RegumatrixBeta
GuidesPathfinderAI RightsFreeAbout
Sign inGet Started Free

Reference

  • All Articles
  • Official Text ↗

Compliance Guides

  • Compliance Timeline
  • High-Risk Checklist
  • Healthcare AI
  • HR & Recruitment
  • Financial Services
  • GPAI / Foundation Models
  • View all guides →

Product

  • Risk Pathfinder
  • AI Rights Check
  • Get Started Free
  • About
  • Feedback
  • Contact

Legal

  • Privacy Policy
  • Terms

Regumatrix — AI compliance powered by Regulation (EU) 2024/1689

This tool is informational only and does not constitute legal advice.

Grounded in Regulation (EU) 2024/1689 · verified 4 Apr 2026
HomeCompliance
August 2026 deadline — 4 months away

EU AI Act Compliance Guides

Every guide you need to understand and meet EU AI Act obligations — organised by industry, risk level, obligation, and role. Updated for the 2025 Digital Omnibus proposals (COM 836 & COM 837).

62guides across 9 topics
2 Aug 2026main deadline
Updated for COM 836 & COM 837 proposals

Not sure where to start?

Does the AI Act apply to me?

Check whether your organisation, system, or use case is in scope — or covered by an exemption.

Scope & exclusions

Is my AI high-risk?

Work through the Article 6 + Annex III classification test to determine your risk tier and obligation level.

Risk classification

I use AI — someone else built it

If you deploy AI in your organisation but did not develop it, you are a “deployer” with a distinct set of obligations under Article 26.

Deployer obligations
Start HereBy Industry & Use CaseRisk Levels ExplainedCompliance ObligationsYour Role & ResponsibilitiesDigital Omnibus ChangesFines & EnforcementAdvanced & Emerging TopicsComparing Regulations

Start Here

Overview guides, the full compliance timeline, and key definitions — the right starting point for any organisation.

EU AI Act — Complete Guide

What the regulation is, who it applies to, the 4 risk tiers, and how to navigate it.

Arts 1–6Art 50Art 99
2025 proposal

Compliance Timeline 2025–2030

Every enforcement date in one place — Feb 2025, Aug 2026, and 836 fallback dates.

Art 113836 dates
2025 proposal

Key Terms & Definitions

Provider, deployer, GPAI, systemic risk, intended purpose — all defined with article refs.

Art 3

What's Out of Scope

Military AI, personal use, pure research, open-source exceptions — what the Act doesn't cover.

Arts 2–3Art 111

By Industry & Use Case

Is your sector's AI high-risk? Each guide covers classification, exact obligations, and the specific Annex III domain or product-safety pathway that applies.

Healthcare & Medical AI

Diagnostic tools, clinical decision support, and surgical AI — Annex III §5 + MDR/IVDR pathway.

Art 6(1)Arts 9–15Art 43

Recruitment & HR AI

CV screening, candidate ranking, employee monitoring — high-risk under Annex III §4.

Art 6(2)Arts 9–15Art 26

Credit Scoring & FinTech AI

Creditworthiness AI, loan decisioning, insurance pricing — Annex III §5.

Art 6(2)Arts 9–15Art 27

Education & EdTech AI

Student admission systems, exam proctoring, AI tutoring — high-risk AND chatbot transparency rules.

Art 6(2) HR-3Arts 9–15Art 50

Biometric AI Systems

Face recognition, iris scanning, emotion detection — notified body required, some uses prohibited.

Art 5(1)(f–h)Art 6(2) HR-1Art 43

Insurance AI

Life insurance pricing, health underwriting, claims assessment — separate guide from broad financial services.

Art 6(2) HR-5Arts 9–15Art 27
2025 proposal

Public Sector & Government AI

Benefits eligibility, social services, tax AI — FRIA mandatory, extended 2030 deadline for public deployers.

Art 26Art 27Art 113

Law Enforcement AI

Recidivism scoring, criminal profiling, polygraph — notified body mandatory, narrow Art 5 exception.

Art 5(1)(d/h)Art 6(2) HR-6Art 43

LegalTech & Judiciary AI

AI assisting judges, contract analysis, legal research tools — Annex III §8 and right to explanation.

Art 6(2) HR-8Arts 9–15Art 86

Critical Infrastructure AI

Power grid, water utilities, road traffic management, SCADA — high-risk under Annex III §2.

Art 6(2) HR-2Arts 9–15

Immigration & Border Control AI

Asylum processing, visa risk assessment, border crossing detection — overlaps with law enforcement.

Art 5(1)(h)Art 6(2) HR-7Art 43
2025 proposal

Medical Device Software (SaMD)

AI as a medical device — MDR/IVDR + AI Act dual compliance. CE marking via notified body.

