EU AI Act Pillar Guide · Updated August 2026 · Pillar #9

EU AI Act Practical Guide for 2026
Risk Tiers, GPAI, August 2, 2026 Deadline, and the 90-Day Gap Plan

A working walkthrough of the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689) — the four-tier risk taxonomy (Art. 5 Prohibited / Art. 6 + Annex III High-Risk / Art. 50 Limited-Risk / Minimal-Risk), the eight high-risk obligations under Articles 9–15 (risk management + data governance + technical documentation + record-keeping + transparency + human oversight + accuracy / robustness / cybersecurity), the Articles 51–55 GPAI obligations (model evaluation + 10^25 FLOPs systemic-risk threshold + 15-day serious-incident reporting to the AI Office), the conformity assessment mechanics (Annex IV self-assessment / Annex VII Notified Body / Art. 48 Presumed Conformity / Art. 72 post-market monitoring), the Article 99 penalty tiers (€35M / €15M / €7.5M), and a 2026 readiness roadmap for SaaS, GTM AI, and GPAI providers deploying AI systems to EU users.

Maintained by ComplianceStack · 2026-08-19 · Citation-ready (Dublin Core & citation_* meta)

On this page

  1. §1 EU AI Act Overview — Reg (EU) 2024/1689, 13 Chapters, 113 Articles, Phased Applicability, and the May 7, 2026 AI Omnibus
  2. §2 The Four Risk Tiers — Art. 5 Prohibited, Art. 6 + Annex III High-Risk, Art. 50 Limited-Risk, Minimal-Risk
  3. §3 Scope and Controls — Articles 9–15 High-Risk Obligations and Articles 51–55 GPAI Obligations
  4. §4 Audit / Conformity Assessment Mechanics — Annex IV, Annex VII, Article 48 Presumed Conformity, Article 72 Post-Market Monitoring
  5. §5 Article 99 Penalties — €35M / 7%, €15M / 3%, €7.5M / 1% Tier System and Member State DPA Designations
  6. §6 Ready-in-90-Days Gap Checklist for the August 2, 2026 / December 2, 2027 High-Risk Enforcement Window
  7. §7 2026 Readiness Roadmap for SaaS / GTM AI / GPAI Deployers
  8. §8 Pair this guide with the ComplianceStack EU AI Act Tools
  9. §8a Framework Crosswalk — EU AI Act Articles 9–15 ↔ NIST AI RMF 1.0 ↔ ISO/IEC 42001 ↔ GDPR Art. 22 ↔ SOC 2 CC6
  10. §9 Frequently Asked Questions

§1 EU AI Act Overview — Reg (EU) 2024/1689, 13 Chapters, 113 Articles, Phased Applicability, and the May 7, 2026 AI Omnibus

The EU AI Act (Regulation (EU) 2024/1689) is the world’s first horizontal AI regulation. Entered into force August 1, 2024; published in the Official Journal of the European Union July 12, 2024; structured across 13 Chapters and 113 Articles covering prohibited practices, high-risk systems, transparency, GPAI models, enforcement, governance, and Member State competent authorities. Phased applicability with enforcement trigger dates that have shifted under the May 7, 2026 AI Omnibus provisional deal.

The EU AI Act applies to any provider placing an AI system on the EU market, any deployer putting an AI system into service in the EU, any provider or deployer of an AI system whose output is used in the EU, and any importer / distributor of AI systems placed on the EU market — regardless of whether the provider or deployer is established in the EU or outside it (Art. 2). The extraterritorial reach is the central reason US companies with EU customers, employees, or users must classify their AI systems. SaaS platforms with EU subscribers, HR tools with EU job applicants, healthcare AI serving EU patients, fintech with EU counterparties, and any foundation model exposing APIs to EU developers all land inside scope.

