EU AI Act Advisory

EU AI Act Consulting
& Compliance Advisory

High-risk AI enforcement began 2 August 2026. GPAI rules have applied since August 2025. Article 4 AI-literacy obligations have been in force since February 2025. We help enterprises classify AI systems, meet Article 26 deployer obligations, and build the audit trail regulators require.

Scope & Obligations

What the EU AI Act Requires

The Act applies to any organisation whose AI systems are used in the EU — regardless of where that organisation is based.

Prohibited AI Systems

Social scoring, real-time biometric surveillance in public spaces, and manipulative AI are banned outright. In force since February 2025.

High-Risk AI Obligations

AI in employment, credit, education, and critical infrastructure requires conformity assessments, technical documentation, and post-market monitoring. Deadline: August 2026.

GPAI Model Rules

General-purpose AI model obligations — transparency, copyright policy, evaluations, and systemic risk assessments — have applied since August 2025.

EU AI ACT ENFORCEMENT CALENDAR

The Compliance Window Is Closing

The EU AI Act is not forthcoming legislation — it is live. Key obligations are already in force.

Aug 2024

Act Entered Into Force

The EU AI Act became law. All organisations with AI systems operating in the EU are within scope.

Feb 2025

Prohibited AI Systems Banned

Chapter II prohibitions apply. Unacceptable-risk AI systems are now illegal to operate.

Aug 2025

GPAI & Governance Obligations

General-purpose AI model obligations and governance rules for all operators are now in force.

Aug 2026

High-Risk AI (Annex III)

High-risk AI systems in areas like employment, education, and critical infrastructure must be fully compliant.

Aug 2027

High-Risk AI (Annex I)

AI systems embedded in regulated products (medical devices, machinery) must meet full compliance requirements.

Has your organisation classified its AI systems?

Book a Compliance Assessment

Our Advisory Work

How Imagine Works Supports EU AI Act Compliance

01

AI System Risk Classification

We inventory your AI systems, classify each against EU AI Act risk tiers, and identify which face prohibited, high-risk, or GPAI obligations — before regulators do.

02

Governance Framework Design

We design the governance architecture: risk management procedures, human oversight protocols, accountability structures, and the post-market monitoring system the Act requires.

03

Technical Documentation & Audit Readiness

We produce model cards, conformity documentation, data governance records, and the logging architecture that forms the audit trail for high-risk AI systems.

Frequently Asked

EU AI Act — Questions Enterprise Leaders Ask

Who does the EU AI Act apply to?
The Act applies to any organisation whose AI systems are used in the EU, regardless of where the organisation is based. That includes providers (who build or place AI on the EU market), deployers (who use AI in their operations in the EU), importers, distributors, and product manufacturers. A US-headquartered SaaS company with EU customers is in scope. So is an Indian services firm running AI-based decisions on EU customer data.
What are the EU AI Act enforcement deadlines?
Prohibited AI practices have been in force since 2 February 2025. AI literacy obligations under Article 4 also applied from 2 February 2025. General-purpose AI model rules applied from 2 August 2025. High-risk AI system obligations under Annex III began enforcement from 2 August 2026, when the wider enforcement architecture activated across national market surveillance authorities and sectoral regulators.
What are the fines for EU AI Act non-compliance?
Article 99 sets three tiers: up to €35 million or 7% of global annual turnover (whichever is higher) for prohibited practices; up to €15 million or 3% for other high-risk violations; and up to €7.5 million or 1% for incorrect information supplied to authorities. Fines are set by national market surveillance authorities and can be levied per violation.
Do I need an EU AI Act consultant if my AI systems are only used internally?
Yes — the Act treats internal deployment as deployer activity. If an internal AI system supports decisions on employment, credit, essential services, education, or another Annex III high-risk category, Article 26 deployer obligations apply: risk assessment, human oversight, monitoring, and logging. Internal use does not exempt an organisation from the Act.
What is the difference between a provider and a deployer under the EU AI Act?
A provider builds, develops, or places an AI system on the EU market under their own name or trademark. A deployer uses an AI system in the course of their professional activity (Article 3(4)). Obligations differ — providers of high-risk systems bear the conformity-assessment burden, while deployers must verify it was done and meet their own Article 26 obligations. An enterprise can be both, for different systems.
How does the EU AI Act interact with ISO/IEC 42001 and the NIST AI RMF?
They are complementary, not substitutes. ISO 42001 is a management-system standard — the audit-ready governance structure for how the organisation runs AI. NIST AI RMF is a voluntary risk-management framework used widely in the US. The EU AI Act is binding law with specific system-level obligations for high-risk AI. A serious enterprise programme aligns with all three: ISO 42001 for governance evidence, NIST AI RMF for the risk vocabulary, EU AI Act for legal compliance.

Ready to Act?

Know where you stand under the EU AI Act

A 90-minute advisory session produces a preliminary risk classification of your AI systems and a prioritised compliance roadmap. No open-ended engagement required.

Book a Compliance Assessment