EU AI Act Compliance Guide: What Organisations Need to Know Before August 2026
The EU AI Act is the world's first comprehensive AI law. Prohibited practices are already enforceable; high-risk obligations take effect on 2 August 2026. Here's what regulated organisations need in place now.

On this page›
- What Is the EU AI Act and Why Does It Matter?
- What Is the EU AI Act's Risk-Based Framework?
- What AI Practices Are Prohibited Under Article 5?
- Which AI Systems Are Classified as High-Risk Under Article 6?
- What Are the Compliance Requirements for High-Risk AI Systems? (Articles 9–15)
- What Are the Transparency Obligations Under Article 50?
- How Does WalledAI Function as Sovereign AI Governance Infrastructure?
- Frequently Asked Questions About EU AI Act Compliance
- The Bottom Line: AI Adoption and Compliance Must Move Together
Regulation (EU) 2024/1689 | Last reviewed: April 2026
Quick answer: The EU AI Act is the world's first comprehensive AI law, in force since August 2024. Prohibited practices have been enforceable since February 2025. High-risk AI obligations take effect on 2 August 2026. Organisations deploying AI in regulated sectors need a risk management system, audit logs, human oversight mechanisms, and data governance controls in place now - not after the deadline.
What Is the EU AI Act and Why Does It Matter?
Every industrial revolution disrupts existing institutional frameworks and forces regulators to establish a new order. The first, second, and third industrial revolutions each produced their own regulatory responses. The fourth - driven by artificial intelligence - is no different.
The European Union Artificial Intelligence Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and is widely recognised as the world's first comprehensive, horizontal legal framework for AI. Its phased implementation schedule means that while prohibitions on the most harmful AI practices are already enforceable, the obligations for high-risk AI systems come into force on 2 August 2026. For organisations deploying AI in sensitive contexts, the preparation window is closing.
The rapid uptake of AI presents both transformative opportunities and serious risks - from biometric surveillance and AI-enabled social engineering to predictive policing and algorithmic discrimination. The EU AI Act provides a framework of guardrails to ensure the appropriate use of large language models (LLMs) and generative AI systems.
Beyond Europe, the Act's influence will extend globally through the "Brussels Effect" - the EU's established ability to shape international business standards through regulation. Countries including the United Kingdom, Singapore, and the United States are already developing their own AI regulatory frameworks, with the EU AI Act serving as the primary reference point.
What Is the EU AI Act's Risk-Based Framework?
The EU AI Act classifies AI systems into four risk tiers, each with distinct obligations and enforcement timelines.
| Risk Level | Examples | Key Obligations | Enforcement Date |
|---|---|---|---|
| Unacceptable - poses a critical threat to human rights and safety | Social scoring, real-time biometric identification in public spaces, subliminal manipulation, predictive policing, exploiting vulnerabilities to influence behaviour | Prohibited (with narrow exceptions, e.g. national security) | February 2025 |
| High Risk - may pose a threat to health, safety, or fundamental rights | Critical infrastructure, law enforcement, biometric identification, education systems, employment management | Pre-market conformity assessment, continuous risk management, human oversight, technical documentation | August 2026 |
| Limited Risk - end users may not be aware they are interacting with AI | Chatbots, AI assistants, AI-generated videos, images, and audio | Transparency: users must be informed they are interacting with AI | August 2026 |
| Minimal Risk | Spam filters, video game AI | None | N/A |
Note: GPAI model obligations became applicable on 2 August 2025. High-risk AI systems embedded into regulated products (e.g. medical devices, machinery) have an extended transition period until 2 August 2027.
What AI Practices Are Prohibited Under Article 5?
Article 5 of the EU AI Act establishes an absolute prohibition on AI practices deemed to pose a fundamental threat to human rights, safety, or democratic processes. These prohibitions have been enforceable since 2 February 2025.