Phased applicability (Article 113): February 2, 2025 — Prohibited practices under Article 5 + AI literacy obligation under Article 4 enforcement began. August 2, 2025 — GPAI model obligations under Chapter V (Articles 51–55) enforcement began, including the systemic-risk classification at the 10^25 FLOPs training-compute threshold. August 2, 2026 — Originally Annex III high-risk-system enforcement + Article 50 transparency obligations; the Article 50 transparency obligations remain unchanged at August 2, 2026 (chatbot disclosure, deepfake labeling, AI-generated content marking, emotion-recognition notification). December 2, 2027 — Annex III high-risk-system enforcement, DEFERRED 16 months by the Council/Parliament AI Omnibus provisional deal reached May 7, 2026. August 2, 2028 — High-risk AI embedded in Annex I product-safety products (medical devices, machinery, toys, etc.), deferred 24 months by the AI Omnibus. New NCII / nudifiers ban: effective December 2, 2026 under the AI Omnibus. Watermarking and content marking moved to December 2, 2026. National sandbox deadline extended to August 2027 with a new EU-level sandbox (SME / start-up priority). SME benefits extended to newly defined “small mid-cap” companies. Source: Council Press Release 2026-05-07.

Governance structure: enforcement is split between the Commission AI Office (a centralized body inside DG CONNECT responsible for GPAI model enforcement and Art. 113 coordination), and the Member State competent authorities (NCAs / DPAs designated per Art. 70). The five largest NCAs by volume are Germany (Bundesnetzagentur + BMBF, NCA designated), France (ARCOM + CNIL, NCA designated), Netherlands (Rijksdienst voor Digitale Infrastructuur RDI), Spain (Agencia Española de Supervisión de Inteligencia Artificial AESIA — the first standalone EU AI regulator, operational since January 2024), and Ireland (Competition and Consumer Protection Commission CCPC — primary NCA for many US tech companies with EU HQ in Ireland). The NCA designation carries the Article 99 penalty-allocation authority within each Member State; cross-border enforcement coordination flows through the AI Office and the European AI Board established under Article 7.

§2 The Four Risk Tiers — Art. 5 Prohibited, Art. 6 + Annex III High-Risk, Art. 50 Limited-Risk, Minimal-Risk

The EU AI Act organizes AI systems into four risk tiers tied to the use case and the data subject affected. Tiers are mutually exclusive: a system is either Prohibited (Art. 5), High-Risk (Art. 6 + Annex III), Limited-Risk (Art. 50 transparency), or Minimal-Risk. ComplianceStack maps every AI deployment to its applicable tier via the Article 6 + Annex III classification decision.

Tier 1 · Unacceptable / Prohibited
Art. 5 — Banned practices
Subliminal manipulation beyond a person’s consciousness, exploitation of vulnerabilities of specific groups, social scoring by public authorities, real-time remote biometric ID in publicly accessible spaces for law enforcement, predictive policing based solely on profiling, untargeted scraping of facial images for facial-recognition databases, emotion recognition in the workplace or in education, biometric categorization inferring sensitive attributes. NCII / nudifier ban added December 2, 2026 under the AI Omnibus.
Tier 2 · High-Risk
Art. 6 + Annex III — Controlled
Biometric ID, critical infrastructure, education / vocational training, employment / worker management, essential private and public services, law enforcement, migration / asylum / border control, administration of justice and democratic processes — plus the Annex I product-safety AI components (medical devices, machinery, toys, etc.). Full Art. 9–15 obligations including Annex IV self-assessment.
Tier 3 · Limited-Risk
Art. 50 — Transparency
Chatbot disclosure, AI-generated content labeling, deepfake disclosure, emotion recognition notification. No Annex IV / Annex VII conformity assessment. The August 2, 2026 enforcement trigger applies here — any AI system that interacts with natural persons, generates synthetic content, or performs emotion / biometric categorization must surface the transparency obligation.
Tier 4 · Minimal-Risk
No mandatory requirements
Most consumer AI tooling, content recommendation systems, spam filters, AI-assisted productivity tools. Voluntary Code of Conduct under Art. 95 encouraged — not a regulatory gate. ComplianceStack tracks this tier with a free Voluntary AI Code-of-Conduct Checklist so organizations that land in minimal-risk can still surface intent.

