NEWMindMap Digital has acquired Bluetide.co— deepening our data & agentic-AI stack.Read more →
Home · EU AI Act
Pillar · EU AI Act · Updated June 2026

The EU AI Act: the architecture choices that produce defensible compliance by 2 August 2026.

What the world's first comprehensive AI law actually requires — risk tiers, Articles 9–15 obligations, penalties up to €35M, the 2 Aug 2026 deadline — and the engineering choices we ship to 50+ regulated enterprises.

2 Aug 2026
Annex III deadline
€35M
Max penalty / 7%
7
Core articles (9–15)
12
Point compliance checklist
Deadline approaching
Annex III high-risk systems enforceable from 2 August 2026.
Most enterprise AI workloads — credit scoring, HR, education, essential services — land in this tier. Penalties up to €35M or 7% of global turnover.
Get the 18-page whitepaper →
Definition

The EU AI Act, defined.

The EU AI Act is Regulation (EU) 2024/1689 — the world's first comprehensive horizontal regulation of AI. Adopted in June 2024, in force from August 2024. It takes a risk-tiered approach: AI systems are classified by their risk to health, safety and fundamental rights into four tiers — prohibited, high-risk, limited risk, minimal — and obligations scale with risk.

It applies extraterritorially. If the output of your AI system is used in the EU — a credit score for an EU customer, an HR shortlist for an EU role, an insurance quote for an EU policyholder — the Act applies to you, regardless of where you are established. The headline enforcement date for enterprise is 2 August 2026, when the Articles 9–15 high-risk obligations become enforceable.

For the underlying terms — EU AI Act, sovereign AI, RAG, agentic AI, evaluation — see the enterprise AI glossary.

The four risk tiers

A practical map of where enterprise workloads land

Prohibited
BANNED

Article 5 — social scoring by public authorities, real-time remote biometric ID in public (with narrow exceptions), emotion recognition in workplaces and education, untargeted facial scraping, predictive policing on profiling, manipulation through subliminal techniques.

High-risk
REGULATED

Annex III — biometric ID, critical infrastructure, education, employment / HR, access to essential private and public services (credit scoring, insurance pricing), law enforcement, migration, justice. The tier most enterprise workloads land in.

Limited risk
TRANSPARENCY

Article 50 — chatbots and conversational AI must disclose they are AI. Deepfakes and synthetic content labelled. Emotion-recognition and biometric-categorisation systems notify natural persons.

Minimal risk
VOLUNTARY

Everything else — spam filters, inventory-prediction models, recommendation systems where the use case is not in another tier, video-game AI. No specific obligations beyond voluntary codes.

The classification is the first design choice. 30–50% of a typical enterprise AI portfolio lands in the high-risk tier — not the 5–10% leadership assumes. Remediation cost is proportional to how early you classify.
Enforcement timeline

The dates that drive programme planning

1 Aug 2024
Act in force
Twenty days after publication in the Official Journal. The clock starts on staggered enforcement.
2 Feb 2025
Prohibitions + AI literacy
Article 5 prohibitions enforceable. Article 4 AI literacy obligation begins.
2 Aug 2025
GPAI rules + governance
Obligations on general-purpose AI model providers commence. European AI Office active.
2 Aug 2026
HIGH-RISK ANNEX III ENFORCEABLE
The headline deadline for most enterprises. Articles 9–15 fully apply. Article 50 transparency live.
2 Aug 2027
Annex I high-risk systems
AI as safety components of products covered by existing sectoral product-safety legislation.
31 Dec 2030
Legacy high-risk systems
Systems in operation on 2 Aug 2026 must be brought into full compliance by end-2030.
High-risk system obligations

Articles 9 through 15 — the substance of compliance

These seven articles define what it actually means for a high-risk AI system to be compliant. Each is an architectural choice made early — or a retrofit cost incurred late.

Art. 9

Risk management

Continuous, documented risk-management process across the AI lifecycle. Identify, estimate, evaluate, mitigate risks to health, safety and fundamental rights.

Art. 10

Data governance

Training, validation, testing data must be relevant, representative, free of errors. Bias detection and mitigation built in.

Art. 11

Technical documentation

Annex IV dossier per system — architecture, training data, evaluation, version history, intended purpose, performance metrics.

Art. 12

Record-keeping

Automatic logging across the lifecycle, retained for traceability — sufficient to reconstruct any decision on demand.

Art. 13

Transparency to deployers

Provider gives deployers instructions for use — capabilities, limitations, oversight measures, output interpretation.

