes — EU data subjects | Yes — Colorado residents | N/A |
Practical read: a GDPR Article 35 DPIA is a strong starting artifact for an AI Act FRIA, and NIST AI RMF gives you the internal governance scaffolding cheaply. Neither substitutes for the Annex III classification decision or the Article 26 log-and-oversight record.
What’s next
Watch the simplification debate. The European Commission’s Digital Omnibus package, floated in November 2025, proposed delaying parts of the high-risk regime — potentially to December 2027 for Annex III systems — and tying applicability to the availability of harmonised standards. That is a proposal, not law; it requires Parliament and Council agreement, and it has drawn sharp opposition from civil society groups who call it deregulation by another name. Betting your compliance program on a delay that may not arrive, and may not cover your category, is a bad trade. Build to August 2, 2026 and treat any postponement as breathing room you earned.
Watch the standards pipeline. CEN-CENELEC JTC 21 is drafting the harmonised standards that would give providers a presumption of conformity. They’ve slipped repeatedly. When they land, your vendors’ claims get testable and your evidence requests get much easier to write. Until then, contractual commitments are your best available substitute. Push for AI Act warranties, indemnities, and log-access guarantees at your next renewal, not after an incident.
Watch the national layer. Member states had until August 2, 2025 to designate market surveillance authorities and lay down penalty rules, and several are behind. Penalties become applicable alongside the August 2026 date for high-risk systems. The realistic near-term enforcement pattern is complaint-driven — a rejected candidate, a declined applicant, a works council — rather than proactive audits. Your first regulator contact will likely arrive attached to a specific person’s specific grievance, and the artifacts that matter will be the log entry and the override record for that one decision. Build for that scenario.
Frequently Asked Questions
We’re a 30-person company outside the EU. Does the EU AI Act really apply to us?
If the output of your AI system is used in the EU, yes. Screening candidates for an EU role, scoring EU customers for credit, or monitoring EU-based staff puts you in scope regardless of where you’re incorporated. Non-EU providers of high-risk systems must also appoint an authorised representative in the Union. SMEs do get relief on the penalty side — the lower of the fixed sum or the percentage applies — plus simplified technical documentation and priority access to regulatory sandboxes.
What’s the difference between a provider and a deployer, and can I be both?
A provider develops the system or has it developed and places it on the market under its own name or trademark. A deployer uses it under its own authority in a professional context. You can absolutely be both. Article 25 converts a deployer into a provider if you put your name or trademark on a high-risk system, substantially modify it, or change a system’s purpose so that it becomes high-risk. Fine-tuning a general model into a candidate-ranking tool is the textbook case, and it drags the full conformity assessment onto your side of the table.
Does using ChatGPT, Claude, or Gemini in my business make me high-risk?
Not by itself. General-purpose models sit under a separate GPAI regime aimed at the model developers, and GPAI transparency requirements largely land on them. Your use case creates high-risk status. Drafting marketing copy is not Annex III. Wiring the same model into an automated screen that ranks or filters job applicants is Annex III 4(a), and you may well have become a provider under Article 25 by building it.
How long do we have to keep AI logs?
At least six months for deployers under Article 26(6), where the logs are under your control, unless sector-specific EU or national law requires longer. Providers face a longer horizon — technical documentation and logs generally held for ten years after the system is placed on the market. In practice, retain deployer logs for at least as long as someone could plausibly challenge a decision the system influenced; twelve to twenty-four months is a more defensible default than the bare minimum.
What are the actual EU AI Act fines and penalties?
Three tiers. Prohibited practices under Article 5: up to 35 million euros or 7% of total worldwide annual turnover, whichever is higher. Breaches of most other obligations, including the high-risk provider and deployer duties and the Article 50 transparency rules: up to 15 million euros or 3%. Supplying incorrect, incomplete, or misleading information to notified bodies or national authorities: up to 7.5 million euros or 1%. For SMEs and startups, the lower of the two figures applies in each tier.
What’s the single highest-leverage thing to do this week?
Build the inventory and send the vendor evidence request. You cannot classify what you haven’t listed, and the artifacts you need — instructions for use, declaration of conformity, log export path — sit with vendors who will take weeks to respond. Everything else in the AI conformity assessment checklist is downstream of knowing what you run and what your suppliers will put in writing.
Go deeper than this article
This article covers the essentials. Our premium eguide library gives you the full step-by-step playbooks — prompts, workflows, and copy-paste recipes you can put to work today.