Why Nexovern
Support Request a demo

Home  /  Resources  /  Frameworks  /  EU AI Act

The world's first comprehensive AI law, and it applies to you.

Regulation (EU) 2024/1689 classifies every AI system by risk, assigns obligations accordingly, and enforces compliance with fines up to 7% of global turnover. If your AI system produces output used in the EU, you are in scope, regardless of where your company is incorporated. The phased rollout is already underway, with prohibited practices enforceable since February 2025 and high-risk system deadlines arriving through December 2027.

What is the EU AI Act?

The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. Adopted on 13 June 2024 and published in the Official Journal on 12 July 2024, it entered into force on 1 August 2024 with a phased application schedule running through August 2030. The regulation establishes harmonised rules for the development, market placement, and use of AI systems across the European Union. It is built on a risk-based classification model: unacceptable-risk practices are banned outright, high-risk systems face mandatory conformity assessments and ongoing monitoring, and general-purpose AI models carry their own transparency and safety obligations. The Omnibus VII amendments, which entered into force on 27 July 2026, extended several compliance deadlines and introduced relief for small and mid-cap companies.

7%

of total worldwide annual turnover as the maximum penalty for prohibited AI practices

EU AI Act, Article 99

8

Annex III application areas that classify AI systems as high-risk, from biometrics to democratic processes

EU AI Act, Annex III

1025

FLOPs threshold above which a GPAI model is presumed to carry systemic risk

EU AI Act, Article 51

Who must comply

Providers

Any entity that develops or commissions an AI system or GPAI model and places it on the EU market or puts it into service under its own name or trademark. Providers bear the heaviest obligations: conformity assessments, technical documentation, post-market monitoring, and serious incident reporting. There is no revenue threshold, no headcount minimum, and no startup exemption.

EU AI Act, Articles 16-22

Deployers

Any entity that uses an AI system under its authority, excluding personal non-professional use. Deployers must implement human oversight measures, inform affected individuals, conduct fundamental-rights impact assessments for high-risk systems, and keep logs generated by the system for at least six months.

EU AI Act, Articles 26-27

Non-EU entities with EU output

The Act's extraterritorial reach covers providers and deployers located outside the EU where the output produced by their AI system is used within the EU. A two-person company shipping an AI feature to EU users is as much in scope as a multinational corporation.

EU AI Act, Article 2(1)

Importers and distributors

Importers are EU-based entities that place non-EU AI systems on the EU market. Distributors make AI systems available in the supply chain. Both must verify that the provider has completed conformity assessment, affixed the CE marking, and drawn up the required technical documentation before the system reaches the market.

EU AI Act, Articles 23-25

Product manufacturers

Manufacturers that place products on the market with an embedded AI system under their own name or trademark. They assume provider obligations for the AI component. This covers sectors such as medical devices, machinery, vehicles, toys, and other products regulated under existing EU product-safety legislation listed in Annex I.

EU AI Act, Article 25

Role conversion: deployers who become providers

A deployer, distributor, or importer becomes a provider (inheriting all provider obligations) if it puts its own name or trademark on a high-risk system, makes a substantial modification, or changes the intended purpose of a system so that it becomes high-risk. This prevents entities from relabeling or modifying systems to avoid compliance.

EU AI Act, Article 25(1)

Risk classification

Unacceptable risk: banned outright

Eight categories of AI practices are prohibited with no compliance pathway, enforceable since 2 February 2025. These include subliminal manipulation, exploitation of age or disability vulnerabilities, social scoring, individual predictive policing, untargeted facial-image scraping, emotion inference in workplaces and schools (except medical/safety), biometric categorisation by sensitive attributes, and real-time remote biometric identification in public spaces by law enforcement (with narrow exceptions). Omnibus VII added non-consensual intimate imagery generation and CSAM, enforceable from December 2026.

EU AI Act, Article 5; Omnibus VII (July 2026)

High risk: full conformity required

AI systems that pose significant risks to health, safety, or fundamental rights. A system is high-risk if it is a safety component of a product covered by Annex I product-safety legislation, or if it falls within one of eight Annex III application areas: biometrics, critical infrastructure, education, employment, essential services (including credit scoring and insurance), law enforcement, migration and border control, and administration of justice. Providers must complete conformity assessments, maintain risk management systems, ensure data governance, produce technical documentation, enable logging, and implement human oversight.