Art. 14

Human oversight

Measures designed so a human can monitor, intervene, override and shut down. Not human-in-name-only.

Art. 15

Accuracy, robustness, cybersecurity

Performance metrics declared and met. Resilient to errors, faults, adversarial inputs. Protected against unauthorised modification.

The penalties

€35M or 7% of global turnover. And worse.

Article 99 sets administrative fines. But the binding constraint for tier-1 enterprises is rarely the fine — it's market withdrawal, public disclosure, and the AI Liability Directive's presumption of causation.

€35M
or 7% of global turnover
Prohibited practices
€15M
or 3% of global turnover
High-risk non-compliance
€7.5M
or 1% of global turnover
Misleading information
The MindMap approach

The 12-point engineering compliance checklist

The architectural choices that produce defensible compliance — mapped to MindMap's reference sovereign stack and shipped to 50+ regulated enterprises since 2022.

01
Classify every AI workload by tier
Inventory all AI systems, classify against Annex III, document the rationale. Output: a risk-tier register signed off by the Chief Risk Officer.
02
Deploy high-risk systems on sovereign infrastructure
Pre-satisfies Articles 10, 12 and 15 architecturally rather than through paperwork retrofit.
03
Run a comprehensive eval harness on every change
Accuracy, robustness, faithfulness, bias scored against an SME-built eval set. Deployment gated on regression thresholds.
04
Log every inference with full provenance
Prompt, context, model version, user, response, action — streamed into the customer's own SIEM.
05
Human-in-the-loop on irreversible actions
Tools the agent cannot call without authorisation. Low-confidence routing to human review built into the runtime.
06
Treat technical documentation as code
Annex IV documentation maintained in source control. Auto-generated where possible — model cards, eval reports, lineage.
07
Stand up a quality management system
Article 17 expects an ISO-style QMS — design controls, change control, testing, release procedures.
08
Maintain data + model lineage end to end
What data trained the model, what filtering applied, what biases measured. The audit asks for this thread.
09
Adversarial testing + cybersecurity controls
Prompt-injection threat models, red-teaming of agent workflows, robustness to data poisoning and model extraction.
10
Build the conformity assessment workflow
Internal control or notified body assessment. CE marking, EU declaration of conformity, EU database registration.
11
Implement post-market monitoring
Operational data captured, analysed, fed back into the risk-management cycle. Drift detection. Incident triage.
12
Set up a serious-incident reporting workflow
Article 73 obliges providers to report serious incidents to authorities. Tight timeframes. Clear ownership and escalation paths.
Article-by-article mapping

MindMap's reference architecture pre-satisfies Articles 9–15.

Sovereign architecture, audit trail in the customer SIEM, eval-gated deployment, bounded-autonomy agents — these are not features MindMap added because of the AI Act. They are the architectural pattern we have shipped to 50+ regulated enterprises since 2022, because the bank, the insurer and the hospital required it.

The EU AI Act has codified what regulators in BFSI and healthcare have been asking for all along. The full article-by-article mapping is in the 18-page whitepaper.

Get the whitepaper →See the sovereign architecture
How MindMap helps

Four phases. Six to nine months. Audit-ready production.

01

Assess (4–6 weeks)

Portfolio inventory · risk-tier classification against Annex III · gap analysis against Articles 9–15 · board-ready exposure report and 90-day action plan.

02

Architect (2–4 weeks)

Reference architecture design · sovereign deployment for high-risk workloads · integration with the customer's existing GRC, SIEM, ITSM and identity stack · CIO-signoff package.

03

Implement (6–24 weeks per workload)

Sovereign-cluster build · model serving · RAG · agent runtime · audit layer · eval-set build · technical documentation (Annex IV) · conformity-assessment workflow.

04

Operate (ongoing)

Continuous risk-management cycle · drift monitoring · eval refresh · serious-incident reporting workflow · quarterly compliance review with the customer's risk function.

FAQ

EU AI Act — the questions buyers ask

What is the EU AI Act?

The EU AI Act is Regulation (EU) 2024/1689, the world's first comprehensive horizontal regulation of AI. It classifies AI systems by risk into four tiers — prohibited, high-risk, limited risk, minimal — and applies obligations proportionate to risk. The Act entered into force on 1 August 2024 with staggered enforcement: prohibitions from February 2025, GPAI rules from August 2025, high-risk Annex III systems from 2 August 2026, and Annex I systems from August 2027.

