Get ready for the EU AI Act.Transparency: 2 Aug 2026 · High-risk: 2 Dec 2027.
Understand what the EU AI Act now requires after the Digital Omnibus on AI, run a free readiness assessment, and get a personalised action plan - without wading through 400 pages of regulation.
Free assessment
~15-20 minute readiness check
Revised timeline
2 Aug 2026 · 2 Dec 2027 · 2 Aug 2028
Expert guidance
Courses, consultancy, audits
AI Act classification
The 4 risk levels
The EU AI Act classifies AI systems by risk. Each level triggers different obligations and fine tiers.
Unacceptable
Prohibited AI: social scoring, manipulative or exploitative use, real-time biometric ID in public (narrow exceptions), and - new - AI nudifiers & CSAM.
High-risk
AI in HR, credit, education, essential services, biometrics, law enforcement, or embedded in regulated products. Heaviest obligations - applies 2 Dec 2027 / 2 Aug 2028.
Limited-risk
Chatbots, deepfakes, generated content, emotion recognition. Transparency & labelling obligations from 2 Aug 2026 (Art. 50).
Minimal-risk
The vast majority of AI systems: spam filters, game AI, recommenders. No specific AI Act obligations beyond horizontal rules.
Who this is for
Every role in the AI value chain is in scope
The EU AI Act assigns duties by role, not by industry. Find yours to see what applies.
Provider
You develop an AI system (or a general-purpose AI model) and place it on the EU market under your own name or trademark - including free and open-source releases that meet the definition.
Deployer
You use an AI system under your authority in a professional context - for example, HR screening, credit scoring, customer chatbots or clinical decision support. Deployers of high-risk systems carry heavy oversight duties.
Importer
You place an AI system from a non-EU provider on the EU market. You must verify the provider ran conformity assessment, drafted the technical documentation and affixed the CE marking before the system reaches EU customers.
Distributor
You make an AI system available on the EU market without being provider or importer. You must check that CE marking and required documentation are in place and act if you have reason to believe the system is non-conforming.
Compliance at a glance
What to have in place, and by when
The compliance-checklist areas mapped to the AI Act timeline - what should already be in place, and what falls due in 2026, 2027 and 2028.
| Compliance area | What to have in place | When |
|---|---|---|
| Prohibited practices (Art. 5) | Ban on social scoring, manipulative, exploitative and untargeted-biometric AI uses. | In force |
| Governance & accountability | Named AI owner, AI usage policy, risk-register entry, incident playbook, board reporting. | Do now |
| AI inventory & risk classification | Central register of every AI system with purpose, data, decision impact and classification. | Do now |
| AI literacy (Art. 4) | Baseline training for all AI users, advanced training for high-risk operators, records kept. | Do now |
| Transparency (Art. 50) | Disclose AI interactions, label AI-generated content, watermark generative output, notify on emotion or biometric categorisation. | 2 Aug 2026 |
| High-risk technical controls (Annex III) | Risk-management system, data governance, Annex IV file, logging, human oversight, post-market monitoring, incident reporting. | 2 Dec 2027 |
| High-risk technical controls (Annex I) | Same high-risk regime for AI embedded in regulated products - medical devices, machinery, vehicles, toys. | 2 Aug 2028 |
Ban on social scoring, manipulative, exploitative and untargeted-biometric AI uses.
Named AI owner, AI usage policy, risk-register entry, incident playbook, board reporting.
Central register of every AI system with purpose, data, decision impact and classification.
Baseline training for all AI users, advanced training for high-risk operators, records kept.
Disclose AI interactions, label AI-generated content, watermark generative output, notify on emotion or biometric categorisation.
Risk-management system, data governance, Annex IV file, logging, human oversight, post-market monitoring, incident reporting.
Same high-risk regime for AI embedded in regulated products - medical devices, machinery, vehicles, toys.
Process
How the assessment works
Three simple steps to a defensible readiness position.
Describe your AI use
Answer our smart questionnaire about the AI systems your company builds, deploys or buys - voice or text.
AI-powered analysis
Our engine maps your answers against the AI Act (including the Digital Omnibus updates) to classify risk and identify gaps.
Personalised report
Download a readiness report with your risk classification, applicable obligations, and a prioritised action plan.
Results in about 15-20 minutes
Start Free AI CheckEverything you need to be AI Act ready
Clarity on obligations, a personalised action plan, and expert help when you need it.
Understand the Act
Plain-English guides to the EU AI Act - risk categories, deadlines (updated for the Omnibus), and who is affected.
Free Readiness Assessment
A short assessment tailored to your industry with concrete, prioritised next steps.
Personalised Report
A downloadable readiness report with your gaps, risks, and recommended actions.
High-Risk Guidance
Practical guidance on Annex III use cases and the documentation regulators expect.
AI Literacy Training (Article 4)
Article 4 of the EU AI Act requires every organisation using AI to ensure staff have adequate AI literacy - in force since 2 February 2025. We deliver role-based training your legal team can point at.
Explore AI Literacy TrainingConsultancy & Audits
Hands-on support to close gaps and readiness audits for high-risk systems.
See consultancy & audit servicesFAQ
Frequently asked questions
Everything you need to know about the EU AI Act and our readiness assessment.
Ready in minutes.
Take the free readiness assessment and get a personalised report you can share with your leadership team.
No credit card required · Answers stay confidential · Report in minutes