What is the full EU AI Act compliance timeline?
| Date | Obligation |
| August 2024 | Regulation entered into force |
| February 2025 | Prohibited AI practices apply — immediate enforcement |
| August 2025 | GPAI (General Purpose AI) model obligations apply, including systemic risk rules for frontier models |
| August 2026 | Full high-risk AI system obligations apply (Annex III) — conformity assessment, CE marking, registration |
| August 2027 | High-risk AI systems in Annex I safety legislation fully applicable |
What are the obligations for a company with a high-risk AI system?
If your company develops or deploys an AI system listed in Annex III (HR recruitment, credit decisions, educational assessment, critical infrastructure, law enforcement, border control, administration of justice), you must comply from August 2026 with the following requirements:
- Establish and maintain a documented risk management system (continuously updated throughout the lifecycle)
- Complete a conformity assessment and affix CE marking
- Register the system in the EU AI Database before placing it on the market
- Create complete technical documentation (system specification, training data, performance metrics)
- Implement an active human oversight mechanism during deployment
- Maintain logs of system decisions for traceability and audit purposes
- Establish a post-market monitoring system and report serious incidents to authorities
SME compliance checklist for the EU AI Act
- Inventory all AI systems your company develops or deploys — including tools bought from third parties
- Classify each system using the four-tier risk framework (Annex I and Annex III)
- Check whether any fall into the prohibited category — cease operation immediately if so
- For high-risk systems: begin the conformity process now to meet the August 2026 deadline
- For limited-risk systems (chatbots, generators): implement user transparency disclosure
- Establish an AI governance policy and assign an internal AI compliance lead
- Update contracts with AI tool providers to include AI Act compliance warranties
- Create and maintain an internal AI Register documenting all systems and their classifications
How IgeraRegtech handles it
Company question:
"We use an AI tool for CV screening in HR recruitment. What risk category does it fall into?"
IgeraRegtech answers:
"HR recruitment AI falls under Annex III, point 4 — HIGH RISK category. Obligations from August 2026: conformity assessment and CE marking, risk management system, EU AI Database registration, technical documentation and active human oversight mechanism. We recommend starting the conformity process now. Source: Regulation (EU) 2024/1689, Annex III(4)."
3 seconds24/7Source cited
Do you know which risk category your AI systems fall into?
IgeraRegtech automatically classifies your AI systems, generates compliance documentation and monitors regulatory updates. Free 14-day trial.
Try IgeraRegtech free — no card required
Summary: EU AI Act for SMEs
- Prohibited practices active from February 2025: social scoring, real-time biometric surveillance in public, subliminal manipulation.
- High-risk AI systems (HR, credit, critical infrastructure): full obligations from August 2026 — CE marking, risk management, EU AI Database registration.
- Limited-risk systems (chatbots, generators): transparency obligation to inform users they are interacting with AI.
- Maximum fines: €35M or 7% of global turnover for prohibited practice violations.
- IgeraFincas and IgeraLegal are limited-risk systems: active transparency, no autonomous decisions with legal impact.
Frequently asked questions
Does the EU AI Act apply to non-EU companies selling to European customers?
Yes. The AI Act has extraterritorial effect: it applies to any provider that places AI systems on the EU market or whose systems are used in the EU, regardless of where the provider is established. A US startup selling an HR screening tool to European companies must comply if the system is high-risk.
Is a customer service chatbot considered high-risk?
Generally no. A customer service chatbot falls into the limited-risk category and carries only a transparency obligation: inform users they are interacting with an AI system, not a human. If the chatbot autonomously makes decisions with significant impact on rights — such as denying credit or insurance — the classification escalates to high-risk.
Can the DPO take on the role of AI Officer under the AI Act?
The AI Act does not formally mandate an "AI Officer" for all companies (unlike the DPO under GDPR). However, appointing an internal AI compliance lead is best practice, particularly for companies developing or deploying high-risk systems. The DPO can take on this role if they have appropriate AI regulation training. For companies that are both GDPR and AI Act subject, combining the roles can be efficient — the AI Act and GDPR often overlap in data governance requirements.
What is the EU AI Database and who must register?
The EU AI Database is a public registry of high-risk AI systems managed by the European Commission. Providers of Annex III high-risk systems must register before placing them on the market or putting them into service. The registration covers provider details, system description, use case, and training data information. The database will be publicly searchable, creating transparency for regulators, procurement bodies and the public.
How does the AI Act interact with GDPR?
The AI Act and GDPR overlap significantly when AI systems process personal data. A high-risk AI system processing personal data (e.g. an HR recruitment tool) must comply with both frameworks simultaneously. The AI Act's technical documentation and logging requirements complement GDPR's accountability obligations. The European Data Protection Board has published guidance on the interaction between the two regulations.
Are IgeraFincas and IgeraLegal high-risk AI systems?
No. IgeraFincas and IgeraLegal are limited-risk AI systems: they are chatbots that provide regulatory information and answer resident or user queries. They do not make autonomous decisions with significant legal effects. They comply with the transparency obligation — users are always informed they are interacting with an AI — and every answer cites the exact regulatory source.
Article by the Igera Solutions editorial team. Based on Regulation (EU) 2024/1689 (EU AI Act) and European AI Office guidance, updated June 2026. Not legal advice.