High-risk decisions: Art. 6 + Annex III vs. Annex I

The Article 6 high-risk classification splits into two pathways. Annex III high-risk is the broad use-case list (biometric ID, critical infrastructure, education, employment, essential services, law enforcement, migration, administration of justice, democratic processes) and was the original August 2, 2026 enforcement date — deferred to December 2, 2027 under the May 7, 2026 AI Omnibus. Annex I product-safety high-risk is the product-safety-track list (medical devices under 93/42/EEC, machinery, toys, radio / telecom equipment, in-vitro diagnostics, motor vehicles, civil aviation, etc.) and was originally a separate earlier enforcement date — deferred to August 2, 2028 under the AI Omnibus. The deferred dates mean US companies deploying AI to EU users have a documented 14-month window (August 2, 2026 → December 2, 2027) for the Annex IV conformance work; companies with Annex I product-safety scope have a 24-month window.

Limited-risk decisions: Art. 50 obligations

Article 50 transparency obligations apply to (a) AI systems directly interacting with natural persons — such as chatbots, virtual assistants, and any conversational AI — users must know they are interacting with an AI; (b) AI systems generating synthetic audio / image / video / text — content must be machine-readable and detectable as AI-generated per the watermarking requirements moved to December 2, 2026; (c) emotion-recognition systems; (d) biometric-categorization systems inferring sensitive attributes; (e) deepfake generation or manipulation — deployers must disclose deepfake content. The Commission Code of Practice on AI-generated content, consultation open from May 2026 (closes October 2, 2026), sets the practical implementation expectations; the second draft of March 5, 2026 simplified obligations and removed the AI-generated vs AI-assisted taxonomy.

ComplianceStack’s tier-mapping logic

The ComplianceStack EU AI Act risk classifier walks every screened AI system through three questions in order: (1) Does the system or use case match any of the eight Article 5 prohibited practices? (2) Does the system or use case match any of the eight Annex III use-case areas, OR is it a safety component of an Annex I product? (3) Does the system or use case match any of the four Article 50 transparency triggers? If yes to (1) → Prohibited — do not deploy. If no to (1) but yes to (2) → High-Risk — run the Annex IV self-assessment or Annex VII Notified Body. If no to (1) and (2) but yes to (3) → Limited-Risk — implement Article 50 transparency. If no to all three → Minimal-Risk — voluntary Code of Conduct under Article 95.

§3 Scope and Controls — Articles 9–15 High-Risk Obligations and Articles 51–55 GPAI Obligations

The high-risk obligations under Articles 9–15 are the substantive control set for any AI system classified under Article 6 + Annex III. The GPAI obligations under Articles 51–55 apply to foundation-model providers above the 10^25 FLOPs threshold. Together they form the documentable evidence pack the Annex IV technical documentation must contain.

Article 9 — Risk-management system across the full lifecycle

Article 9 requires a documented, iterative risk-management system that runs from the initial design phase through the post-market monitoring phase. The system must identify and analyze known and reasonably foreseeable risks to health, safety, fundamental rights, the environment, democracy, and the rule of law; estimate and evaluate those risks; evaluate other risks arising from the use of the AI system; and adopt appropriate risk-management measures. The risk-management cycle is iterative: risks re-evaluated every significant system modification. ComplianceStack pairs Article 9 with the ComplianceStack AI Risk Register tool that maps deployment risks against use-case / data / model-inference / output categories.

