EU AI Act compliance
Turn AI obligations into enforceable guardrails.
Inventory your AI systems, determine your role and risk classification, automate assessments, assign controls, preserve evidence and monitor compliance as the EU AI Act evolves.
Assess Your AI SystemsExplore AI Governance
// Software-powered workflows backed by real privacy and governance specialists.
Illustrative demonstration data
The EU AI Act is now being enforced
Most applicable provisions, including Article 50 transparency requirements and enforcement powers, began applying on 2 August 2026. High-risk obligations continue to phase in through 2027 and 2028.
// Updated for the AI Omnibus — Regulation (EU) 2026/1744, in force 27 July 2026.
Who it applies to
The AI Act can apply well beyond companies headquartered in Europe.
The EU AI Act assigns obligations according to an organization’s role in the AI value chain and the way an AI system is placed on the market, put into service or used.
Providers
Organizations that develop an AI system or general-purpose AI model — or have one developed — and place it on the market or put it into service under their name or trademark.
Deployers
Organizations using an AI system under their authority, except for certain personal, nonprofessional uses.
Importers
EU-established organizations placing an AI system bearing a non-EU provider’s name or trademark on the EU market.
Distributors
Organizations in the supply chain that make an AI system available in the EU but are not the provider or importer.
Product manufacturers
Manufacturers placing AI systems on the market or putting them into service with a regulated product under their own name or trademark.
Authorized representatives
EU-established representatives appointed by providers located outside the EU.
Organizations outside the EU may be covered when they place AI systems or models on the EU market, or when an AI system’s output is used in the EU.
Risk classification
Different AI systems create different obligations.
Prohibited AI practices
Certain practices are prohibited because they present unacceptable risks. Examples can include specific forms of manipulation, exploitation, social scoring, biometric categorization, emotion recognition and biometric identification — subject to the Act’s definitions and exceptions. Not every use of biometrics or emotion recognition is automatically prohibited.
High-risk AI systems
High-risk categories can include certain uses involving:
Employment and worker managementEducation and vocational trainingAccess to essential servicesCreditworthiness and insuranceBiometricsCritical infrastructureLaw enforcementMigration and border controlJustice and democratic processesAI embedded in regulated products
Transparency-risk systems
Certain AI interactions and generated or manipulated content can trigger transparency duties, including:
Chatbots and direct-interaction systemsAI-generated or manipulated synthetic contentDeepfakesEmotion-recognition systemsBiometric-categorization systemsCertain AI-generated text on matters of public interest
General-purpose AI
Providers of general-purpose AI models can have separate documentation, information, copyright, transparency and — in some cases — systemic-risk obligations.
Minimal or no additional risk
Many AI applications do not fall into a prohibited or high-risk category, but organizations should still inventory, review, document and monitor them under an internal governance program.
// Risk classification is fact-specific. Intended purpose, deployment context, affected individuals, organizational role and changes to the system can all affect the classification.
What to operationalize
The AI Act requires more than a policy document.
AI inventory
Maintain an authoritative record of internally developed, purchased, embedded and employee-adopted AI systems.
Role determination
Record whether the organization acts as a provider, deployer, importer, distributor, product manufacturer or authorized representative.
Risk classification
Evaluate prohibited-practice, high-risk, transparency and general-purpose AI requirements.
AI assessments
Run configurable assessments based on role, risk, use case, jurisdiction, personal data and affected groups.
Human oversight
Assign accountable individuals, document intervention procedures and preserve evidence of meaningful oversight.
Transparency controls
Track required notices, AI interaction disclosures, synthetic-content labeling and accessibility requirements.
Incident and change management
Capture incidents, complaints, material changes, new vendors, model updates and changes in intended use.
Evidence and reporting
Maintain policies, approvals, technical documentation, training records, assessments, decisions, controls and audit evidence.
Implementation timeline
EU AI Act implementation timeline.
1 August 2024
The EU AI Act entered into force.
2 February 2025
Definitions, prohibited AI practices and AI-literacy requirements began applying.
2 August 2025
Governance provisions and obligations for general-purpose AI models began applying.
2 August 2026
Most remaining provisions began applying, including Article 50 transparency obligations and enforcement for applicable requirements.
2 December 2026
New prohibitions introduced through the AI Omnibus apply, along with the transition deadline for certain existing synthetic-content systems under Article 50(2).
2 August 2027
Member States should have at least one AI regulatory sandbox operational.
2 December 2027
Requirements for high-risk AI systems covered by Annex III begin applying under the amended timeline.
2 August 2028
Requirements for high-risk AI embedded in regulated products covered by Annex I begin applying.
// Last legally reviewed: August 2026. Dates reflect the AI Omnibus, Regulation (EU) 2026/1744. The Act continues to develop through implementation measures, standards, guidance and codes of practice.
AI literacy
AI literacy is already an active obligation.
Providers and deployers must take measures to ensure a sufficient level of AI literacy among relevant staff and other persons operating or using AI systems on their behalf, considering their technical knowledge, experience, education, training and the context in which the systems are used.
Role-based AI training assignmentsPolicy acknowledgmentsCompletion recordsSystem-specific guidanceDocumented competencyPeriodic refresh requirementsEvidence for internal and external review
// One generic employee training course does not satisfy every organization’s obligation. The required level depends on role, system and context. This duty has applied since 2 February 2025 and was not postponed by the AI Omnibus.
Assessments
Connect AI assessments to privacy assessments.
AI systems frequently raise overlapping questions involving the EU AI Act, GDPR, data protection impact assessments, security, vendors, fundamental rights and internal risk policies. Captain Compliance connects these reviews so organizations do not have to answer the same questions repeatedly.