Art 6(1)Art 43Art 113
2025 proposal

Automotive & Vehicle AI

AI safety components in type-approved vehicles under Regulation 2019/2144 — Annex I pathway.

Art 6(1)Art 43Art 113
2025 proposal

Aviation AI (EASA)

Annex I pathway + 7 technical corrections to EASA Regulation 2018/1139 under COM 836.

Art 6(1)Art 43Art 113

Risk Levels Explained

The four tiers — prohibited, high-risk, limited risk, minimal risk — and how to classify your AI system correctly.

2025 proposal

Is My AI High-Risk? (Checklist)

All 8 Annex III domains + the Article 6(1) product safety track — one-page decision guide.

Art 6Art 7Annex III

Banned AI: Article 5 Prohibited Practices

All 8 banned uses in plain English — social scoring, facial scraping, real-time biometric ID, emotion recognition at work and school.

Art 5€35M / 7%
2025 proposal

AI Transparency Obligations (Article 50)

Chatbot disclosure, deepfake labelling, AI-generated text marking — the limited-risk tier.

Art 50
2025 proposal

Claiming 'Not High-Risk' (Art 6(3) Derogation)

The narrow exception, 4-condition test, profiling void rule — and the €15M misclassification penalty.

Art 6(3)Art 99(3)

Minimal-Risk AI Systems

Spam filters, recommenders, basic automation — what's fully out of scope and voluntary codes under Art 95.

Art 95

Compliance Obligations

Deep-dive guides for each mandatory requirement. If you've confirmed you're high-risk, start here.

Risk Management System (Article 9)

Iterative process: identify, estimate, evaluate, mitigate. How to document foreseeable misuse.

Art 9

Human Oversight (Article 14)

What 'effective oversight' means legally — HITL, override controls, who must be assigned.

Art 14Art 26(2)
2025 proposal

Conformity Assessment (Article 43)

Self-assessment (Annex VI) vs notified body (Annex VII) — when each applies, who decides.

Arts 40–44Annex VIAnnex VII
2025 proposal

Technical Documentation (Article 11)

What 17+ elements must be documented before market placement — SME simplified form.

Art 11Art 18Annex IV
2025 proposal

EU Database Registration (Art 49 & 71)

Who must register, what data to submit (Annex VIII), when — and what COM 836 removes.

Art 49Art 71Annex VIII

Fundamental Rights Impact Assessment (Art 27)

Who must do it: public bodies + specific deployers. What to assess and when to register.

Art 27
2025 proposalSME proposal

Data Governance (Article 10)

Training/validation/testing dataset obligations, bias handling, sensitive data rules.

Art 10
2025 proposal

Post-Market Monitoring (Arts 72–73)

Continuous monitoring, serious incident reporting obligations and what 836 changes.

Art 72Art 73
2025 proposal

Quality Management System (Article 17)

What a QMS must cover: design, development, testing, monitoring — SME proportionality.

Art 17

CE Marking for AI Systems (Arts 47–48)

EU declaration of conformity (Annex V) then CE marking — which AI systems need it.

Arts 47–48Annex V

Your Role & Responsibilities

Obligations depend on your role in the AI supply chain. Find the guide for your position.

2025 proposal

AI Provider Obligations

Full checklist for developers/vendors — Arts 9–21, conformity, CE marking, registration, post-market.

Arts 9–21Art 43Arts 47–49
2025 proposal

AI Deployer Obligations (Article 26)

'I bought an AI tool' — what deployers must do: oversight, logging, worker notification, FRIA.

Art 26Art 27Art 50(4)

Non-EU AI Companies Selling Into Europe

Extraterritorial reach, authorised representative requirement, obligations for US/UK/Asian providers.

Art 22Arts 23–24Art 2(1)(c)

Importer & Distributor Obligations

Verifying CE marking, forbidden placing of non-compliant systems, labelling requirements.

Art 23Art 24

Product Manufacturers Adding AI (Article 25)

Integrating AI into your product under your own name = treated as provider. Obligations follow.

Art 25

Digital Omnibus Changes2025 proposals

COM(2025) 836 and COM(2025) 837 propose significant amendments to the AI Act and GDPR. These pages explain what changes and what it means for your compliance programme.

2025 proposal

COM 836 — What Changes in the AI Act

Plain-English summary: SME relief, deadline delays, notified body simplification, AI Office expansion.

14 major changes
2025 proposal

EU AI Act for SMEs & Startups

Simplified docs, lighter QMS, fine cap (lower of %, not higher), sandbox priority, new SMC category.

Art 62Art 99(6)
2025 proposalSME proposal

EU AI Act + GDPR: How They Interact

Art 22 automated decisions, Art 9 sensitive data, Art 86 right to explanation — the two regimes side by side.

