Practice — EU AI Act compliance

Which AI systems
the Act actually touches.

Most organisations do not have an AI Act problem. They have an inventory problem — until somebody asks a question in writing.

We sort what you run, which category each system falls into, and who you are in law for each one.

Request a 30-minute diagnostic What the audit covers

jakub@novus-point.co.uk — every enquiry is answered at principal level.

One of three practices — EU AI Act compliance

The Act arrives in instalments

Where the Act stands.

The Act did not arrive on one date. It arrives in instalments, and in July 2026 the instalments were re-cut. Here is where the Regulation stands, taken from the Regulation and its amending act — not from the commentary around them.

This is the sorting exercise Novus Point runs first: which of your systems the Act actually touches, what that makes you responsible for, and what you would be able to evidence if you were asked tomorrow morning. The output is a written position a board can act on — not a policy pack, not a certificate.

The dates that already bind you

Regulation (EU) 2024/1689 has been in force since 1 August 2024.

  1. 2 February 2025

    01

    Article 5 prohibitions.

    The shortest list in the Act, and the first thing to clear.

  2. 2 February 2025

    02

    Article 4, AI literacy.

    An obligation about your people, not your software. That is why it is routinely missed.

  3. 2 August 2025

    03

    General-purpose AI model obligations.

    Chapter V, for those who place GPAI models on the market.

  4. 2 August 2025

    04

    Article 99 penalties.

    Enforceable. Article 101, the fines regime for GPAI model providers, followed on the general application date.

  5. 2 August 2026

    05

    The general date of application.

    On 2 August 2026. This is the one most UK boards missed, because it carries no headline: it is the date the Chapter IV transparency duties under Article 50 became live, along with the market-surveillance machinery that enforces them.

The Digital Omnibus on AI

What the Digital Omnibus changed — and what it did not.

Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, amended the AI Act. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Read the amendments precisely, because they are narrower than the relief being reported:

  1. From 2 December 2027 and 2 August 2028

    01

    High-risk obligations were deferred, not withdrawn.

    Chapter III, Sections 1–3 now apply from 2 December 2027 for systems classified high-risk under Article 6(2) and Annex III, and from 2 August 2028 for systems classified high-risk under Article 6(1) and Annex I. The stated reason is delayed standards and delayed national authorities. The requirements themselves are unchanged.

  2. From 2 December 2026

    02

    Two new prohibitions were added, applying 2 December 2026.

    Article 5(1) now also prohibits, at points (ba) and (bb), AI systems that generate or manipulate non-consensual intimate material and child sexual abuse material. The new Article 5(1a) sets out how that bites differently on each role: a provider is caught where such generation is the intended purpose, or is reasonably foreseeable without significant technical modification; a deployer is caught on actual use. That is 2 December 2026.

  3. Applies from 27 July 2026

    03

    Article 4 was rewritten, and softened.

    Providers and deployers must now take measures to support the development of AI literacy among staff and others operating AI on their behalf; the amended text states expressly that it does not require you to guarantee any specific level of literacy in any individual. The lighter formulation applies from 27 July 2026; the literacy obligation itself has applied since February 2025, in its stricter original form, and there was no deferral in between.

  4. Deadline 2 December 2026

    04

    Synthetic-content marking got a four-month runway.

    Providers whose generative systems were already on the market before 2 August 2026 have until 2 December 2026 to comply with the Article 50(2) marking duty.

Three windows, not equally urgent

What that means for you this quarter.

Three windows, and they are not equally urgent. What is already enforceable — prohibitions, literacy, transparency, penalties — is enforceable now, with no grace period attached. What lands on 2 December 2026 is close enough that it is a this-quarter item. The high-risk obligations land in December 2027 — ample time to prepare properly, and no time at all if nobody has yet written down what the organisation runs.

The deferral bought preparation time. It did not buy the right to start later.

Scope

Who is caught.

Almost every conversation we have starts with a firm that believes it is outside the Act because it does not build AI. The Act does not ask whether you build. It asks what role you occupy, system by system.

01 — Roles

Provider or deployer — the distinction that decides everything

Under Article 3(3), a provider develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark. Under Article 3(4), a deployer is anyone using an AI system under their authority, other than in the course of a personal, non-professional activity.

Read that second definition again. It has no threshold. A law firm running a contract-review tool is a deployer. A distributor using demand forecasting is a deployer. A recruitment team using a CV-screening product bought from a vendor is a deployer. There is no minimum spend, no minimum headcount, no carve-out for “we just use the off-the-shelf version”.