Article 10 — Data and data governance

Article 10 requires that training, validation, and testing data sets meet quality criteria including relevance, representativeness, and (to the best extent possible) absence of errors and biases; that data sets are obtained lawfully; that they have appropriate statistical properties for the intended purpose; that data preparation processing operations (annotation, labeling, cleaning, enrichment, aggregation) are documented; and that datasets are examined for possible biases that could lead to discrimination. Where sensitive personal data is used, Article 10 subjects overlap with GDPR Art. 9 special-category processing.

Article 11 — Technical documentation per Annex IV

Article 11 sets the technical-documentation requirement, with the Annex IV required content list: (1) general description of the AI system including intended purpose, person(s) deploying, version, environment, etc.; (2) detailed description of system elements and design choices; (3) detailed description of capabilities and limitations; (4) intended purposes; (5) risk-management measures per Article 9; (6) data and data-governance per Article 10; (7) performance metrics, foreseeable unintended outcomes, sources; (8) validation and testing procedures; (9) cybersecurity measures; (10) post-market monitoring plan; (11) declarations of conformity; (12) instructions for use. ComplianceStack pairs Article 11 with the ComplianceStack Annex IV Technical Documentation Builder that scaffolds every required section.

Article 12 — Record-keeping (automatic logging)

Article 12 requires automatic logging of events over the AI system’s lifetime to ensure traceability of the system’s functioning, with a minimum retention matching the intended purpose and applicable Union law. Logs must enable monitoring of the AI system’s operation, post-market monitoring per Article 72, and reconstruction of past events. ComplianceStack pairs Article 12 with the ComplianceStack AI Lifecycle Event Logger that records every deployment decision + inference input / output metadata into an immutable, auditable trail.

Article 13 — Transparency to deployers

Article 13 requires high-risk AI systems to be designed to enable deployers to interpret the system’s output and use it appropriately. Instructions for use must be concise, complete, correct, and clear; include the identity and contact details of the provider; the system’s characteristics, capabilities, and limitations; the intended purposes; the level of accuracy, robustness, and cybersecurity metrics per Article 15; and known foreseeable circumstances that may lead to foreseeable unintended outcomes.

Article 14 — Human oversight

Article 14 requires that high-risk AI systems be designed to allow effective human oversight during the period of use, with appropriate measures to enable it. Human oversight must be effective — overseen by natural persons; interactive — allowing meaningful intervention; and understood by natural persons. The designer-side measures (built into the system) and the operator-side measures (instructed by the deployer) are spelled out in Annex IV. AI systems used for biometric identification or critical infrastructure carry mandatory minimum human-oversight configurations.

Article 15 — Accuracy, robustness, cybersecurity

Article 15 requires that high-risk AI systems be designed with appropriate levels of accuracy, robustness (resilience to errors, faults, inconsistencies), and cybersecurity (resilience to adversarial attacks per Recital 96). The accuracy metrics must be declared in the instructions for use; robustness minimisation of unintended outcomes must operate under foreseeable misuse; cybersecurity measures must address unauthorized access, data poisoning, model inversion, and adversarial examples. ComplianceStack pairs Article 15 with the ComplianceStack AI Robustness & Adversarial Testing tool that runs red-team testing against deployed AI systems.

Articles 51–55 — GPAI model obligations

Articles 51–55 apply to providers of general-purpose AI models. Article 51 requires training-data summarization, intellectual-property-respect policy, and downstream-integration documentation support. Article 52 sets the Annex XI technical-documentation content list (model architecture + training process + evaluation results + safety testing + risk-mitigation). Article 53 obliges providers to cooperate with downstream AI-system providers (the integrator tier). Article 54 activates when the model is classified as “systemic risk” — triggered at the 10^25 FLOPs training-compute threshold — with model evaluation, adversarial testing, cybersecurity incident-reporting, and energy-efficiency tracking. Article 55 sets serious-incident reporting to the AI Office within 15 days of the provider becoming aware. The 10-year Annex XI documentation retention applies.