Art 10Art 14Art 86
SME proposal

COM 837 — GDPR & Data Law Changes

GDPR AI training exemption, automated decisions, cookie consent reform, 96h breach notification.

GDPR Art 9GDPR Art 22
SME proposal

Training AI on Personal Data (837)

New Art 9(2)(k) lawful basis for special category data, conditions, bias detection use.

GDPR Art 9(2)(k)
SME proposal

Automated Decision-Making: GDPR + AI Act

When GDPR Art 22 applies, 837 update for contract automation, Art 14/26 oversight obligations.

GDPR Art 22Art 14Art 86
SME proposal

Cookie Consent Reform (837)

Machine-readable signals (Arts 88a/88b), migration from ePrivacy to GDPR framework.

GDPR Arts 88a/88b
SME proposal

Data Breach Notification: 72h → 96h (837)

Extended timeline, ENISA single-entry reporting across NIS2, GDPR, DORA, eIDAS, CER.

NIS2 Art 23a

Fines & Enforcement

Penalty structure, enforcement mechanisms, and individual rights — what's at stake for non-compliance.

2025 proposal

EU AI Act Fines & Penalties (Article 99)

€35M/7% for prohibited AI, €15M/3% for high-risk violations, €7.5M/1.5% for incorrect info — plus SME cap.

Art 99Art 100Art 101
2025 proposal

How the EU AI Act Is Enforced

Market surveillance authorities, AI Office vs national regulators, investigation powers, recall.

Arts 74–84Arts 88–94
SME proposal

Right to Explanation of AI Decisions (Art 86)

Individuals' right to ask deployers how an AI made a decision — when it applies and what you must provide.

Art 86Art 26

Advanced & Emerging Topics

GPAI systemic risk, agentic AI, open-source exemptions, emotion recognition, regulatory sandboxes — specialist topics for technical and legal teams.

2025 proposal

General-Purpose AI Models (GPAI)

Foundation models and LLMs — Chapter V obligations, copyright policy, downstream provider duties.

Arts 51–56Art 88Art 101

Systemic Risk GPAI Models (Article 55)

10²⁵ FLOPs threshold — adversarial testing, AI Office incident reporting, energy consumption.

Art 51Art 55Art 101

Open-Source AI Compliance

Art 53(2) exemptions for open-weights models, conditions that remove the exemption.

Art 53(2)Art 52
2025 proposal

Agentic AI Systems

New Annex XIV classification codes (836), legal definition of agentic AI, multi-step autonomous systems.

836 Annex XIV codes
2025 proposal

AI Regulatory Sandboxes (Arts 57–63)

How to apply, SME priority access, new EU-level sandbox added by 836, real-world testing.

Arts 57–63

Emotion Recognition AI

Prohibited in workplace/education (Art 5), transparent elsewhere (Art 50), high-risk in other contexts.

Art 5(1)(f)Art 50(3)Art 6(2) HR-1

Social Scoring: Banned Under Article 5

Public and private social scoring both prohibited. What counts. Penalty: €35M/7%.

Art 5(1)(c)
2025 proposal

Deepfakes & Synthetic AI Content

Labelling obligations, Art 50(4) disclosure rule, satire exceptions, 836 watermarking deadline.

Art 50(4)Art 50(2)
2025 proposal

Fundamental Rights & AI

Art 77 authority powers, FRIA (Art 27), right to complain (Art 85) and right to explanation (Art 86).

Arts 27Art 77Arts 85–87

Comparing Regulations

For compliance teams navigating multiple EU regulations simultaneously — where the AI Act overlaps with GDPR, DSA, NIS2, and DORA.

SME proposal

EU AI Act vs GDPR

Scope, who it covers, data rights, automated decisions, and sanctions — side by side. Do you need both?

AI Act + GDPR
2025 proposal

EU AI Act vs Digital Services Act

Recommendation systems, VLOPs, content moderation — and 836's AI Office exclusive competence.

AI Act + DSA
SME proposal

EU AI Act & NIS2: Critical Infrastructure

Annex III HR-2 + NIS2 essential entity requirements — two obligations on the same system.

AI Act + NIS2
SME proposal

EU AI Act & DORA: FinTech AI

AI Act Annex III §5 + DORA ICT risk — financial sector AI caught by both regimes.

AI Act + DORA

These guides explain the rules. Regumatrix tells you which ones hit your system.

Describe your AI system in a sentence. Get back: risk tier, applicable Annex, every obligation with article citations, required actions before August 2026, and fine exposure under Article 99. Eight structured sections. About 30 seconds. 3 free analyses, no credit card.

Analyse my system free — 3 checks included →Quick risk checklist