The eight prohibited practices are:
- Subliminal or manipulative techniques (Article 5(1)(a)): Distorting an individual's decision-making without their awareness
- Exploitation of vulnerabilities (Article 5(1)(b)): Using AI to exploit vulnerabilities related to age, disability, or socioeconomic status to influence behaviour
- Social scoring (Article 5(1)(c)): Inferring and assigning social scores based on an individual's characteristics or personality traits
- Predictive policing and criminal profiling (Article 5(1)(d)): Assessing or predicting the risk of a person committing a criminal offence based on profiling
- Untargeted biometric scraping: Building or expanding facial recognition databases from internet or CCTV footage
- Emotion recognition in workplaces and educational institutions
- Biometric categorisation to deduce protected characteristics (Article 5(1)(g)): Inferring race, political opinions, trade union membership, religious beliefs, sex life, or sexual orientation
- Real-time remote biometric identification in public spaces for law enforcement purposes
A critical compliance note: Article 5 targets intentional epistemic manipulation, but its spirit extends to the provision of misleading information through AI hallucinations. Organisations should not assume that unintentional inaccuracy falls outside the regulatory framework. Hallucination management is a compliance obligation, not just a product quality issue.
Which AI Systems Are Classified as High-Risk Under Article 6?
Article 6 classifies an AI system as high-risk if it meets one of two conditions:
- It is used as a safety component of a product subject to EU harmonisation legislation (Annex I) and requires third-party conformity assessment; or
- It falls within the use cases listed in Annex III of the Act.
Annex III domains that are always considered high-risk include:
- Biometrics: Remote biometric identification, biometric categorisation, and emotion recognition systems
- Critical infrastructure: Digital infrastructure, road traffic, water, and energy management
- Education and vocational training: Admissions, evaluation of learning outcomes, monitoring student behaviour during assessments
- Employment and worker management: Recruitment, performance evaluation, and access to self-employment
- Essential private and public services: Healthcare, insurance, banking, and first responders
- Law enforcement and criminal justice
- Migration, asylum, and border control management
- Administration of justice and democratic processes
Deployers of high-risk AI systems bear significantly greater responsibility, including data governance, human oversight, and comprehensive documentation obligations, as outlined in Articles 8 to 27.
Important: Any AI system in Annex III that performs profiling of individuals - automated processing of personal data to assess behaviour, economic situation, health, or movement - is always classified as high-risk, regardless of other conditions.
What Are the Compliance Requirements for High-Risk AI Systems? (Articles 9–15)
Articles 9 to 15 define the core compliance obligations for high-risk AI providers and deployers. The table below maps each requirement to WalledAI's capabilities.
| Article | Regulatory Requirement | Relevant WalledAI Capability |
|---|---|---|
| Article 9 - Risk Management System | Providers must establish, document, and continuously maintain a risk management system covering health, safety, and fundamental rights risks throughout the AI system's lifecycle. | Walled Protect allows deployers to define operational boundaries at the input and output levels - restricting off-topic prompts, enforcing industry-specific restrictions, and filtering toxic content. |
| Article 10 - Data and Data Governance | Training, validation, and testing datasets must meet quality criteria: relevant, sufficiently representative, and free of errors and bias to the extent possible. | Walled Redact prevents organisational secrets and confidential data from being shared with AI models, reducing data contamination at the point of use. |
| Articles 11 and 12 - Technical Documentation and Record Keeping | Providers must maintain extensive technical documentation before market placement. Deployers must retain operational logs, with particular attention to cybersecurity (Article 15). | Walled Protect maintains a comprehensive audit log enabling human review. Walled Redact ensures sensitive personal data is not stored or exposed in the event of a data breach. |
| Article 13 - Transparency and Information to Deployers | High-risk AI systems must provide deployers with clear information about the system's functioning, the basis for its outputs, and its limitations. | Walled Correct validates AI outputs before they reach end users, supporting output reliability under Article 13 and reducing the risk of epistemic manipulation through inaccuracy under Article 5. |
| Article 14 - Human Oversight | High-risk AI systems must be designed and developed so that natural persons can effectively oversee them throughout deployment. | Walled Protect allows humans to define model limitations and generates an audit log that enables meaningful oversight. |
What Are the Transparency Obligations Under Article 50?
Article 50 places transparency obligations on providers and deployers of AI systems that interact with users or generate synthetic content. The key requirements are:
- Chatbots and AI assistants: Users must be informed they are interacting with an AI system (unless this is obvious from context)
- Deepfake videos and synthetic images: Providers must ensure AI-generated content is clearly labelled as artificial
- AI-generated text for public information: Content published with the intent to inform the public on matters of public interest must be disclosed as AI-generated
WalledAI can intervene at both the input and output layers of data interactions, ensuring users are explicitly aware they are engaging with AI and understand the nature of the content they receive.
