Compliance guide

The EU AI Act
for enterprise AI.

A path you can actually walk: what you must do as a deployer, which deadlines apply, what an evidence trail looks like and which duties the platform takes off your desk instead of leaving them there.

Deadlines at a glance

Application deadlines of Regulation (EU) 2024/1689
What applies from that date
2 February 2025The Article 4 training duty and the Article 5 ban on prohibited practices are live.
2 August 2025Obligations for general-purpose AI models enter into force.
2 August 2026Full applicability for high-risk systems under Annex III.
2 August 2027High-risk systems under Annex I, that is, tied into product safety law.

Six steps to compliance

The path we walked in our own audits. Realistic timeframe: about four weeks.

  1. Inventory your AI

    List every AI system in use, including the ones hidden as a module inside an existing application: Copilot, ChatGPT Team, smart filters in the mailbox.

  2. Classify by risk

    Assess each system against Annex III: prohibited, high-risk, limited or minimal risk. The classification drives everything that follows.

  3. Meet the Article 4 training duty

    Train everyone with access to AI, and keep the proof. Two certified packages are ready for exactly this.

  4. Set up the evidence trail

    For every request, record who, what, which model, which data source, which outcome. In SIMOSphere AI this ships with the product.

  5. Meet transparency and notice duties

    Tell end customers when they interact with an AI system directly, and label synthetic media.

  6. Document conformity

    Per high-risk system: declaration of conformity, risk management, technical documentation and post-market monitoring.

What the platform takes off your desk

  • Evidence trail per request

    Who, what, which model, which data source, which outcome. CSV export, GDPR-compliant.

  • Risk-class tagging

    Attach an Annex III tag per workflow and flag requests that carry high risk.

  • Model cards

    EU models such as Apertus and Mistral documented with provider, knowledge cutoff and sub-processors.

  • Data residency commitment

    EU only or on your own premises. The sub-processor list is public.

  • Article 4 training packages

    Two certified trainings: AI prompting for decision makers, and working with language models under GDPR.

  • EU AI Act audit

    One day at a fixed price, quoted on request: inventory, risk classification, training proof and a prioritized action plan.

Common questions

  • Is my company a deployer under the EU AI Act?

    Yes, as soon as your company puts an AI system to work under its own responsibility in a professional context, including systems you bought, such as ChatGPT, Copilot or SIMOSphere AI. Purely private use is out of scope. Deployer status brings the Article 4 training duty, risk classification and, in some cases, transparency and documentation duties.

  • Which deadlines matter in 2026?

    Since 2 February 2025 the ban on prohibited practices and the Article 4 training duty have applied. Since 2 August 2025 the obligations for general-purpose AI models have applied. From 2 August 2026 high-risk systems under Annex III are fully covered, and from 2 August 2027 those under Annex I.

  • What counts as a high-risk system under the EU AI Act?

    Annex III names eight areas, among them biometrics, critical infrastructure, education, employment including hiring decisions and performance review, essential public and private services such as creditworthiness and insurance pricing, law enforcement and migration. AI used in recruiting frequently falls into this bracket.

  • What does an EU AI Act audit cost at SIMO?

    The audit runs for one day at a fixed price, which we quote on request. You receive a per-system risk classification, a training proof set, documentation templates and a prioritized action plan.

A note on binding force

This guide is not legal advice. It summarizes what we learned across audit projects between the fourth quarter of 2024 and the second quarter of 2026.

Only the competent national supervisory authority and the European Commission's AI Office can interpret the regulation with binding effect.

Book the audit: one day, price on request

You receive a per-system risk classification, a training proof set, documentation templates and a prioritized action plan, ready for inspection.