- Article 50 transparency obligations are now in force from 5 August 2026: chatbots must disclose they are AI, synthetic content must be labelled, deepfakes must be marked
- Annex III high-risk AI obligations were delayed to 2 December 2027 by the Digital Omnibus, giving organisations 16 additional months of preparation time
- High-risk categories include hiring, credit scoring, biometrics, critical infrastructure, education, and law enforcement
- Organisations that use AI (deployers) carry distinct legal obligations, separate from those of their AI vendors (providers)
- Fines reach up to 35 million euros or 7% of global turnover for the most serious violations
Where the enforcement timeline stands
The EU AI Act entered into force on 1 August 2024. Enforcement has rolled out in three waves. The first, in February 2025, banned a defined set of AI practices: social scoring systems operated by public authorities, real-time biometric surveillance in public spaces (with narrow exceptions), AI designed to exploit psychological vulnerabilities, and systems that scrape facial images to build recognition databases.
The second wave arrived in August 2025. Providers of general-purpose AI models such as OpenAI's GPT-4, Anthropic's Claude, and Google's Gemini became subject to new transparency and copyright compliance requirements. Those obligations fall on the model developers, not on the businesses that access those models via API.
The third wave took effect on 5 August 2026, splitting into two parts. Article 50 transparency obligations applied on schedule: any AI system that interacts with people must disclose it is AI, synthetic content must carry machine-readable labelling, and deepfakes require explicit marking. The European AI Office gained its full penalty enforcement powers over GPAI providers on the same date.
Annex III high-risk AI obligations moved on a different track. In June 2026, the EU passed the Digital Omnibus on AI, shifting the high-risk standalone system compliance deadline from August 2026 to 2 December 2027. High-risk AI embedded in Annex I regulated products moved from August 2027 to August 2028. The harmonised technical standards required to operationalise compliance were not finalised in time.
Is your AI use high-risk? What Annex III covers
Annex III of the EU AI Act lists eight categories of high-risk AI use. The list is broader than most organisations expect. You do not need to build machine learning models to fall under it. A third-party tool that automates or materially influences a decision in any of these categories brings you in scope as a deployer.
The eight categories are:
- Biometric identification and categorisation of natural persons, including remote identification systems and emotion recognition tools
- Critical infrastructure management, including AI used in electricity, water, gas, transport, and digital infrastructure operations
- Education and vocational training, including AI that determines access to educational institutions or assesses students (automated exam scoring, admission ranking)
- Employment, worker management, and access to self-employment, including CV screening, recruitment ranking, performance monitoring, and promotion or dismissal decisions supported by AI
- Essential private services, including AI used in credit scoring, insurance risk assessment, life and health insurance underwriting
- Law enforcement, including AI used for risk assessment of individuals, profiling, evidence evaluation, and crime analytics
- Migration, asylum, and border control management, including risk assessment of visa applicants and detection of document authenticity
- Administration of justice and democratic processes, including AI that assists courts in researching or applying the law
Employment and essential services catch more commercial organisations than any other category. If your HR platform ranks job applicants, your CRM scores customers for credit risk, or your performance management software assigns productivity ratings to workers, you are operating a high-risk AI system under Annex III.
The Act targets organisations that use AI to make consequential decisions about people. Most affected organisations are buyers of third-party tools, not AI developers.
What high-risk AI systems must have in place by December 2027
High-risk AI systems must operate within a documented, auditable framework. The Act specifies eight mandatory requirements.
Providers, meaning organisations that develop and market the systems, bear primary responsibility for building those requirements in. Deployers must operate within the constraints providers establish and meet their own obligations around deployment and monitoring.
The eight technical and governance requirements are:
- Risk management system. A continuous, documented process for identifying and mitigating risks across the AI system's lifecycle. Providers must maintain and update it as the system evolves, not treat it as a one-time exercise.
- Data governance. Documentation of the training, validation, and testing data used to build the system. The data must be relevant, representative, and free from errors that could produce discriminatory outputs.
- Technical documentation. A detailed technical file describing the system's design, development, and capabilities. National supervisory authorities can request this file at any time.
- Automatic logging. The system must generate audit logs recording each decision or output, so regulators and deployers can reconstruct how specific outcomes were reached.
- Transparency and information to deployers. Providers must give deployers documentation that enables them to understand the system, use it correctly, and meet their own obligations under the Act.
- Human oversight. High-risk AI systems must allow human review and override. A person must be able to intervene, correct, or halt the system. Fully automated decisions without human oversight are non-compliant across most high-risk categories.
- Accuracy, robustness, and cybersecurity. Systems must meet defined accuracy thresholds, resist adversarial attempts to manipulate outputs, and protect the data they process.
- EU declaration of conformity and CE marking equivalent. Providers must issue a formal declaration that the system meets Act requirements and register it in the EU AI database before deployment.
The EU database for high-risk AI systems is a public registry. Providers must register a system before deploying it in the EU. Ask your vendors to confirm registration and supply valid conformity declarations before December 2027.
Your duties as a deployer versus what your AI vendor must handle
The Act draws a clear line between providers and deployers. Understanding where that line sits prevents both duplicated effort and gaps in your compliance position.
Providers are responsible for: building risk management and data governance into the system, creating and maintaining technical documentation, ensuring the system logs its decisions, issuing the EU declaration of conformity, registering the system in the EU AI database, and giving deployers clear instructions for use.