§4 Audit / Conformity Assessment Mechanics — Annex IV, Annex VII, Article 48 Presumed Conformity, Article 72 Post-Market Monitoring

For high-risk AI systems, conformity assessment is the gate that turns design and engineering documentation into a deployable system matching the Member State NCA expectations. ComplianceStack breaks the conformity assessment into four paths, calibrated to the classification and the use case.

Conformity path Trigger Who audits Output
Annex IV internal control Annex III high-risk (most use cases) Provider self-assessment Annex IV technical documentation + EU Declaration of Conformity
Annex VII Notified Body Biometric ID + certain critical infrastructure AI Notified Body (designated by Member State) Notified Body certificate + Annex VII audit report
Article 48 Presumed Conformity Harmonized CEN / CENELEC standards (when issued) Provider self-attestation against published standard EU Declaration of Conformity + citation of harmonized standard
Annex I product-safety pathway AI component of a regulated product (medical device, machinery, etc.) Existing product-safety Notified Body sectoral process CE marking per existing sectoral process + AI overlay

Annex IV self-assessment (the default high-risk path)

Annex IV self-assessment is the conformity path for the bulk of Annex III high-risk use cases. The provider performs the assessment internally against the eight Articles 9–15 obligations, packages the Annex IV required content list (general system description, design choices, capabilities and limitations, intended purposes, risk-management measures, data-governance, performance metrics, validation / testing, cybersecurity, post-market monitoring plan, declarations of conformity, instructions for use), generates an EU Declaration of Conformity under Annex V, runs the CE marking compliance step, and registers the system in the EU AI database before placing it on the market. ComplianceStack pairs Annex IV with the ComplianceStack Annex IV Builder that scaffolds every required Annex IV section.

Annex VII Notified Body assessment

Annex VII Notified Body assessment is required for certain biometrics and critical-infrastructure AI systems — the most sensitive categories of the Annex III list. The provider engages a Member-State-designated Notified Body to perform the conformity assessment; the Notified Body issues an assessment report and (where compliant) a Notified Body certificate. The CE marking step follows. The Notified Body designation structure is still being operationalized in 2026; Member State NCAs have begun publishing the list of designated Notified Bodies in Q2 2026. ComplianceStack pairs the Annex VII path with a Notified Body Readiness Package that pre-checks the Annex IV documentation against Notified Body expectations before the formal engagement.

Article 48 Presumed Conformity (harmonized standards route)

Article 48 sets the Presumed Conformity mechanism: AI systems conforming to harmonized CEN / CENELEC standards adopted per Regulation (EU) No 1025/2012 are presumed to conform to the Articles 9–15 obligations the standards seek to cover. As of 2026, the CEN/CENELEC JTC 21 technical committee has started publishing drafts of the harmonized standards — the first published standards are expected in late 2026 / early 2027. Until then, providers must perform the Annex IV internal assessment themselves; once standards are published, providers can replace selected Annex IV sections with citations to the harmonized standard. ComplianceStack tracks the harmonized-standard publication list and updates Annex IV mappings as new standards land.

Article 72 Post-Market Monitoring & Article 73 serious-incident reporting

Article 72 requires every high-risk AI provider to establish and document a post-market monitoring system proportionate to the nature of the AI system. The post-market monitoring plan is part of the Annex IV technical documentation; the active monitoring actively analyzes feedback from deployers + reports on AI system performance + documents any serious incident or malfunction. Article 73 requires that providers of high-risk AI systems report any serious incident to the market surveillance authorities of the Member States where the incident occurred within 15 days of becoming aware of the incident (or earlier for critical-infrastructure incidents causing a breach of EU fundamental rights). The Article 73 notice must include the Member States affected, the AI system characteristics, the circumstances of the incident, and the corrective measures taken or planned.

§5 Article 99 Penalties — €35M / 7%, €15M / 3%, €7.5M / 1% Tier System and Member State DPA Designations

Article 99 sets the penalty tier system, applied by Member State NCAs proportionate to the nature, gravity, and duration of the infringement. ComplianceStack ranks every EU AI Act exposure against the three tiers plus the GPAI-specific upper cap under Article 101.