02 — Article 25

Why the role is not fixed

Article 25 sits in Chapter III, Section 3. Under the Digital Omnibus it applies from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Annex I high-risk systems. Read the timing carefully, because it is not a reason to defer the question.

Article 25(1) converts a deployer into a provider — with the full provider obligation set — in three circumstances: you put your own name or trademark on a high-risk system already on the market; you substantially modify such a system; or you modify the intended purpose of a system, including a general-purpose AI system, in a way that makes it high-risk under Article 6. When that happens, the original provider steps out of the provider role for that system — though under Article 25(2) it must still cooperate closely with you, make the necessary information available and provide reasonably expected technical access. That is not a clean discharge, and it is not a substitute for your own record.

Here is why the deferral does not help. The conversion is triggered by what you build, brand and repurpose — and firms are doing that now, in sprint planning sessions, without a written record of having crossed the line. Wrapping a general-purpose model in your own product, giving it your brand, and pointing it at a hiring or credit decision is not procurement. It is, in law, becoming a provider. The obligations attach in December 2027. The act that attracts them happens this quarter, and by 2027 nobody will remember which release it was.

03 — Article 2(1)

Extraterritorial reach, in one paragraph

Article 2(1) applies the Regulation to providers placing AI systems on the Union market “irrespective of whether those providers are established or located within the Union or in a third country”; to deployers established or located in the Union; and — the limb that catches British firms — to providers and deployers established in a third country “where the output produced by the AI system is used in the Union”. Establishment is not the test. Output is. A London company with no EU entity, running a model on UK infrastructure, is within scope the moment the output of that system is used in the Union — in a report to an EU client, a decision affecting an EU customer, a screening outcome for an EU applicant. Brexit did not move this boundary, because the boundary was never drawn at the border.

Penalties and proof

The exposure.

The fines are the headline. The evidential problem is the actual risk, and it is the one that cannot be fixed retrospectively.

01 — Article 99

What the penalties are

Article 99 sets three tiers. For infringement of the Article 5 prohibitions: administrative fines of up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher for an undertaking. For most other breaches — including the deployer obligations under Article 26 and the transparency obligations under Article 50 — up to EUR 15 million or 3%. For supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities, up to EUR 7.5 million or 1%.

Two moderating provisions matter, and they are not the same provision. The one most readers of this page fall under is Article 99(6): for SMEs, including start-ups, the fine is the lower of the percentage or the amount, and it applies across all three tiers. The Digital Omnibus then extended that treatment through Article 99(6a): the fine caps that applied to SMEs and start-ups — the lower of the percentage or the fixed amount — now reach small mid-cap enterprises as well. If your organisation sits in that bracket, it is worth establishing on paper which of your exposures the cap actually reaches, rather than assuming it covers all of them.

We do not lead with these numbers, and you should be sceptical of anyone who does. Fines are the tail of the distribution. The near-certain cost is elsewhere.

02 — Evidence

The evidential problem

Every obligation in this Regulation resolves, in practice, into a question of proof. Can you show which systems you run? Can you show which of them are high-risk, and on what reasoning?

Then there is the set of questions the deferral has scheduled rather than cancelled. From 2 December 2027 for Annex III systems, and 2 August 2028 for Annex I, Article 26 will ask a deployer of a high-risk system: who was assigned oversight, and did they have the competence, training and authority to exercise it, as Article 26(2) requires? Can you produce the logs Article 26(6) requires you to retain for at least six months? Can you show workers and their representatives were informed before deployment, as Article 26(7) requires?

None of that can be manufactured after the question is asked. Log retention is not a policy you adopt in November 2027 — it is a system configuration that either was or was not set years earlier, and the six months of history the Act asks for must already exist on the day the duty bites. Oversight assignments and workforce notifications are the same: they are records of things done at the time, or they are nothing. The organisations that will struggle are not the reckless ones. They are the ones that did everything sensibly and wrote none of it down.

There is a second-order exposure that boards notice faster than regulators do, and it does not wait for 2027: your customers’ procurement teams. EU-based buyers are already putting AI Act representations into contracts. A firm that cannot answer a supplier questionnaire loses the deal long before it meets an authority.

The engagement

What the audit covers in this practice.

The entry point is the audit. It runs in three steps:

  1. 01

    Diagnostic — 30 minutes, no charge.

    A conversation about what you run and what you have already committed to in writing.

  2. 02

    Written position.

