AccuroAI
Products
What We Do
Solutions
Company
Resources
Book demo
EU AI Act · Regulation (EU) 2024/1689

EU AI Act compliance, with the evidence already generated.

The Act has applied in general since August 2, 2026, and the Commission can now fine general-purpose model providers. AccuroAI gives deployers the AI inventory, the logs, the human-oversight controls and the transparency evidence the Act asks for — across every assistant, agent and device.
Aug 2, 2026
General application · Commission fining powers for GPAI
€35M / 7%
Maximum fine for prohibited practices
Dec 2, 2027
Annex III high-risk obligations (post-Omnibus)
ConsoleCompliance · EU AI ActEvidence live
Requirement · referenceEvidence
Know every AI system in scopeArt. 4 · Art. 26 · Continuous AI inventory with owner, risk score and first-seen dateGenerated
Keep the logsArt. 12 · Art. 26(6) · Retained audit trail, exportable per system and per periodGenerated
Human oversight that can actually interveneArt. 14 · Art. 26(2) · Oversight log: who approved, overrode or stopped what, and whenGenerated
Transparency to people and workersArt. 50 · Art. 26(7) · Disclosure and acknowledgement records per systemGenerated
Monitor and report incidentsArt. 72 · Art. 73 · Incident timeline with affected system, data class and responseGenerated
Prove it across frameworksArt. 17-aligned QMS evidence · One evidence pack, reused across regulators and auditorsGenerated
6 requirements mapped · evidence refreshed continuously8 frameworks
Why it matters

Most enterprises are deployers — and deployers have duties now.

The Act regulates providers who build AI systems and deployers who use them. Almost every enterprise is a deployer of general-purpose AI the moment employees use ChatGPT, Copilot or Gemini at work, and a deployer of agents the moment one runs with tool access. AI literacy (Article 4) has applied since February 2025; the Commission and national authorities gained enforcement powers on August 2, 2026; and the high-risk regime lands from December 2027. The common thread across every obligation is the same: you must be able to say what AI runs in your organisation, who uses it, what it touched, and how a human could intervene.

What EU AI Act asks for

The obligations that touch security and IT.

01Art. 4

AI literacy

Providers and deployers must ensure a sufficient level of AI literacy among staff operating AI systems — which presupposes knowing which systems staff actually operate.

02Art. 26

Deployer obligations

Use high-risk systems per instructions, assign human oversight to competent people, keep automatically generated logs for at least six months, monitor operation and inform workers.

03Art. 27

Fundamental rights impact assessment

Public bodies and certain private deployers must assess the impact on fundamental rights before putting a high-risk system into use — and keep that assessment current.

04Art. 50

Transparency

People must be told when they interact with an AI system; synthetic content must be marked; deployers of emotion-recognition or deep-fake systems carry disclosure duties.

05Art. 12 · 14

Record-keeping & human oversight

High-risk systems must log events automatically and be designed so that natural persons can oversee, override or stop them — obligations deployers inherit operationally.

06Art. 72 · 73

Post-market monitoring & incidents

Serious incidents must be reported to market-surveillance authorities; monitoring must continue for the life of the system, not end at go-live.

How AccuroAI maps

Each requirement, one control, one piece of evidence.

RequirementReferenceAccuroAI controlEvidence produced
Know every AI system in scopeArt. 4 · Art. 26Shadow AI discovery and the 1,400+ app catalog — every assistant, agent, IDE plugin and MCP server, browser and endpointContinuous AI inventory with owner, risk score and first-seen date
Keep the logsArt. 12 · Art. 26(6)Every prompt, response, tool call and policy decision recorded and attributed to a user or agent identityRetained audit trail, exportable per system and per period
Human oversight that can actually interveneArt. 14 · Art. 26(2)Approval gates on destructive agent actions, session kill switch, redact/warn/block at the prompt boundaryOversight log: who approved, overrode or stopped what, and when
Transparency to people and workersArt. 50 · Art. 26(7)Per-tool disclosure banners and usage notices, policy acknowledgement trackingDisclosure and acknowledgement records per system
Monitor and report incidentsArt. 72 · Art. 73Inline inspection with 40+ classifiers; alerts on data exposure, injection and policy breachesIncident timeline with affected system, data class and response
Prove it across frameworksArt. 17-aligned QMS evidenceEvidence mapped to 8 frameworks — the EU AI Act alongside ISO 42001, NIST AI RMF, SOC 2 and GDPROne evidence pack, reused across regulators and auditors

General information about the public text of the framework, not legal advice. Mappings describe how AccuroAI controls support each obligation; scope and conformity decisions remain with your legal, compliance and certification partners.

Timeline

The dates that are settled.

As amended by the Digital Omnibus, adopted June 2026. Earlier dates have passed; the next ones are fixed in the regulation.

Aug 1, 2024Regulation enters into forceIn effect
Feb 2, 2025Prohibited practices banned · AI literacy duty appliesIn effect
Aug 2, 2025GPAI model obligations apply · national penalties (Art. 99) availableIn effect
Aug 2, 2026General application · Commission fining powers for GPAI providers (Art. 101) · Article 50 transparencyApplies now
Dec 2, 2026Art. 50(2) marking grace period ends · new prohibition on NCII/CSAM generation appliesUpcoming
Dec 2, 2027Annex III high-risk obligations (moved by the Digital Omnibus)Upcoming
Aug 2, 2028Annex I high-risk (product-safety) obligationsUpcoming
Where it runs

The products behind the evidence.

Further reading
FAQ

What teams ask about EU AI Act.

We only use ChatGPT and Copilot — does the EU AI Act apply to us?

Yes, as a deployer. The AI literacy duty (Article 4) applies to everyone operating AI systems, and the transparency rules in Article 50 apply from August 2, 2026. The heavier high-risk obligations only apply if you use AI for an Annex III purpose — recruitment, credit, education, essential services — and those land from December 2, 2027.

What changed with the Digital Omnibus?

The Omnibus — Regulation (EU) 2026/1744, in force since July 27, 2026 — moved the Annex III high-risk application date to December 2, 2027 and Annex I to August 2, 2028. It did not move the GPAI obligations, the Article 50 transparency duties, or the general application date of August 2, 2026; it also added a new prohibition on AI that generates non-consensual intimate imagery, applying from December 2, 2026.

Does AccuroAI make us compliant?

No product does. AccuroAI produces the inventory, logs, oversight controls and transparency evidence that the deployer obligations depend on, and maps that evidence to the Act's articles so your legal and compliance teams can demonstrate it. The legal assessment of scope and risk tier remains yours.

How long does it take to get the inventory the Act assumes we have?

Most organisations have a complete first inventory within the 72-hour discovery pilot: every AI tool, agent and MCP server seen in the browser and on managed endpoints, with owners and risk scores. Deployment typically takes under 30 minutes through your existing MDM and identity provider.

Is this legal advice?

No. This page summarises the public text of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the Digital Omnibus on AI), as of August 2026 and describes how AccuroAI controls support the obligations. Confirm your obligations with counsel.

See your EU AI Act evidence, live.

Book a 30-minute demo and we'll show the inventory, the logs and the oversight controls behind every mapping on this page — on your own AI estate within 72 hours.

Book a demoTalk to security