Tier Trigger (Article 99) Maximum penalty
Tier 1 — Art. 99(3) Article 5 prohibited practices €35M or 7% of global annual turnover (whichever is higher)
Tier 2 — Art. 99(4) High-risk Articles 9–15 non-compliance €15M or 3% of global annual turnover (whichever is higher)
Tier 3 — Art. 99(5) Misinformation to authorities + ancillary infringements €7.5M or 1% of global annual turnover (whichever is higher)
Article 101 GPAI cap Article 51–55 GPAI model provider non-compliance Up to 3% of global turnover OR €15M (whichever higher)

Member State NCA designations (Article 70 NCA listings, source: ArtificialIntelligenceAct.eu / Member State designations as of May 14, 2026):

The Commission AI Office is the centralized enforcement body for GPAI models — it can request information from GPAI providers under Article 91, conduct evaluations under Article 92, and apply the Article 101 GPAI penalty cap. Cross-border enforcement coordination flows through the European AI Board established under Article 7.

§6 Ready-in-90-Days Gap Checklist for the August 2, 2026 / December 2, 2027 High-Risk Enforcement Window

ComplianceStack packages the EU AI Act readiness program as an 8-obligation, 90-day gap checklist mapped to every Article 9–15 high-risk obligation plus the Article 51–55 GPAI obligations. The 90-day program is the readiness runway between the August 2, 2026 Article 50 transparency deadline and the December 2, 2027 deferred Annex III high-risk enforcement date.

Day 0–14 — Article 9 Risk-Management System + Article 10 Data Governance

Day 15–30 — Article 11 Technical Documentation + Article 12 Record-Keeping

Day 31–45 — Article 13 Transparency to Deployers + Article 14 Human Oversight

Day 46–60 — Article 15 Accuracy / Robustness / Cybersecurity

Day 61–90 — Article 51–55 GPAI + Article 72 Post-Market Monitoring + Article 73 Serious-Incident Reporting

§7 2026 Readiness Roadmap for SaaS / GTM AI / GPAI Deployers

ComplianceStack tracks three sector-specific 2026 EU AI Act readiness roadmaps. The roadmaps share an Articles 9–15 baseline but diverge on which obli gations apply, the conformity-assessment path, and the Member State NCA engagement.

Pattern 1 — SaaS deploying AI systems to EU users with Annex III high-risk classification

The recommended pathway is Annex IV self-assessment with Annex VII Notified Body engagement reserved for biometric ID or critical-infrastructure scope. The 90-day program covers the full eight-Articles 9–15 obligation matrix (risk management + data governance + technical documentation + record-keeping + transparency + human oversight + accuracy / robustness + cybersecurity); the Annex IV technical-documentation scaffolding; the Annex V EU Declaration of Conformity; the CE marking; and the EU AI database registration. Article 99 Tier 2 penalty exposure: €15M or 3% of global annual turnover, whichever is higher. ComplianceStack pairs the SaaS pattern with the Annex IV Builder + the Article 99 exposure estimator.

Pattern 2 — GTM / Sales AI deployers (Article 50 limited-risk)

Chatbots, AI-generated content, deepfake generation, and emotion-recognition systems in GTM / Sales contexts typically fall under Article 50 limited-risk rather than Annex III high-risk. The recommended pathway is the August 2, 2026 Article 50 transparency obligations: chatbot user disclosure (the user must know they’re interacting with an AI); AI-generated content labeling; deepfake disclosure; emotion-recognition notification. The Commission Code of Practice on AI-generated content, consultation open from May 2026 (closing October 2, 2026), sets the practical implementation expectations. ComplianceStack pairs the GTM pattern with the Article 50 Transparency Notice template + the Code of Practice orientation checklist. Typical 30-day readiness program.

