EU AI Act compliance,
built into the platform.

Who it applies to

The Act uses four roles. Most organisations will be deployers — using AI systems built by others. Some will also be providers if they fine-tune, adapt, or build their own models.

  • Provider — develops or places an AI system on the market, or puts it into service
  • Deployer — uses an AI system under its authority for professional purposes
  • Importer — places an AI system from a third country on the EU market
  • Distributor — makes an AI system available on the market without modifying it

Endaxi AIG supports organisations acting in any of these roles, with AIMS scope declarations and governance controls tailored to each.

Geographic scope

The Act applies where:

  • The provider or deployer is established in the EU
  • The AI system’s output is used in the EU — regardless of where the provider is based
  • The AI system affects persons located in the EU

UK organisations are not subject to the EU AI Act by virtue of UK law alone, but any UK organisation whose AI systems affect EU persons – customers, employees, users – falls within scope. Most UK commercial organisations do.

The Act is not a future problem. Enforcement is already underway.

The EU AI Act is being phased in over four years. Several obligations are already in force.

Act enters into force

The regulation becomes binding EU law. The 24-month implementation clock starts.

Prohibited practices — Art. 5 IN FORCE

Absolute prohibitions on subliminal manipulation, social scoring, real-time biometric identification in public spaces, and five other practices are immediately enforceable. Updated by Omnibus to include Art. 5(1)(ga) — generation of non-consensual intimate imagery.

GPAI obligations — Arts. 51–56 IN FORCE

General Purpose AI model providers must comply with transparency, copyright policy, and (for systemic risk models) safety and adversarial testing obligations.

Transparency obligations — Art. 50

Chatbots must disclose they are AI. Deepfake and synthetic content must be labelled. (Art. 50(2) watermarking deferred to 2 December 2026 by Omnibus.)

AI watermarking — Art. 50(2) COMING

Providers of AI-generated content must implement machine-readable watermarking. Deferred from August 2026 by the Omnibus amendments.

High-risk AI (Annex III) — Art. 6 COMING

The core high-risk obligations — risk management, technical documentation, conformity assessment, registration — apply to stand-alone high-risk AI systems. Deadline extended from August 2026 by the Omnibus amendments. This is the window to build your governance programme.

High-risk AI embedded in regulated products — Annex I COMING

AI embedded in products covered by existing EU product safety regulation (medical devices, machinery, vehicles, etc.) must comply with high-risk obligations.

The Omnibus deadline extension to December 2027 is not a reason to wait — it is a window to build a governance programme properly, before the scramble. Organisations with a system of record in place by 2027 will be in a fundamentally stronger position than those who start then.

Four risk tiers. Different obligations for each.

The EU AI Act classifies AI systems into four tiers based on the risk they pose. Your obligations depend entirely on which tier each of your systems falls into. Getting the classification right — and documenting the rationale — is where it starts.

Absolute ban — 8 practices

AI systems that cross fundamental rights red lines are banned entirely. Endaxi AIG screens every system for all eight prohibited practices:

  • Subliminal or manipulative techniques
  • Exploitation of vulnerabilities (age, disability)
  • Social scoring by public authorities
  • Real-time biometric identification in public spaces
  • Retrospective biometric categorisation
  • Emotion recognition in workplace / education
  • Biometric categorisation inferring sensitive attributes
  • Non-consensual intimate imagery generation — Art. 5(1)(ga) (Omnibus 2026)

Full compliance programme required

AI systems in eight sensitive areas carry the most extensive obligations. Endaxi AIG checks all eight Annex III categories:

  • Biometrics and biometric categorisation
  • Critical infrastructure management
  • Education and vocational training
  • Employment, recruitment, and HR decisions
  • Essential private and public services
  • Law enforcement and border control
  • Migration and asylum
  • Administration of justice and democratic processes

Transparency obligations

AI systems that interact directly with people, or generate synthetic content, must be transparent about what they are. The most common examples:

  • Chatbots — must disclose they are AI
  • Deepfake image, audio, or video — must be labelled
  • Synthetic text for public information purposes
  • AI-generated content — machine-readable watermarking (from December 2026)

No mandatory obligations — good practice recommended

The majority of AI systems — spam filters, recommendation engines, AI-assisted productivity tools — fall into this category. No mandatory compliance obligations apply, but registration and basic governance is strongly recommended for audit readiness and internal accountability.

Endaxi AIG’s Tier 1 governance model is designed precisely for Minimal Risk systems — proportionate, lightweight, and audit-ready.

Every EU AI Act obligation. All mapped in Endaxi AIG.

For high-risk AI systems, the Act imposes seventeen distinct obligations. Endaxi AIG implements a dedicated module or workflow for each one.

