Regulation (EU) 2024/1689 — incl. Omnibus 2026
EU AI Act compliance,
built into the platform.
The EU AI Act is the world’s first comprehensive legal framework for artificial intelligence. If your organisation deploys, develops, or uses AI systems that affect people in the EU or UK, it applies to you — and enforcement has already begun.
The Regulation
What the EU AI Act actually requires.
The EU AI Act (Regulation 2024/1689) came into force on 1 August 2024. It creates a tiered system of obligations based on the risk level of each AI system. The Act applies to providers, deployers, importers, and distributors of AI systems — any organisation that builds, buys, or uses AI in a way that affects people in the EU or UK.
Who it applies to
The Act uses four roles. Most organisations will be deployers — using AI systems built by others. Some will also be providers if they fine-tune, adapt, or build their own models.
- Provider — develops or places an AI system on the market, or puts it into service
- Deployer — uses an AI system under its authority for professional purposes
- Importer — places an AI system from a third country on the EU market
- Distributor — makes an AI system available on the market without modifying it
Endaxi AIG supports organisations acting in any of these roles, with AIMS scope declarations and governance controls tailored to each.
Geographic scope
The Act applies where:
- The provider or deployer is established in the EU
- The AI system’s output is used in the EU — regardless of where the provider is based
- The AI system affects persons located in the EU
UK organisations are not subject to the EU AI Act by virtue of UK law alone, but any UK organisation whose AI systems affect EU persons – customers, employees, users – falls within scope. Most UK commercial organisations do.
Enforcement Timeline
The Act is not a future problem. Enforcement is already underway.
The EU AI Act is being phased in over four years. Several obligations are already in force.
1 August 2024
Act enters into force
The regulation becomes binding EU law. The 24-month implementation clock starts.
2 February 2025
Prohibited practices — Art. 5 IN FORCE
Absolute prohibitions on subliminal manipulation, social scoring, real-time biometric identification in public spaces, and five other practices are immediately enforceable. Updated by Omnibus to include Art. 5(1)(ga) — generation of non-consensual intimate imagery.
2 August 2025
GPAI obligations — Arts. 51–56 IN FORCE
General Purpose AI model providers must comply with transparency, copyright policy, and (for systemic risk models) safety and adversarial testing obligations.
2 August 2026 NOW
Transparency obligations — Art. 50
Chatbots must disclose they are AI. Deepfake and synthetic content must be labelled. (Art. 50(2) watermarking deferred to 2 December 2026 by Omnibus.)
2 December 2026
AI watermarking — Art. 50(2) COMING
Providers of AI-generated content must implement machine-readable watermarking. Deferred from August 2026 by the Omnibus amendments.
2 December 2027
High-risk AI (Annex III) — Art. 6 COMING
The core high-risk obligations — risk management, technical documentation, conformity assessment, registration — apply to stand-alone high-risk AI systems. Deadline extended from August 2026 by the Omnibus amendments. This is the window to build your governance programme.
2 August 2028
High-risk AI embedded in regulated products — Annex I COMING
AI embedded in products covered by existing EU product safety regulation (medical devices, machinery, vehicles, etc.) must comply with high-risk obligations.
The Omnibus deadline extension to December 2027 is not a reason to wait — it is a window to build a governance programme properly, before the scramble. Organisations with a system of record in place by 2027 will be in a fundamentally stronger position than those who start then.
Risk Classification
Four risk tiers. Different obligations for each.
The EU AI Act classifies AI systems into four tiers based on the risk they pose. Your obligations depend entirely on which tier each of your systems falls into. Getting the classification right — and documenting the rationale — is where it starts.