EU AI Act, Articles 6-15, 43-49; Annex I, Annex III

Limited risk: transparency obligations

AI systems with disclosure requirements only. Users must be informed that they are interacting with an AI system. This tier covers chatbots and conversational AI, AI-generated or manipulated content (deepfakes, which must be labelled), and emotion-recognition and biometric-categorisation systems that are not otherwise prohibited. No conformity assessment or risk management system is required.

EU AI Act, Article 50

Minimal risk: no mandatory obligations

The majority of AI systems fall here, including AI-enabled video games and spam filters. No mandatory obligations under the Act, though voluntary codes of conduct are encouraged. Systems in this tier can be placed on the market without any regulatory requirements beyond existing general product safety standards.

EU AI Act, Recital 28; voluntary codes of conduct

What you must do

"Complete a conformity assessment and affix the CE marking before placing a high-risk AI system on the EU market."

Articles 43-49, Conformity Assessment Most Annex III high-risk systems use the internal control route: the provider self-assesses its quality management system, examines technical documentation, and verifies design consistency. Real-time remote biometric identification systems and AI embedded in products that already require third-party assessment must go through a notified body. After assessment, the provider draws up an EU declaration of conformity, affixes the CE marking, and registers the system in the EU database.

→ Nexovern captures the continuous runtime evidence that conformity assessments demand: system behavior, data flows, and performance records that map directly to the documentation requirements of Articles 11 and 12.

"Establish and maintain a risk management system throughout the entire AI system lifecycle."

Article 9, Risk Management The system must be continuous, not periodic. Providers must identify and analyse known and reasonably foreseeable risks, estimate risks from intended use and foreseeable misuse, adopt risk-mitigation measures, and demonstrate that residual risk is acceptable. The risk management process must be documented and updated throughout the system's operational lifetime.

→ Nexovern's runtime monitoring feeds continuous risk signals, prompt content, and behavioral metrics into the documented risk management process, replacing periodic manual reviews with real-time evidence collection.

"Design high-risk systems for automatic event logging and full traceability."

Article 12, Record-Keeping / Logging Systems must allow automatic recording of events (logs) throughout their lifetime. Logs must enable traceability of the system's functioning. Deployers must keep logs generated by the system for at least six months. For high-risk systems, the logging requirement is not optional: it must be built into the system's design and architecture.

→ Nexovern correlates app-layer prompt capture with OS-layer telemetry under one identity, producing the traceable, tamper-evident logs that Article 12 requires without depending on the AI system's own logging capabilities.

"Implement human oversight with a mechanism to stop, correct, or override the system."

Article 14, Human Oversight High-risk AI systems must be designed for effective human oversight during their period of use. This includes a "stop" button or similar safe-shutdown mechanism. Oversight measures must be proportionate to the risks, the system's level of autonomy, and the context of use. For autonomous AI agents, oversight cannot be nominal: the design must allow external monitoring and meaningful intervention.

→ Nexovern provides the real-time visibility that human oversight requires: live session monitoring, intervention alerts, and identity-correlated activity records that let oversight personnel understand what each AI system is doing and respond when it deviates.

"Comply with GPAI model obligations: technical documentation, copyright policy, and training data summaries."

Articles 51-55, General-Purpose AI GPAI model obligations have been enforceable since 2 August 2025. All GPAI providers must maintain technical documentation, provide information to downstream system providers, comply with the EU Copyright Directive, and publish a training content summary. Models exceeding 10^25 FLOPs are presumed to carry systemic risk and face additional obligations: model evaluation with adversarial testing, systemic risk assessment, serious incident reporting within two weeks, and cybersecurity protections.

→ Nexovern tracks how GPAI models are integrated and used downstream, providing the evidence chain that downstream providers need when documenting their own systems' reliance on foundation models.

"Establish continuous post-market monitoring and report serious incidents within defined timelines."

