✨ Standpoint covers EU AI Act readiness free for 14 days. Start your free trial →
Standpointby AI Service Pro
Frameworks / EU AI Act
AI governance · Regulation (binding)

EU AI Act

The EU AI Act is the world's first comprehensive law governing how artificial intelligence can be built and used. If your product touches AI and reaches anyone in the European Union, it can apply to you — even if your company sits in the US. This guide gives you the plain-language version: who it covers, the four risk tiers, the deadlines, the penalties, and a practical path to get ready.

What
Regulation (EU) 2024/1689 — a risk-based law for AI systems and general-purpose AI models.
Who
Providers (you build/place an AI system on the EU market) and deployers (you use one in the EU).
How it works
obligations scale with risk — prohibited, high-risk, limited (transparency), and minimal.
Key date
Art 50 transparency duties apply from 2 August 2026; standalone high-risk (Annex III) obligations were deferred to 2 December 2027; prohibitions and general-purpose AI rules are already in force.
// What Standpoint gives you

EU AI Act checklist

A step-by-step compliance checklist by risk tier.

Free readiness assessment

Find your risk tier and obligations in minutes.

Map to other frameworks

How the EU AI Act overlaps with NIST AI RMF, ISO 42001 & SOC 2.

// What the framework covers
ProhibitedGAP
High-riskPARTIAL
Limited (transparency)DONE
MinimalGAP

Illustrative statuses. Your real assessment is generated from your answers in the app. Standpoint is a self-assessment aid, not legal advice.

// Go deeper

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is a horizontal, risk-based regulation that sets rules for placing AI systems on the EU market and for general-purpose AI (GPAI) models. Rather than regulating a single industry, it classifies AI by how much risk a given use poses to health, safety, and fundamental rights, and attaches obligations accordingly. It entered into force on 1 August 2024 and applies in phases through 2028.

Who does the EU AI Act apply to?

It applies along the AI value chain, and the two roles that matter most for a startup are: - Provider — you develop an AI system (or a GPAI model) and place it on the EU market or put it into service under your own name, whether for payment or free. - Deployer — you use an AI system under your own authority in the course of your business (for example, you deploy a third-party model in your product or internal workflow). Crucially, the Act follows the use and effect of the system, not where your company is registered. If the output of your AI system is used by people in the EU, you are likely i…

What are the EU AI Act deadlines?

The Act phases in over roughly four years. Note the 2026 change: in the Digital Omnibus (confirmed 13 May 2026) the EU deferred the standalone high-risk (Annex III) obligations from 2 August 2026 to 2 December 2027, and the embedded-product high-risk rules (Annex I) from August 2027 to August 2028. The practical takeaway: the acute 2026 milestone is the Article 50 transparency rules, not a high-risk deadline. - 1 Aug 2024 — the Act entered into force. - 2 Feb 2025 — prohibited practices banned; AI-literacy duties begin. - 2 Aug 2025 — obligations for general-purpose AI (GPAI) models, governance bodies, and penalties provisions apply. - 2 Aug 2026 — Article 50 transparency: marking/watermarking AI-generated content, and deepfake and chatbot disclosure. GPAI enforcement powers and fines commence (up to €15M / 3%); a grace period runs to 2 Dec 2026 for watermarking existing systems. - 2 Dec 2027 — standalone high-risk (Annex III) obligations — recruitment, credit scoring, education, essential services, law enforcement, migration, justice — apply to providers and deployers (deferred from 2 Aug 2026 by the Digital Omnibus). - 2 Aug 2028 — high-risk rules for AI that is a safety component of regulated products (Annex I: medical devices, machinery, vehicles) apply (deferred from 2 Aug 2027).

What are the penalties?

Enforcement is real and the fines are tiered by severity: - Up to €35M or 7% of total worldwide annual turnover (whichever is higher) for breaching the prohibited-practices rules. - Up to €15M or 3% for breaching most other obligations (including the high-risk and GPAI duties). - Up to €7.5M or 1% for supplying incorrect, incomplete, or misleading information to authorities. For startups and SMEs, caps are applied proportionately, but the direction is clear: the cheapest time to get organised is before a customer or regulator asks.

What obligations apply to high-risk AI?

If you operate a high-risk system, the core obligations a provider must meet include: a continuous risk-management system; data governance over training, validation, and test data; technical documentation and record-keeping (logging); transparency and instructions for deployers; human oversight designed into the system; appropriate accuracy, robustness, and cybersecurity; a conformity assessment and CE-style declaration before going to market; and registration in the EU database. Deployers have their own lighter duties — using the system per instructions, ensuring human oversight, and monitoring.

What about general-purpose AI (GPAI)?

If you build on top of a model like GPT or Claude, you are typically a deployer or downstream provider, while the model maker is the GPAI provider. The GPAI rules — technical documentation, a summary of training content, and a copyright policy — mostly bind the model maker. Models with "systemic risk" carry extra duties (model evaluation, risk mitigation, incident reporting, cybersecurity). You still own the obligations for your system and how you use it.

EU AI Act work counts elsewhere too

The crosswalk maps your EU AI Act evidence onto the frameworks it overlaps — so you move forward on several at once.

NIST AI RMFISO 42001ISO 27001SOC 2

Get your EU AI Act readiness score.

Free to start. No card, no demo wall. You decide what leaves your device.

Run your free check →