When does the EU AI Act become enforceable?

The headline deadline is 2 August 2026, when the high-risk-system obligations in Articles 9–15 become enforceable for AI systems falling under Annex III categories — biometric identification, critical infrastructure, education, employment, essential services, law enforcement, migration, justice. Prohibited practices have been enforceable since 2 February 2025. GPAI obligations have applied since 2 August 2025. Annex I high-risk systems (product-safety components) become enforceable on 2 August 2027.

Does the EU AI Act apply to companies outside the EU?

Yes. The Act applies extraterritorially under Article 2(1)(c) — to any provider or deployer whose AI system outputs are used in the EU, regardless of where the provider or deployer is established. If your AI-driven decision affects an EU resident (a credit score, an HR shortlist, an insurance quote), the Act applies. Your headquarters can be anywhere; the relevant question is where the output is used.

What are the four risk tiers under the EU AI Act?

Prohibited (Article 5) — social scoring, untargeted facial scraping, emotion recognition in workplaces, real-time biometric ID with narrow exceptions. High-risk (Annex III) — biometric ID, critical infrastructure, education, employment, essential services, law enforcement, migration, justice. Limited risk (Article 50) — chatbots, deepfakes and synthetic content require disclosure. Minimal risk — everything else, no specific obligations beyond voluntary codes.

What are the high-risk system obligations under Articles 9–15?

Article 9: risk management system across the AI lifecycle. Article 10: data governance including bias detection. Article 11: technical documentation per Annex IV. Article 12: automatic logging and record-keeping. Article 13: transparency to deployers. Article 14: human oversight measures. Article 15: accuracy, robustness and cybersecurity. Plus parallel obligations including quality management system (Article 17), conformity assessment (Article 43), CE marking (Article 48), EU database registration (Article 49), post-market monitoring (Article 72) and serious-incident reporting (Article 73).

What are the penalties under the EU AI Act?

Maximum administrative fines under Article 99: up to €35 million or 7% of global annual turnover for prohibited practices; up to €15 million or 3% for high-risk non-compliance; up to €7.5 million or 1% for misleading information. Beyond financial penalties: market withdrawal of non-compliant systems, prohibition of specific uses, public disclosure of non-compliance, and a presumption of causation in civil liability under the proposed AI Liability Directive.

Are foundation models and GPAI regulated separately?

Yes. Articles 53–55 establish a parallel regime for general-purpose AI models — broad-capability models like LLMs and large multimodal models. Baseline obligations include technical documentation, downstream-provider documentation, EU copyright compliance and a public summary of training data. Systemic-risk GPAI models (training compute above 10²⁵ FLOPs) face additional obligations including adversarial testing, EU-level risk assessment, serious-incident reporting and cybersecurity protection.

How does MindMap Digital help with EU AI Act compliance?

MindMap Digital delivers EU AI Act compliance through a four-phase engagement model. Phase 1 (Assess, 4–6 weeks): portfolio inventory, risk-tier classification, gap analysis, board-ready remediation plan. Phase 2 (Architect, 2–4 weeks): reference architecture design, integration with the customer's GRC/SIEM/ITSM stack. Phase 3 (Implement, 6–24 weeks per workload): sovereign-cluster build, model serving, eval harness, Annex IV documentation, conformity assessment workflow. Phase 4 (Operate, ongoing): continuous risk management, drift monitoring, incident reporting, quarterly compliance review.

How is MindMap's reference architecture mapped to EU AI Act obligations?

Article 9 (risk management) — risk-tier classification baked into every engagement, continuous cycle. Article 10 (data governance) — sovereign architecture keeps data inside the perimeter, lineage tracked, bias detection on every fine-tuning. Article 11 (technical documentation) — Annex IV documentation auto-generated as code in customer Git. Article 12 (record-keeping) — Langfuse in-perimeter, every prompt and tool call streamed to the customer's SIEM. Article 13 (transparency to deployers) — operator manuals shipped with every deployment. Article 14 (human oversight) — bounded-autonomy tool registry, permission gates, low-confidence routing. Article 15 (accuracy/robustness/cybersecurity) — eval harness gating every change, adversarial testing including prompt-injection red-teaming, namespace-level egress blocking.

Sixty days to 2 August 2026. Where will your enterprise be?

The 18-page MindMap whitepaper · the 12-point engineering checklist · the article-by-article mapping. Free.

Download the whitepaper →Book a 30-min review →
Talk to the product team