Pattern 3 — GPAI providers and GPAI-systemic-risk providers

Article 51–55 obligations: training-data summary (Art. 53); Annex XI technical documentation maintained for 10 years; downstream-integration support documentation; systemic-risk classification at the 10^25 FLOPs training-compute threshold (Art. 51); model evaluation, adversarial testing, cybersecurity incident-reporting, energy-efficiency tracking (Art. 54); 15-day serious-incident reporting to the AI Office (Art. 55). Article 101 GPAI penalty cap: up to 3% of global turnover OR €15M, whichever is higher. The 90-day program covers the full Article 51–55 obligation matrix; the Annex XI technical-documentation scaffolding; the 15-day reporting channel setup; the systemic-risk classification decision documentation. ComplianceStack pairs the GPAI pattern with the Annex XI Builder + the 10^25 FLOPs classification calculator + the Article 101 exposure estimator.

§8 Pair this guide with the ComplianceStack EU AI Act Tools

Three ComplianceStack tools pair directly with this pillar guide. The EU AI Act report is the lightweight tier-classification diagnostic (under 60 seconds, no signup); the EU AI Act audit is the in-depth Articles 9–15 readiness pass with conformity-path selection; and the 90-day roadmap deliverable converts the 8-obligation gap backlog into a sequenced plan. ComplianceStack pricing covers audit-ready deliverables from free gap-mapping to paid 90-day roadmap reports.

EU AI Act Risk Report ($19)

The ComplianceStack EU AI Act Risk Report at /eu-ai-act-report covers every AI system in your EU deployment scope against the Article 5 prohibited list and the Annex III high-risk list, classifies by tier, surfaces the most-cited Article 9–15 deficiency categories — missing risk-management under Art. 9, missing training-data bias examination under Art. 10, missing Annex IV technical documentation under Art. 11, missing automatic logging under Art. 12, missing human-oversight measures under Art. 14, missing adversarial-attack resilience under Art. 15 — with conformity-path recommendation (Annex IV / Annex VII / Art. 48 / sectoral) and a 90-day Art. 9–15 implementation timeline. Output is a PDF deliverable + an interactive checklist view in your account dashboard.

Get the $19 EU AI Act Risk Report →

EU AI Act Audit ($199)

The ComplianceStack EU AI Act Audit at /eu-ai-act-audit runs the deep Articles 9–15 readiness pass across every high-risk AI system in scope. The audit pairs EU AI Act with adjacent frameworks — GDPR Article 22 automated-decision overlap, NIST AI RMF 1.0 GOVERN/MAP/MEASURE/MANAGE alignment, SOC 2 CC6 logical-access crossover, ISO/IEC 42001 Annex A controls. Output: a prioritized 8-obligation gap remediation backlog, conformity-path selection, Article 99 Tier 1/2/3 penalty exposure across the three tiers, Member State DPA designation matrix, 90-day readiness roadmap deliverable, and an EU Declaration of Conformity draft per Annex V.

Run the $199 EU AI Act Audit →

90-Day Readiness Roadmap

The ComplianceStack 90-Day Roadmap at /90-day-roadmap converts the EU AI Act 8-obligation gap backlog into a sequenced implementation plan. Output: a 90-day delivery plan covering Article 9 risk-management system + Article 10 data-governance + Article 11 Annex IV technical documentation + Article 12 record-keeping + Article 13 transparency + Article 14 human oversight + Article 15 accuracy / robustness / cybersecurity + Article 72 post-market monitoring, with named owners, evidence-package expectations, the EU Declaration of Conformity draft per Annex V, and the CE marking + EU AI database registration checklist. ComplianceStack delivers this in 3–5 business days.