Articles 72-73, Post-Market Monitoring and Incident Reporting Providers of high-risk AI systems must establish a continuous post-market monitoring system that actively collects and analyses performance data throughout the system's operational lifetime. Serious incidents must be reported to national market surveillance authorities: within 2 days for widespread or severe incidents, within 10 days when a death is involved, and within 15 days as the default timeline.

→ Nexovern's continuous monitoring captures drift, performance anomalies, and behavioral deviations in real time, giving incident response teams the documented evidence needed to meet the Act's reporting timelines.

"Ensure sufficient AI literacy across staff, contractors, and anyone operating AI systems on your behalf."

Article 4, AI Literacy Enforceable since 2 February 2025. Providers and deployers must ensure AI literacy of their staff and anyone dealing with the operation and use of AI systems on their behalf, including contractors and service providers. While no direct fines apply specifically for violating Article 4, insufficient AI literacy will be treated as an aggravating factor in enforcement of other provisions.

→ Nexovern's visibility into how each user interacts with AI systems provides the usage data that informs AI literacy programs, helping organizations identify where training gaps exist and document the steps taken to close them.

Penalties for non-compliance

Tier 1: up to EUR 35M or 7% of global turnover

For violations of prohibited AI practices under Article 5. The fine is the higher of the fixed amount or turnover percentage. This top tier is 75% higher than GDPR's maximum of 4% / EUR 20M. For SMEs and startups, the fine is the lower of the two figures.

EU AI Act, Article 99(3)

Tier 2: up to EUR 15M or 3% of global turnover

For violations of provider, deployer, importer, distributor, and notified-body obligations, as well as transparency obligations under Article 50. This tier covers the full range of high-risk system requirements: conformity assessment, risk management, technical documentation, logging, human oversight, and data governance.

EU AI Act, Article 99(4)

Tier 3: up to EUR 7.5M or 1% of global turnover

For supplying incorrect, incomplete, or misleading information to notified bodies or national competent authorities. This tier penalizes obstruction of regulatory oversight, whether in conformity assessment submissions, incident reports, or responses to authority requests.

EU AI Act, Article 99(5)

SME and startup relief

For SMEs and startups, the fine is the lower of the fixed amount or turnover percentage (not the higher). The Omnibus VII amendments extended similar relaxations to small and mid-cap companies (SMCs), including simplified technical documentation and proportionate penalties. EU institutions, agencies, and bodies face a separate cap of EUR 1.5 million.

EU AI Act, Article 99(6); Omnibus VII

Key dates

01

1 August 2024: Entry into force

The EU AI Act entered into force 20 days after publication in the Official Journal. No requirements applied yet, beginning a phased application schedule.

02

2 February 2025: Prohibited practices and AI literacy

Prohibited AI practices under Article 5 became enforceable. The AI literacy obligation under Article 4 also took effect, requiring providers and deployers to ensure sufficient AI literacy across their staff and contractors.

03

2 August 2025: GPAI obligations and governance

General-purpose AI model obligations under Articles 51-55 became enforceable. Notified body provisions, governance rules, and the penalty framework also took effect.

04

2 August 2026: Transparency and national authorities

Majority of remaining provisions apply, including transparency obligations for providers under Article 50. Member States must designate national competent authorities and ensure at least one AI regulatory sandbox is operational.

05

2 December 2027: High-risk Annex III systems (amended deadline)

Omnibus VII extended the compliance deadline for stand-alone high-risk systems under Annex III by 16 months. This covers biometrics, critical infrastructure, employment, credit scoring, law enforcement, migration, and administration of justice.

06

2 August 2028: Annex I embedded systems (amended deadline)

Omnibus VII extended the deadline for high-risk AI systems embedded in regulated products (Annex I) by 12 months. This covers AI components in medical devices, machinery, vehicles, and other product-safety legislation.

07

2 August 2030: Public-sector compliance

Public-sector high-risk AI systems must be fully compliant. The Commission is due to publish its enforcement assessment by August 2031.

How Nexovern helps

The compliance clock is running. Build your evidence base now.

Prohibited practices are already enforceable. GPAI obligations are live. High-risk system deadlines arrive in December 2027. Nexovern captures the runtime evidence, identity-correlated logs, and continuous monitoring data that every tier of the EU AI Act demands. See how it maps to your compliance program.