Prohibited — Art. 5
Absolute ban — 8 practices
AI systems that cross fundamental rights red lines are banned entirely. Endaxi AIG screens every system for all eight prohibited practices:
- Subliminal or manipulative techniques
- Exploitation of vulnerabilities (age, disability)
- Social scoring by public authorities
- Real-time biometric identification in public spaces
- Retrospective biometric categorisation
- Emotion recognition in workplace / education
- Biometric categorisation inferring sensitive attributes
- Non-consensual intimate imagery generation — Art. 5(1)(ga) (Omnibus 2026)
High-Risk — Art. 6, Annex III
Full compliance programme required
AI systems in eight sensitive areas carry the most extensive obligations. Endaxi AIG checks all eight Annex III categories:
- Biometrics and biometric categorisation
- Critical infrastructure management
- Education and vocational training
- Employment, recruitment, and HR decisions
- Essential private and public services
- Law enforcement and border control
- Migration and asylum
- Administration of justice and democratic processes
Limited Risk — Art. 50
Transparency obligations
AI systems that interact directly with people, or generate synthetic content, must be transparent about what they are. The most common examples:
- Chatbots — must disclose they are AI
- Deepfake image, audio, or video — must be labelled
- Synthetic text for public information purposes
- AI-generated content — machine-readable watermarking (from December 2026)
Minimal Risk
No mandatory obligations — good practice recommended
The majority of AI systems — spam filters, recommendation engines, AI-assisted productivity tools — fall into this category. No mandatory compliance obligations apply, but registration and basic governance is strongly recommended for audit readiness and internal accountability.
Endaxi AIG’s Tier 1 governance model is designed precisely for Minimal Risk systems — proportionate, lightweight, and audit-ready.
Full Coverage
Every EU AI Act obligation. All mapped in Endaxi AIG.
For high-risk AI systems, the Act imposes seventeen distinct obligations. Endaxi AIG implements a dedicated module or workflow for each one.
| Article | Obligation | AIG | How AIG addresses it |
|---|---|---|---|
| Art. 5 | Prohibited practices — 8 checks | ✓ | Classification wizard screens all 8 prohibited practices including Omnibus Art. 5(1)(ga) |
| Art. 6, Annex III | High-risk classification — 8 categories | ✓ | Guided classification wizard with deterministic tier assignment and Legal Classification Certificate |
| Art. 9 | Risk management system | ✓ | Pre-seeded risk taxonomy, 5×5 matrix, treatment plans, residual scoring, ASIA assessment |
| Art. 10 | Data governance | ✓ | Data sensitivity flags (personal, special category), bias detection safeguards in SoA (A.4.3) |
| Art. 11, Annex IV | Technical documentation — 15 sections | ✓ | Structured Annex IV pack with versioned approval workflow and one-click plain-text export |
| Art. 12 | Record-keeping and logging | ✓ | Append-only audit log — every governance action, user identity, IP, timestamp, old/new values |
| Art. 13 | Transparency and information provision | ✓ | SoA control A.6.5; transparency obligation screening in classification wizard |
| Art. 14 | Human oversight | ✓ | Decision influence scoring; Human Review Checkpoint control; mandatory sign-off evidence for High influence |
| Art. 15 | Accuracy, robustness, cybersecurity | ✓ | Annex IV sections 5–7; adversarial testing log; prompt injection controls; model drift monitoring |
| Art. 16 | Provider obligations | ✓ | AI system register with full lifecycle; assessment engine; technical documentation pack |
| Art. 17 | Roles and responsibilities | ✓ | Named Business Owner, Technical Owner, Executive Sponsor; RBAC with four platform roles |
| Art. 25 | Information-sharing obligations (Omnibus) | ✓ | Known failure case register; adversarial test results; SoA A.6.1.4 mapped to Art. 25 |
| Art. 26 | Deployer obligations | ✓ | Assessment engine; FRIA; human oversight controls; vendor DPA and audit rights tracking |
| Art. 27 | Fundamental Rights Impact Assessment | ✓ | Full FRIA module — all EU Charter rights, mitigation measures, authority notification tracking |
| Art. 50 | Transparency obligations (chatbots, deepfakes, synthetic content) | ✓ | Classification wizard identifies all Art. 50 obligations; disclosure requirements recorded per system |
| Art. 51+ | GPAI model obligations and systemic risk | ✓ | GPAI classification including 10²³ FLOP systemic risk threshold assessment |
| Art. 72 | Post-market monitoring | ✓ | Monitoring plans with KPI tracking, frequency scheduling, status lifecycle, and review owner |
| Art. 73 | Serious incident reporting | ✓ | Incident reporting workflow — authority selection, 15-day preliminary report tracking, authority reference number |
Your Obligations by Role
Provider, deployer, or both — your obligations differ.
The EU AI Act assigns different obligations depending on your role in the AI supply chain. Endaxi AIG supports all four roles, and the AIMS Scope module requires you to declare which apply to your organisation.
