Timeline (Digital Omnibus, 2 December 2027), risk classification, high-risk and GPAI obligations, D7™ scoring and compliance checklist. The reference guide for European AI compliance.
Last updated: 6 June 2026 · Reflects Digital Omnibus political agreement (7 May 2026)
The EU AI Act (Regulation (EU) 2024/1689) is the world's first binding regulatory framework specifically governing artificial intelligence. Adopted on 13 June 2024 and published in the Official Journal on 12 July 2024, it entered into force on 2 August 2024.
It applies to any provider, deployer, importer or distributor of AI systems operating in the EU market — regardless of where they are established. A US company selling an AI recruitment tool to European companies is fully subject to the Act (Art. 2).
The Digital Omnibus update (7 May 2026): A political agreement between the Council and Parliament extended the application deadline for high-risk Annex III systems from 2 August 2026 to 2 December 2027. Formal adoption is pending. Prohibited practices (Art. 5) and GPAI obligations (Art. 51–55) remain unchanged and fully in force.
| Date | Regime | Legal basis |
|---|---|---|
| 2 August 2024 | Entry into force | Art. 113 — 20 days after OJEU publication (12 July 2024) |
| 2 February 2025 | Prohibited practices (Art. 5) + Chapter I | Art. 113§a — 6 months after entry into force |
| 2 August 2025 | GPAI models (Chapter V) + Governance | Art. 113§b — 12 months after entry into force |
| 2 December 2027 | High-risk systems (Annex III) | Digital Omnibus political agreement, 7 May 2026 |
| 2 August 2028 | AI systems embedded in regulated products (Annex I) | Digital Omnibus — 36 months from EIF |
| Tier | Examples | Obligation |
|---|---|---|
| Unacceptable risk | Real-time biometric surveillance, social scoring, subliminal manipulation, emotion recognition at work | Prohibited — immediate ban (Art. 5) |
| High risk | CV screening, credit scoring, medical diagnostics, critical infrastructure, law enforcement AI | Full compliance regime (Art. 9–15) |
| Limited risk | Chatbots, AI-generated content, emotion recognition systems | Transparency obligations only (Art. 50) |
| Minimal risk | Spam filters, recommendation engines, image editing tools | No specific obligation |
A system is high-risk under Art. 6§2 if it falls within one of the eight sectors listed in Annex III:
Key principle: Classification attaches to the use case, not the model. A general-purpose LLM is not high-risk in itself. Deployed for CV screening, it becomes high-risk under Annex III §4.
| Article | Obligation | What it means in practice |
|---|---|---|
| Art. 9 | Risk management system | Documented QMS, continuous, covering the full AI lifecycle |
| Art. 10 | Data governance | Training data documented, biases identified, quality controls in place |
| Art. 11 + Annex IV | Technical documentation | Detailed technical file (architecture, data, performance, testing) |
| Art. 12 | Record-keeping | Automatic logs for decisions and operations of the system |
| Art. 13 | Transparency | Deployers must receive adequate information on capabilities and limits |
| Art. 14 | Human oversight | Human operators must be able to understand, monitor and override outputs |
| Art. 15 | Accuracy, robustness, cybersecurity | Performance standards maintained; resilience against adversarial attacks |
General-Purpose AI models (GPAI) — foundation models used for multiple purposes — have specific obligations regardless of how they are deployed:
Systemic risk threshold: 10²⁵ FLOPs of training compute (or designation by the AI Office). Above this threshold, additional obligations apply: adversarial testing, incident reporting to the AI Office, and enhanced cybersecurity measures (Art. 55).
| Violation | Maximum fine |
|---|---|
| Prohibited practice (Art. 5) | €35M or 7% of global annual turnover |
| Non-compliant high-risk system | €15M or 3% of global annual turnover |
| Non-compliant GPAI model | €15M or 3% of global annual turnover |
| Inaccurate information to authorities | €7.5M or 1.5% of global annual turnover |
Regulatory risk under the AI Act attaches to the asset, not the transaction. It persists after closing. An acquirer who purchases a company with a non-compliant high-risk AI system inherits the compliance obligation — and potential enforcement exposure.
On a €50M acquisition, a regulatory haircut of 10–15% represents €5–7.5M of lost value. A D7™ pre-signing score costs less than 0.03% of that exposure.
W&I insurance implication: W&I insurers (AXA XL, Howden, Tokio Marine) are increasingly requiring AI Act compliance documentation for transactions involving AI-significant targets. The D7™ W&I Insurability Mapping™ is designed as the first-pass document for underwriters.
Yes. Art. 2 provides for extraterritorial application: any provider or deployer that markets an AI system to users in the EU is subject to the regulation, regardless of where they are established. A US startup selling an AI hiring tool to European companies is fully subject to the Act.
Yes, with some accommodations. SMEs benefit from regulatory sandboxes (Art. 57) and lighter documentation obligations. But if their system is high-risk or prohibited, the obligations apply in full. A startup developing an AI recruitment tool is subject to Annex III §4 from launch.
Providers (those who develop and place AI systems on the market) carry the primary compliance obligations under Art. 16: they must produce the technical file, register the system, affix the CE marking. Deployers (those who use a provider's system in their operations) have obligations under Art. 26: ensuring the system is used as intended, reporting serious incidents, and maintaining human oversight. Both are subject to enforcement.
The CNIL (Commission Nationale de l'Informatique et des Libertés) is designated as the national competent authority for AI Act enforcement in France. The AI Office (European Commission, DG CNECT) has authority over GPAI model providers at EU level.
The D7™ is a proprietary compliance and value score (0–100) produced by MB AI Value Intelligence. It assesses an AI asset across 7 dimensions: regulatory exposure, technical maturity, data governance, AI governance, commercial defensibility, financial value adjustability, and operational risk. Produced in 48 hours from public data (or 5–10 days with client dataroom). Used for M&A due diligence, W&I underwriting, and PE/VC portfolio monitoring. Pricing on request.
Classification · Regulatory exposure · Remediation plan · W&I insurability mapping
Pricing on request. Audit-grade. Defensible before a regulator or an investor.