Beyond WalledAI's ability to determine content origins and verify authenticity, comprehensive compliance with Article 50 will also require standardised labelling frameworks. This is an area where the EU AI Office is actively developing guidance.
How Does WalledAI Function as Sovereign AI Governance Infrastructure?
WalledAI is designed to provide a durable, runtime governance layer around an organisation's AI deployments - without requiring those organisations to build compliant AI infrastructure from scratch.
As sovereign AI governance infrastructure, WalledAI operates independently of the underlying AI model. This means firms can adopt new models, switch providers, or scale deployments without re-engineering their compliance posture. The governance layer travels with the deployment.
This matters because the EU AI Act is the first of its kind, but it is not the last. Regulatory frameworks are advancing in parallel across:
- Singapore: PDPA amendments and the Model AI Governance Framework, with IMDA providing compliance guidance
- United Kingdom: The AI Safety Institute's evaluation frameworks and sector-specific guidance
- United States: Executive orders on AI safety and emerging state-level legislation
Sovereign AI governance infrastructure allows organisations to adapt to this evolving multi-jurisdictional landscape without rebuilding compliance systems for each new regulation.
Frequently Asked Questions About EU AI Act Compliance
What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It entered into force on 1 August 2024 and classifies AI systems into four risk tiers - unacceptable, high-risk, limited risk, and minimal risk - each with distinct obligations for providers and deployers.
When does the EU AI Act come into force?
The EU AI Act has a phased implementation schedule:
- 2 February 2025: Prohibited AI practices (Article 5) and AI literacy obligations became enforceable
- 2 August 2025: GPAI model obligations became applicable
- 2 August 2026: High-risk AI system obligations (Articles 8–27) and transparency obligations (Article 50) take effect
- 2 August 2027: Extended deadline for high-risk AI systems embedded in regulated products (e.g. medical devices, machinery)
Who does the EU AI Act apply to?
The Act applies to providers (developers) and deployers (organisations using AI in a professional capacity) operating in the EU, regardless of where they are based. Third-country providers whose AI system outputs are used in the EU are also in scope.
What are the penalties for non-compliance with the EU AI Act?
Fines for violations of prohibited practices (Article 5) can reach €35 million or 7% of global annual turnover, whichever is higher. Violations of other obligations can result in fines of up to €15 million or 3% of global annual turnover.
What is a high-risk AI system under the EU AI Act?
A high-risk AI system is one that either serves as a safety component in a product subject to EU harmonisation legislation, or falls within the Annex III use cases (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice). Any Annex III system that profiles individuals is always classified as high-risk.
How can organisations prepare for EU AI Act compliance?
Organisations should: (1) conduct an AI system inventory to identify high-risk deployments; (2) implement a risk management system per Article 9; (3) establish data governance controls per Article 10; (4) set up audit logging per Articles 11–12; (5) deploy human oversight mechanisms per Article 14; and (6) ensure transparency disclosures per Article 50. Sovereign AI governance infrastructure like WalledAI can operationalise steps 2–6 without requiring bespoke infrastructure development.
What is the Brussels Effect in the context of AI regulation?
The Brussels Effect refers to the EU's ability to influence global regulatory standards through its own legislation. Because multinational organisations must comply with EU rules to access the EU market, EU standards effectively become global standards. The EU AI Act is expected to shape AI regulation in the UK, Singapore, and beyond.
The Bottom Line: AI Adoption and Compliance Must Move Together
AI is moving from experimentation to regulation. Failure to adapt will not just slow organisations down - it will expose them to serious regulatory penalties and legal liability.
The models are getting more capable and more robust, and regulatory scrutiny is rising in parallel. The sustainable path forward is one where the speed of adoption and the rigour of compliance move in lockstep.
WalledAI exists precisely to make that possible: a governance layer that ensures compliant AI deployment without requiring organisations to choose between innovation and accountability.
Sources: EU AI Act full text | EU AI Act high-level summary | European Commission AI Act overview
Get audit-ready before August 2026.
See how WalledAI operationalises Articles 9–15 and Article 50 obligations as a runtime governance layer.