Provider
You build or place AI systems on the market
Providers carry the heaviest obligations — full technical documentation, conformity assessment, CE marking (for EU market), and post-market monitoring. This includes organisations that fine-tune or significantly adapt a third-party model.
- Annex IV technical documentation (15 sections)
- Conformity assessment before market placement
- Post-market monitoring plan (Art. 72)
- Serious incident reporting (Art. 73)
- Registration in the EU AI database (for Annex III systems)
- Information-sharing with downstream deployers (Art. 25)
Deployer
You use AI systems built by others
Deployers — the largest category, covering most UK and Irish organisations — must ensure the systems they deploy are used in accordance with the provider’s instructions, implement appropriate human oversight, and conduct a Fundamental Rights Impact Assessment where required.
- Fundamental Rights Impact Assessment — FRIA (Art. 27)
- Human oversight measures (Art. 26)
- Vendor DPA and AI-specific contractual terms (Art. 25)
- Input data governance for high-risk systems
- Serious incident reporting to provider and authority (Art. 73)
- Transparency to affected persons (Art. 26(6))
Common Questions
EU AI Act — questions we hear most.
We’re a UK company. Does the EU AI Act apply to us?
Possibly — and for most UK organisations that deal with EU customers, employees, or users, the answer is yes. The Act applies wherever an AI system’s output affects persons located in the EU, regardless of where the provider or deployer is based. A UK company providing an AI-assisted service to EU customers falls within scope. The UK government has not enacted equivalent domestic legislation, but the EU Act’s extraterritorial reach means UK organisations with any EU-facing activity need to assess their position.
The Omnibus pushed the high-risk deadline to 2027. Does that mean we can wait?
No, for two reasons. First, several obligations are already in force — prohibited practice screening (February 2025), GPAI obligations (August 2025), and transparency obligations (August 2026). Second, the December 2027 deadline for Annex III systems means your governance programme needs to be operational before then, not starting then. Organisations that begin classification, documentation, and risk management now will be demonstrably ahead of those who wait — which matters both for regulatory posture and for ISO 42001 certification timelines.
We only use third-party AI tools — Microsoft Copilot, ChatGPT, etc. Are we still a deployer?
Yes. Using AI tools built by others in a professional context makes you a deployer under the Act. Your obligations as a deployer include assessing whether any of those tools qualify as high-risk for your specific use case, implementing appropriate human oversight, ensuring vendor DPAs and AI-specific contractual terms are in place, and conducting a FRIA if you deploy a high-risk system. The classification of a tool depends on how you use it, not just what it is — the same AI system can be high-risk in one deployment and minimal risk in another.
What is a Fundamental Rights Impact Assessment and who needs to do one?
The FRIA (Art. 27) is a structured assessment of the impact a high-risk AI system may have on the fundamental rights of people it affects — covering rights such as privacy, non-discrimination, freedom of expression, and the right to a fair trial. It is mandatory for deployers of high-risk AI systems that are bodies governed by public law, or private bodies delivering services to the public in key areas (employment, education, essential services). Endaxi AIG includes a full FRIA module covering all relevant EU Charter rights, with mitigation measures and authority notification tracking.
What does Annex IV technical documentation look like?
Annex IV sets out a 15-section structure that providers of high-risk AI systems must maintain. It covers the system’s general description and intended purpose, architectural and design choices, training data and methodology, human oversight measures, performance metrics, validation and testing records, cybersecurity measures, instructions for use, and post-market monitoring plan summary. Endaxi AIG implements all 15 sections with a versioned approval workflow (Draft → Under Review → Approved → Archived) and generates a one-click plain-text export formatted for regulatory submission.
How does Endaxi AIG handle classification — do we need expert input?
The classification wizard in Endaxi AIG is designed to be used by a compliance professional without requiring deep technical AI expertise. It asks structured questions about each system’s purpose, use case, and characteristics, and applies the Act’s precedence logic (Prohibited > GPAI > High-Risk > Limited Risk > Minimal Risk) deterministically. The output is a Legal Classification Certificate with the classification, full rationale, assessor identity, and timestamp — audit-ready from the moment it is generated. Where a system sits close to a boundary, the wizard flags this for human review before finalising.
Start your EU AI Act compliance programme today.
Endaxi AIG covers all 17 obligations, reflects the Omnibus 2026 amendments, and is ready to use from day one — no configuration required.