    A board-facing document setting out where you stand and what to do first.

  3. 03

    Engagement, if warranted.

    Only if the written position shows there is work worth doing.

Three areas sit under that audit: EU AI Act compliance, AI governance and AI automation. This page covers the first. The same diagnostic opens all three, and in practice most engagements touch more than one — governance is what makes a compliance position hold, and automation is where the next set of systems will come from.

Deliverables

For this practice, the work produces five artefacts.

Each is a document a board can hold, take away and be examined on.

The five artefacts

  • 01 — AI system inventory A register of what the organisation actually runs, including the systems nobody sanctioned: the departmental subscription, the plug-in inside the CRM, the model embedded in a product you bought for another reason. Fields that matter under the Act — purpose, data in, decision out, who touches it, where the output goes, whether it reaches the Union.
  • 02 — Role determination, system by system For each entry: are you provider, deployer, both, or neither, and on what reasoning. Includes an explicit Article 25 test on anything branded, modified or repurposed in-house, so the moment you would become a provider is identified before it happens rather than after.
  • 03 — Classification against the Act’s categories Each system tested against the Article 5 prohibitions, the Annex III high-risk list read with Article 6, the Article 50 transparency triggers, and the general-purpose AI provisions. Most systems land outside high-risk. Knowing that with reasons on the page is worth more than assuming it.
  • 04 — The written position A short board-facing document: what you have, what it is exposed to, what to do first, what can wait, and what is out of scope with the reasoning shown. Written to survive being forwarded to your general counsel, your insurer and your largest customer.
  • 05 — AI-literacy programme under Article 4, and the documentation baseline A literacy programme scoped to the amended Article 4 — proportionate measures matched to roles and to the context each system is used in, with a record that they were taken. Alongside it, the documentation baseline for the obligations that follow: oversight assignment under Article 26(2), input-data control under Article 26(4), monitoring and suspension under Article 26(5), log retention under Article 26(6), worker information under Article 26(7), the fundamental rights impact assessment under Article 27 where you fall within it, and the disclosure notices required by Article 50(3) and 50(4).

House stance: We will not promise you compliance. No adviser can — the regulator decides that, not us. What we give you is an accurate picture of where you stand and a defensible order of work. In most cases, that is precisely what was missing.

Four situations

Who this is for.

Four situations we are called into. If one of them reads like your week, the diagnostic is the right next half hour.

01 — General counsel

The general counsel who has been asked to sign something

An EU client has sent a supplier questionnaire with AI Act representations in it. You are being asked to warrant things about systems you did not procure and cannot see. You need an inventory and a defensible position before you put your name to a contractual statement.

02 — Chief compliance officer

The chief compliance officer with a policy but no register

There is an AI policy. It was approved. It says the right things. What there is not is a list of systems, a role determination for each, or evidence that anyone has been trained in a way Article 4 would recognise. The policy is the easy artefact. The register is the one that gets asked for.

03 — Chief operating officer

The COO who rolled out an assistant across the business

Copilot, or its equivalent, went to every desk and productivity improved. Since then, teams have connected it to systems nobody mapped and pointed it at decisions nobody classified. The question is no longer whether to allow it. It is which uses have quietly become something the Act treats differently.

04 — Chief executive

The chief executive of a UK firm serving EU customers

No EU entity, no EU office, and a growing share of revenue from EU clients whose decisions your systems inform. You have been told the Act is a European problem. Article 2(1)(c) says it follows the output, and your board is entitled to a clear written answer on that point rather than reassurance.

In the diagnostic

Questions we are actually asked.

01 — Scope

We only use ChatGPT and Copilot. Are we in scope?

Yes, as a deployer. Article 3(4) defines a deployer as anyone using an AI system under their authority outside personal, non-professional use — there is no size or spend threshold.

Two obligations already bind you. Article 4 literacy, which has applied since 2 February 2025. And the deployer limbs of Article 50, live since the general application date of 2 August 2026: Article 50(3) requires you to inform people exposed to emotion recognition or biometric categorisation, and Article 50(4) requires you to disclose deepfake content, and to disclose AI-generated text where it is published with the purpose of informing the public on matters of public interest — not all published AI-assisted text, and not text that has gone through human review or editorial control where a person or company holds editorial responsibility for the publication. Routine marketing copy and client documents will usually sit outside that duty. It is worth knowing which side of the line yours sits on, rather than assuming.