ArticleObligationAIGHow AIG addresses it
Art. 5Prohibited practices — 8 checksClassification wizard screens all 8 prohibited practices including Omnibus Art. 5(1)(ga)
Art. 6, Annex IIIHigh-risk classification — 8 categoriesGuided classification wizard with deterministic tier assignment and Legal Classification Certificate
Art. 9Risk management systemPre-seeded risk taxonomy, 5×5 matrix, treatment plans, residual scoring, ASIA assessment
Art. 10Data governanceData sensitivity flags (personal, special category), bias detection safeguards in SoA (A.4.3)
Art. 11, Annex IVTechnical documentation — 15 sectionsStructured Annex IV pack with versioned approval workflow and one-click plain-text export
Art. 12Record-keeping and loggingAppend-only audit log — every governance action, user identity, IP, timestamp, old/new values
Art. 13Transparency and information provisionSoA control A.6.5; transparency obligation screening in classification wizard
Art. 14Human oversightDecision influence scoring; Human Review Checkpoint control; mandatory sign-off evidence for High influence
Art. 15Accuracy, robustness, cybersecurityAnnex IV sections 5–7; adversarial testing log; prompt injection controls; model drift monitoring
Art. 16Provider obligationsAI system register with full lifecycle; assessment engine; technical documentation pack
Art. 17Roles and responsibilitiesNamed Business Owner, Technical Owner, Executive Sponsor; RBAC with four platform roles
Art. 25Information-sharing obligations (Omnibus)Known failure case register; adversarial test results; SoA A.6.1.4 mapped to Art. 25
Art. 26Deployer obligationsAssessment engine; FRIA; human oversight controls; vendor DPA and audit rights tracking
Art. 27Fundamental Rights Impact AssessmentFull FRIA module — all EU Charter rights, mitigation measures, authority notification tracking
Art. 50Transparency obligations (chatbots, deepfakes, synthetic content)Classification wizard identifies all Art. 50 obligations; disclosure requirements recorded per system
Art. 51+GPAI model obligations and systemic riskGPAI classification including 10²³ FLOP systemic risk threshold assessment
Art. 72Post-market monitoringMonitoring plans with KPI tracking, frequency scheduling, status lifecycle, and review owner
Art. 73Serious incident reportingIncident reporting workflow — authority selection, 15-day preliminary report tracking, authority reference number

The EU AI Act assigns different obligations depending on your role in the AI supply chain. Endaxi AIG supports all four roles, and the AIMS Scope module requires you to declare which apply to your organisation.

Provider

You build or place AI systems on the market

Providers carry the heaviest obligations — full technical documentation, conformity assessment, CE marking (for EU market), and post-market monitoring. This includes organisations that fine-tune or significantly adapt a third-party model.

  • Annex IV technical documentation (15 sections)
  • Conformity assessment before market placement
  • Post-market monitoring plan (Art. 72)
  • Serious incident reporting (Art. 73)
  • Registration in the EU AI database (for Annex III systems)
  • Information-sharing with downstream deployers (Art. 25)

Deployer

You use AI systems built by others

Deployers — the largest category, covering most UK and Irish organisations — must ensure the systems they deploy are used in accordance with the provider’s instructions, implement appropriate human oversight, and conduct a Fundamental Rights Impact Assessment where required.

  • Fundamental Rights Impact Assessment — FRIA (Art. 27)
  • Human oversight measures (Art. 26)
  • Vendor DPA and AI-specific contractual terms (Art. 25)
  • Input data governance for high-risk systems
  • Serious incident reporting to provider and authority (Art. 73)
  • Transparency to affected persons (Art. 26(6))

EU AI Act — questions we hear most.

We’re a UK company. Does the EU AI Act apply to us?

Possibly — and for most UK organisations that deal with EU customers, employees, or users, the answer is yes. The Act applies wherever an AI system’s output affects persons located in the EU, regardless of where the provider or deployer is based. A UK company providing an AI-assisted service to EU customers falls within scope. The UK government has not enacted equivalent domestic legislation, but the EU Act’s extraterritorial reach means UK organisations with any EU-facing activity need to assess their position.

The Omnibus pushed the high-risk deadline to 2027. Does that mean we can wait?

No, for two reasons. First, several obligations are already in force — prohibited practice screening (February 2025), GPAI obligations (August 2025), and transparency obligations (August 2026). Second, the December 2027 deadline for Annex III systems means your governance programme needs to be operational before then, not starting then. Organisations that begin classification, documentation, and risk management now will be demonstrably ahead of those who wait — which matters both for regulatory posture and for ISO 42001 certification timelines.

We only use third-party AI tools — Microsoft Copilot, ChatGPT, etc. Are we still a deployer?

Yes. Using AI tools built by others in a professional context makes you a deployer under the Act. Your obligations as a deployer include assessing whether any of those tools qualify as high-risk for your specific use case, implementing appropriate human oversight, ensuring vendor DPAs and AI-specific contractual terms are in place, and conducting a FRIA if you deploy a high-risk system. The classification of a tool depends on how you use it, not just what it is — the same AI system can be high-risk in one deployment and minimal risk in another.

What is a Fundamental Rights Impact Assessment and who needs to do one?

The FRIA (Art. 27) is a structured assessment of the impact a high-risk AI system may have on the fundamental rights of people it affects — covering rights such as privacy, non-discrimination, freedom of expression, and the right to a fair trial. It is mandatory for deployers of high-risk AI systems that are bodies governed by public law, or private bodies delivering services to the public in key areas (employment, education, essential services). Endaxi AIG includes a full FRIA module covering all relevant EU Charter rights, with mitigation measures and authority notification tracking.

What does Annex IV technical documentation look like?

Annex IV sets out a 15-section structure that providers of high-risk AI systems must maintain. It covers the system’s general description and intended purpose, architectural and design choices, training data and methodology, human oversight measures, performance metrics, validation and testing records, cybersecurity measures, instructions for use, and post-market monitoring plan summary. Endaxi AIG implements all 15 sections with a versioned approval workflow (Draft → Under Review → Approved → Archived) and generates a one-click plain-text export formatted for regulatory submission.

How does Endaxi AIG handle classification — do we need expert input?

The classification wizard in Endaxi AIG is designed to be used by a compliance professional without requiring deep technical AI expertise. It asks structured questions about each system’s purpose, use case, and characteristics, and applies the Act’s precedence logic (Prohibited > GPAI > High-Risk > Limited Risk > Minimal Risk) deterministically. The output is a Legal Classification Certificate with the classification, full rationale, assessor identity, and timestamp — audit-ready from the moment it is generated. Where a system sits close to a boundary, the wizard flags this for human review before finalising.

Start your EU AI Act compliance programme today.