EU AI Act compliance: deadlines, penalties, and the evidence regulators expect.
“We’re not in Europe” is the most expensive assumption in AI right now. If your AI outputs reach EU users, the Act reaches you — and the high-risk obligations land on August 2, 2026.
Does the EU AI Act apply to you?
The Act is extraterritorial by design. It applies to providers placing AI systems on the EU market, to deployers established in the EU — and, critically, to providers and deployers outside the EU when the output of their AI system is used in the Union. A North American SaaS product with EU customers, a bank whose models score EU residents, a manufacturer whose AI-assisted product ships to Europe: all in scope.
The question is not whether you have an EU office. It is whether any AI system you run produces output that touches EU users — and whether you could prove, with records, how that system behaves.
The enforcement timeline
| Date | What becomes enforceable |
|---|---|
| February 2, 2025 | Prohibited practices banned (social scoring, manipulative systems, most real-time biometric ID); AI literacy obligations begin. |
| August 2, 2025 | Obligations for general-purpose AI models; governance structures live; penalties become applicable. |
| August 2, 2026 | The big one: high-risk system obligations (Annex III) and transparency requirements apply — risk management, data governance, logging, human oversight, post-market monitoring, all with documented evidence. |
| August 2, 2027 | High-risk AI embedded in regulated products; deadline for legacy general-purpose models. |
What non-compliance costs
| Violation | Maximum penalty |
|---|---|
| Prohibited AI practices (Article 5) | €35M or 7% of global annual turnover — whichever is higher |
| Most other obligations (incl. high-risk requirements) | €15M or 3% — whichever is higher |
| Supplying incorrect or misleading information to authorities | €7.5M or 1% — whichever is higher |
Article 99 penalties apply when contemporaneous evidence is absent — not only when systems fail. A policy document written after the letter arrives is not evidence. Records generated while the system runs are.
What compliance actually requires
Strip away the legal prose and the Act asks six operational questions. Regulators on three continents are converging on the same list:
- Inventory: Do you know every AI system you run, and its risk classification?
- Governance: Is there a named owner, a risk-management system, and documented data governance for each?
- Logging & records: Does each high-risk system keep automatic logs a regulator could inspect?
- Human oversight: Can a person understand, intervene in, and override the system — provably?
- Independent validation: Has anyone outside the build team tested the system’s claims? (This is where AI security testing and conformity overlap.)
- A kill switch: Can you stop the system — and show that you can?
Notice what all six have in common: they are answered with evidence, not intentions. That is HANDVANTAGE’s entire thesis — policies don’t pass audits; evidence does.
How HANDVANTAGE gets you there
Start: know your exposure (free, 15 minutes)
The EU AI Act exposure check classifies every AI system you run, gives you your risk tier, your binding deadline, and your maximum penalty exposure in dollars — then a personalised action plan. No lawyer required.
Then: stand up the six controls with evidence
We implement governance, logging, oversight and validation mapped simultaneously to the EU AI Act, ISO 42001, NIST AI RMF and SOC 2 — one audit trail, eleven frameworks, continuously maintained. The ISO 42001 gap assessment shows how far you are from the world’s first certifiable AI management standard.
Architecture, when it is the answer
For agentic AI, the cleanest path to compliant logging and oversight is running AI inside your own boundary: Vantage Workspace signs every AI action to a named person and ships with the assessment module’s EU AI Act template active. For what agent-specific risk looks like, read the agentic AI security guide.
Frequently asked questions
Does the EU AI Act apply to companies outside the EU?
What deadline matters in 2026?
What counts as a high-risk AI system?
What are the maximum fines?
What evidence do regulators actually expect?
Where do I start with EU AI Act compliance?
Fifteen minutes to know your exposure.
Your risk tier, your binding deadline, your penalty exposure in dollars — and a plan. Free, no lawyer required.