The third thing is not yet a duty, but it is a decision you are taking now: Article 25. If anyone in your organisation brands, substantially modifies or repurposes one of those tools in a way that would make it high-risk, the provider obligations attach when Chapter III, Section 3 applies — 2 December 2027 for Annex III systems, 2 August 2028 for Annex I. The conversion is caused by what you ship now. Being a deployer is a light obligation set. It is not an empty one, and it is not permanent.

02 — Extraterritoriality

We are a UK company with EU customers. Does the Act reach us?

Yes, on the Act’s own terms. Article 2(1)(c) applies the Regulation to providers and deployers established in a third country “where the output produced by the AI system is used in the Union”. Article 2(1)(a) applies it to providers placing systems on the Union market regardless of where they are established. Neither limb depends on you having an EU entity, EU infrastructure or EU staff. The practical test is where the output of the system is used — and for most UK B2B firms with European clients, at least some of it is.

03 — Vendors

Our vendor says they handle AI Act compliance. Is that enough?

No, and it is not the vendor’s to give. Provider obligations and deployer obligations are separate sets held by separate parties, and no contract moves them.

Article 26 applies to you only as a deployer of a high-risk system, and only from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. When it applies, it will require you to use the system in accordance with the provider’s instructions for use, to assign human oversight to people with the necessary competence, training and authority, to ensure input data you control is relevant and sufficiently representative, to monitor operation and suspend use where a risk emerges, to retain logs for at least six months, and to inform workers’ representatives and affected workers before the system goes live in the workplace.

Two consequences follow. If none of your systems is high-risk, Article 26 never reaches you — which is worth establishing on paper rather than hoping. If any of them is, the evidence those duties call for has to be accumulating well before the date, and the contract you sign with the vendor this year determines whether you can produce it. A vendor’s assurance is useful evidence. It is not a transfer of responsibility.

04 — GPAI Code of Practice

Does the general-purpose AI Code of Practice apply to us?

Almost certainly not directly. The Code of Practice, published by the Commission on 10 July 2025, is a voluntary instrument for providers of general-purpose AI models, structured in three chapters — transparency, copyright, and safety and security — addressing obligations under Articles 53 and 55. If you use models rather than place them on the market, you are not a signatory and cannot become one. It is still worth reading: the transparency chapter’s model documentation form tells you exactly what your model provider should be able to give you, which makes it a useful procurement instrument even though it imposes nothing on you.

05 — The dates ahead

What actually happens on 2 December 2027 — and is 2 December 2026 relevant to us?

On 2 December 2027, Chapter III Sections 1–3 apply to systems classified high-risk under Article 6(2) and Annex III: the requirements on risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, together with the provider and deployer obligations that attach to them — Articles 16 to 27, including the Article 25 role conversion, the Article 26 deployer duties and the Article 27 fundamental rights impact assessment. Systems high-risk under Article 6(1) and Annex I follow on 2 August 2028. Nothing happens automatically on either date — the question is whether, by then, you can show which of your systems fall inside Annex III and which do not, and whether the records those articles will ask for have been accumulating in the meantime.

2 December 2026 is likely to be more immediately relevant. Two new Article 5 prohibitions take effect that day, at points (ba) and (bb) of Article 5(1), covering AI systems that generate or manipulate non-consensual intimate material and child sexual abuse material, with the provider and deployer conditions set out in the new Article 5(1a). Firms that build or fine-tune generative image or video capability should be reading those provisions now, not in November. The same date closes the four-month transitional window for Article 50(2) synthetic-content marking for generative systems already on the market before 2 August 2026.

Next step

Thirty minutes. Then you will know where you stand.

The diagnostic is a conversation, not a pitch. We ask what you run, who touches it, where the output goes and what you have already committed to in writing. You get a straight answer on the call about whether this is worth taking further — including, often enough, that it is not.

We build and run AI systems as well as advise on them. Hadar AI, a CRM for Dubai real-estate brokerages, and ADOZ are both in production and both run by the firm. That is the reason our inventory and classification work is quick: we have had to answer these questions about our own systems first. The firm is led by Jakub Piórkowski, Founder and Principal, Chairman of the Supervisory Board of Carlson Investments SE, listed on the Warsaw Stock Exchange (WSE: CAI), elected August 2026.

Engagements are senior-led throughout. Where the work needs legal, security or data expertise, we bring in advisers who have it, under the firm’s direction and on the firm’s responsibility. There is no handover to a junior after signature.

Request a 30-minute diagnostic

jakub@novus-point.co.uk — every enquiry is answered at principal level.

Back to the home page