AI system intake assessmentsProhibited-practice screeningRisk-classification assessmentsProvider and deployer assessmentsFundamental Rights Impact AssessmentsData Protection Impact AssessmentsVendor assessmentsGeneral-purpose AI reviewsHuman-oversight assessmentsChange and reassessment workflows
// Not every organization or high-risk system requires a Fundamental Rights Impact Assessment. Article 27 applies to specified deployers and use cases. Where applicable, an FRIA complements rather than automatically replaces a GDPR DPIA.
The workflow
From AI discovery to defensible governance.
Software capabilities
AI governance software with experts behind it.
Central AI inventory
Keep every approved, restricted, experimental and retired AI system in one governed record.
Configurable assessments
Use conditional questions, reusable templates, approval routing and supporting evidence.
AI-assisted workflows
Use AI agents to organize responses, identify missing information, suggest classifications and help draft remediation tasks — with human review and approval.
Control mapping
Connect requirements to policies, risks, systems, vendors, owners and evidence.
Guardrail management
Define acceptable use, restricted uses, human-review requirements, data restrictions and escalation procedures.
Continuous monitoring
Trigger reassessment when an AI system, model, vendor, purpose, geography or risk profile changes.
Executive reporting
Give leadership visibility into AI adoption, risk levels, unresolved findings and governance status.
Expert support
Access Captain Compliance privacy, assessment and governance specialists.
// AI agents support human review. They do not make final legal determinations autonomously.
Penalties
EU AI Act penalties can reach global-turnover levels.
Prohibited practices
€35M or 7%
Up to €35 million or 7% of worldwide annual turnover, whichever applies under the Act’s rules.
Other operator and transparency violations
€15M or 3%
Up to €15 million or 3% of worldwide annual turnover.
Incorrect or misleading information
€7.5M or 1%
Up to €7.5 million or 1% of worldwide annual turnover.
// Different calculations apply to SMEs, including startups, and penalties must account for the circumstances of the infringement. Maximum penalties are not automatic. Source: Article 99, official AI Act Service Desk.
Connected solutions
Build one connected governance program.
Questions
The EU AI Act, answered plainly.
What is the EU AI Act?
It is the European Union’s horizontal regulation for artificial intelligence, assigning obligations by risk level and by the organization’s role in the AI value chain. It entered into force on 1 August 2024 and applies in phases, most recently amended by the AI Omnibus, Regulation (EU) 2026/1744.
Does the EU AI Act apply outside Europe?
It can. Organizations established outside the EU may be covered when they place AI systems or general-purpose AI models on the EU market, or when the output of an AI system is used in the EU.
What is the difference between a provider and a deployer?
A provider develops an AI system or model — or has one developed — and places it on the market or into service under its own name or trademark. A deployer uses an AI system under its own authority. The same organization can be a provider for one system and a deployer for another, and the obligations differ.
What counts as a high-risk AI system?
High-risk categories include certain uses in employment, education, essential services, creditworthiness and insurance, biometrics, critical infrastructure, law enforcement, migration, and justice, as well as AI embedded in certain regulated products. Whether a specific system qualifies depends on its intended purpose, the applicable annex and the organization’s role.
Are all AI systems regulated in the same way?
No. The Act is tiered: prohibited practices, high-risk systems, transparency-risk systems, general-purpose AI models, and everything else. Obligations differ substantially between tiers.
What are the EU AI Act’s transparency requirements?
Article 50 covers duties such as disclosing that a person is interacting with an AI system, labeling AI-generated or manipulated content, and disclosures for deepfakes, emotion recognition and biometric categorization. Most Article 50 obligations began applying on 2 August 2026; certain existing synthetic-content systems have until 2 December 2026 under Article 50(2).
What is an AI literacy program?
Article 4 requires providers and deployers to ensure a sufficient level of AI literacy among staff and others operating AI systems on their behalf, taking account of their knowledge, experience, training and the deployment context. It has applied since 2 February 2025 and was not postponed.
Does every organization need a Fundamental Rights Impact Assessment?
No. Article 27 applies to specified deployers and use cases rather than to every organization or every high-risk system. Where an FRIA is required, it complements a GDPR DPIA rather than automatically replacing it.
How does the EU AI Act interact with GDPR?
They operate in parallel. An AI system processing personal data can trigger obligations under both, and a single system may require an AI Act assessment and a GDPR DPIA covering different questions. Connecting the two reviews avoids duplicated effort.
What are the maximum penalties?
Up to €35 million or 7% of worldwide annual turnover for prohibited practices; up to €15 million or 3% for other operator and transparency violations; and up to €7.5 million or 1% for supplying incorrect or misleading information. Different calculations apply to SMEs, and maximums are not automatic.
How can Captain Compliance help?
The platform maintains your AI inventory, records organizational role and risk classification, runs the applicable assessments, assigns guardrails and owners, tracks remediation, monitors material changes and preserves the evidence behind each decision — with privacy and governance specialists available for the harder judgments.
Get started
Turn the EU AI Act into an operating system for responsible AI.
Inventory your AI systems, classify risks, automate assessments, assign guardrails and maintain the evidence your organization needs.
Assess Your AI SystemsBook an AI Governance Demo
Captain Compliance provides privacy and AI governance technology, implementation and support. It does not provide legal advice and does not guarantee compliance with the EU AI Act. Classification, applicable obligations and required assessments depend on your systems, role, intended purpose and jurisdiction, and warrant review by qualified counsel.