EU AI Act Consulting
& Compliance Advisory
High-risk AI enforcement began 2 August 2026. GPAI rules have applied since August 2025. Article 4 AI-literacy obligations have been in force since February 2025. We help enterprises classify AI systems, meet Article 26 deployer obligations, and build the audit trail regulators require.
Scope & Obligations
What the EU AI Act Requires
The Act applies to any organisation whose AI systems are used in the EU — regardless of where that organisation is based.
Prohibited AI Systems
Social scoring, real-time biometric surveillance in public spaces, and manipulative AI are banned outright. In force since February 2025.
High-Risk AI Obligations
AI in employment, credit, education, and critical infrastructure requires conformity assessments, technical documentation, and post-market monitoring. Deadline: August 2026.
GPAI Model Rules
General-purpose AI model obligations — transparency, copyright policy, evaluations, and systemic risk assessments — have applied since August 2025.
The Compliance Window Is Closing
The EU AI Act is not forthcoming legislation — it is live. Key obligations are already in force.
Aug 2024
Act Entered Into Force
The EU AI Act became law. All organisations with AI systems operating in the EU are within scope.
Feb 2025
Prohibited AI Systems Banned
Chapter II prohibitions apply. Unacceptable-risk AI systems are now illegal to operate.
Aug 2025
GPAI & Governance Obligations
General-purpose AI model obligations and governance rules for all operators are now in force.
Aug 2026
High-Risk AI (Annex III)
High-risk AI systems in areas like employment, education, and critical infrastructure must be fully compliant.
Aug 2027
High-Risk AI (Annex I)
AI systems embedded in regulated products (medical devices, machinery) must meet full compliance requirements.
Has your organisation classified its AI systems?
Book a Compliance AssessmentOur Advisory Work
How Imagine Works Supports EU AI Act Compliance
01
AI System Risk Classification
We inventory your AI systems, classify each against EU AI Act risk tiers, and identify which face prohibited, high-risk, or GPAI obligations — before regulators do.
02
Governance Framework Design
We design the governance architecture: risk management procedures, human oversight protocols, accountability structures, and the post-market monitoring system the Act requires.
03
Technical Documentation & Audit Readiness
We produce model cards, conformity documentation, data governance records, and the logging architecture that forms the audit trail for high-risk AI systems.
Frequently Asked
EU AI Act — Questions Enterprise Leaders Ask
- Who does the EU AI Act apply to?
- The Act applies to any organisation whose AI systems are used in the EU, regardless of where the organisation is based. That includes providers (who build or place AI on the EU market), deployers (who use AI in their operations in the EU), importers, distributors, and product manufacturers. A US-headquartered SaaS company with EU customers is in scope. So is an Indian services firm running AI-based decisions on EU customer data.
- What are the EU AI Act enforcement deadlines?
- Prohibited AI practices have been in force since 2 February 2025. AI literacy obligations under Article 4 also applied from 2 February 2025. General-purpose AI model rules applied from 2 August 2025. High-risk AI system obligations under Annex III began enforcement from 2 August 2026, when the wider enforcement architecture activated across national market surveillance authorities and sectoral regulators.
- What are the fines for EU AI Act non-compliance?
- Article 99 sets three tiers: up to €35 million or 7% of global annual turnover (whichever is higher) for prohibited practices; up to €15 million or 3% for other high-risk violations; and up to €7.5 million or 1% for incorrect information supplied to authorities. Fines are set by national market surveillance authorities and can be levied per violation.
- Do I need an EU AI Act consultant if my AI systems are only used internally?
- Yes — the Act treats internal deployment as deployer activity. If an internal AI system supports decisions on employment, credit, essential services, education, or another Annex III high-risk category, Article 26 deployer obligations apply: risk assessment, human oversight, monitoring, and logging. Internal use does not exempt an organisation from the Act.
- What is the difference between a provider and a deployer under the EU AI Act?
- A provider builds, develops, or places an AI system on the EU market under their own name or trademark. A deployer uses an AI system in the course of their professional activity (Article 3(4)). Obligations differ — providers of high-risk systems bear the conformity-assessment burden, while deployers must verify it was done and meet their own Article 26 obligations. An enterprise can be both, for different systems.
- How does the EU AI Act interact with ISO/IEC 42001 and the NIST AI RMF?
- They are complementary, not substitutes. ISO 42001 is a management-system standard — the audit-ready governance structure for how the organisation runs AI. NIST AI RMF is a voluntary risk-management framework used widely in the US. The EU AI Act is binding law with specific system-level obligations for high-risk AI. A serious enterprise programme aligns with all three: ISO 42001 for governance evidence, NIST AI RMF for the risk vocabulary, EU AI Act for legal compliance.
EU AI Act Insights
Further Reading
EU AI Act High-Risk Classification: A Plain-English Guide for Business Leaders
The EU AI Act is live. If your organisation deploys AI systems in the EU, some of them may already be classified as high-risk — triggering significant compliance obligations. Here's what high-risk means, how to identify it, and what it requires.
General-Purpose AI Models and the EU AI Act: What the August 2025 Obligations Mean
The EU AI Act's General-Purpose AI provisions became enforceable in August 2025. For organisations using foundation model APIs, fine-tuning GPAI models, or building products on large language models, the obligations are direct and material. Here is what changed and what it requires.
What Is an AI Model Card — and Why Every Enterprise AI System Needs One
Every AI system has a design history: what data it was trained on, what it was optimised for, where it performs well and where it does not. Almost none of this is documented in a way that the people operating or affected by the system can access. A model card changes that.
Ready to Act?
Know where you stand under the EU AI Act
A 90-minute advisory session produces a preliminary risk classification of your AI systems and a prioritised compliance roadmap. No open-ended engagement required.
Book a Compliance Assessment