Deployers are responsible for: using the system according to the provider's instructions and the Act's requirements, conducting a risk assessment for their specific deployment context, implementing the human oversight measures the provider specifies, telling employees when AI monitors or assesses their performance, carrying out fundamental rights impact assessments where relevant, and keeping records of system use for at least 10 years.
Many AI tools were not built with EU AI Act compliance in mind. If your vendor cannot supply a valid EU declaration of conformity and complete technical documentation, press them now. Organisations that find gaps early have time to fix them; those that wait until mid-2027 will not.
Do not assume your AI vendor is handling compliance. Many vendors, including those outside the EU, have not started their conformity process. Ask for evidence now. "We are working on it" is not a defensible position once enforcement begins.
The fine structure
The EU AI Act uses the same tiered penalty model as GDPR: fines are the higher of a fixed euro amount or a percentage of global annual turnover. Executives who authorise non-compliant deployments face personal accountability alongside corporate penalties.
- Prohibited AI violations (Article 5): up to 35 million euros or 7% of global annual turnover, whichever is higher
- High-risk AI non-compliance (Annex III obligations not met): up to 15 million euros or 3% of global annual turnover, whichever is higher
- Incorrect information to authorities: up to 7.5 million euros or 1.5% of global annual turnover, whichever is higher
For a company with one billion euros in global revenue, a high-risk compliance failure carries a maximum fine of 30 million euros. National supervisory authorities in each EU member state enforce the Act. GDPR precedent suggests the largest fines will target systematic failures and cases where individuals were harmed, but early enforcement decisions will set the tone.
Building your AI compliance foundation
With December 2027 as the Annex III deadline, organisations have time to build a proper compliance programme. The Digital Omnibus delay is not a reason to defer the work. Harmonised standards are now emerging and the December 2027 date is firm. Organisations starting now can inventory, classify, engage vendors, and document oversight without the pressure that comes with a looming deadline.
Week 1: Build your AI inventory
Ask every business unit the same question: what software do you use that makes or recommends decisions about people? Include HR platforms, recruitment tools, CRM systems with lead or credit scoring, workforce management software, fraud detection tools, and customer service routing systems. For each tool, record the vendor, the use case, and which Annex III category it falls under.
Week 2: Classify and prioritise
For each AI system in your inventory, determine whether it meets the Annex III definition of high-risk. A chatbot that routes customer queries does not qualify. A system that ranks job applicants or scores customers for loan eligibility does. Prioritise high-risk systems for immediate action. Bring in your legal or compliance team to confirm classifications where doubt remains.
Week 3: Engage vendors and review documentation
Contact each vendor of a high-risk AI system and request three documents: the EU declaration of conformity, the technical documentation package for deployers, and confirmation that the system is registered in the EU AI database. Log every vendor communication in writing. If a vendor cannot produce these documents, escalate internally and decide whether continued use of that tool fits your risk appetite.
Week 4: Document human oversight and start logging decisions
For each high-risk AI system in use, write down the human oversight process: who reviews AI outputs, how they can override the system, and how those override decisions get recorded. Tell affected employees in writing where any system monitors or evaluates their performance. Start logging AI-assisted decisions in a retrievable format. Assign a named owner for each system's ongoing compliance.
Where to focus now
The December 2027 deadline is firm and the obligations are not optional. The Digital Omnibus delay reflected unfinished technical standards, not a softening of requirements. Compliance means operating AI tools with documentation, oversight, and accountability, not abandoning them.
Inaction carries two distinct risks. Regulators can fine your organisation once enforcement begins. If an AI-supported decision harms an individual and you cannot demonstrate appropriate safeguards, you face civil liability on top of regulatory penalties.
December 2027 gives most organisations time to build a mature programme. Start with the foundation: an AI inventory classified against Annex III, vendor conformity documentation confirmed, human oversight procedures written down, and key decisions logged. That foundation supports good governance regardless of when authorities act.
- Complete an AI inventory across all business functions
- Classify each AI use against Annex III and confirm scope with legal or compliance counsel
- Request EU conformity documentation from every vendor of a high-risk AI system in writing
- Document human oversight procedures for every high-risk AI tool currently in use
- Notify employees in writing where AI systems assess or monitor their performance
- Begin logging AI-assisted decisions with sufficient detail to reconstruct the basis for each outcome
- Ensure all customer-facing chatbots disclose they are AI and all AI-generated content carries labelling; Article 50 is enforceable now
- Assign a named owner for each high-risk AI system and schedule a review date for ongoing compliance
How Cyvra helps with EU AI Act compliance
Cyvra works with deployers to identify which AI systems fall under Annex III, build the documentation those systems require, and establish the human oversight processes the regulation demands. Our focus is your obligations as a user of AI, separate from what your vendors owe.
- AI system inventory: catalogue every AI tool in use across your organisation, including embedded AI features in software your IT team approved for other purposes
- Annex III classification: assess each system against the eight high-risk categories and document the reasoning in a format regulators can audit
- Vendor documentation review: confirm your AI providers have supplied the required technical documentation and conformity declarations, and identify where they have not
- Human oversight design: build the processes and controls that high-risk AI deployments must have in place before December 2027
- ISO 42001 alignment: map your AI Act compliance work to the ISO 42001 AI management system standard, producing a single audit-ready framework rather than two parallel compliance exercises
Talk to our AI practice or compliance team about what Article 50 requires now and how to prepare for the December 2027 Annex III deadline.