Build the 90-Day Roadmap →

Multi-Framework Coverage (EU AI Act + GDPR + NIST AI RMF + SOC 2)

The ComplianceStack free compliance assessment at /free-compliance-assessment scores EU AI Act alongside GDPR + NIST AI RMF 1.0 + SOC 2 in a single multi-question instrument. Useful for any organization facing EU AI Act exposure alongside adjacent frameworks — GDPR for personal-data-processing AI, NIST AI RMF for the GOVERN/MAP/MEASURE/MANAGE alignment that’s the de facto US-market counterpart, SOC 2 for the enterprise-buyers logical-access cell. Output: every-framework risk score and a cross-framework remediation map.

Open the Multi-Framework Assessment →

§8a Framework Crosswalk — EU AI Act Articles 9–15 ↔ NIST AI RMF 1.0 ↔ ISO/IEC 42001 ↔ GDPR Art. 22 ↔ SOC 2 CC6

ComplianceStack pairs every EU AI Act Article 9–15 high-risk obligation with its NIST AI RMF 1.0 function counterpart, its ISO/IEC 42001:2023 Annex A control, its GDPR Article 22 (automated decision-making) overlap, its SOC 2 CC1–CC9 logical-access cell, plus the four primary-source families the roadmap item mandates binding every Article 9–15 row to NIST CSF 2.0 Function/Category/Subcategory, NIST SP 800-53 Rev 5 control family IDs, HIPAA Security Rule §164.302-318 safeguard IDs, and AICPA TSC CC1-CC9 (2022) criterion IDs with named primary-source citations and outbound pillar links. Use this crosswalk to map a finished EU AI Act evidence package to a NIST AI RMF Current-vs-Target Profile without re-papering controls and to demonstrate continued NIST AI RMF + ISO/IEC 42001 alignment to enterprise buyers who request both attestations.

EU AI Act Article NIST AI RMF 1.0 Function / Category / Subcategory ISO/IEC 42001 Annex A GDPR overlap SOC 2 Trust Services Criterion (CC1–CC9) NIST CSF 2.0 Function / Category / Subcategory NIST SP 800-53 Rev 5 control family HIPAA Security Rule 45 CFR §164.302-318 (when AI processes PHI) Primary-source citation
Art. 9 — Risk-management system GOVERN-1.1 / 1.2 / 2.1 / 2.2 + MANAGE-1.1 A.5.1 AI policies + A.5.7 risk management Art. 35 DPIA (high-risk automated processing) CC1.1 + CC2.3 + CC3.1 + CC3.2 GV.RM-01 / GV.RM-04 + ID.RA-01 / ID.RA-04 RA-3 (Risk Assessment) + PM-9 (Risk Management Strategy) §164.308(a)(1)(ii)(A) Risk Analysis + §164.308(a)(1)(ii)(B) Risk Management Reg (EU) 2024/1689 Art. 9 / NIST AI RMF 1.0 (Jan 2023) / NIST CSF 2.0 (Feb 2024) / NIST SP 800-53 Rev 5 / 45 CFR §164.308(a)(1)
Art. 10 — Data governance MAP-1.1 / 1.2 / 1.3 + MEASURE-2.1 / 2.2 / 2.3 A.6.2 / A.6.3 data quality Art. 5(1)(b) accuracy + Art. 22(1) profiling logic CC2.1 + P1.1 + P2.1 + P3.5 (Privacy) ID.AM-05 / ID.AM-07 + PR.DS-01 + PR.IP-06 AC-16 (Security Attributes) + SI-7 (Software / Firmware Integrity) + SR-4 (Provenance) §164.502 Uses / Disclosures of PHI + §164.514 de-identification standard + §164.308(a)(6) Security Incident Procedures Reg (EU) 2024/1689 Art. 10 / GDPR Art. 5 + 22 / NIST SP 800-53 Rev 5 AC-16 SI-7 SR-4 / 45 CFR §164.502 / §164.514
Art. 11 — Annex IV technical documentation GOVERN-4.1 (documentation) A.7.5 documented information Art. 13 / 14 information obligations CC2.1 / CC2.3 + CC4.1 GV.OV-01 / GV.OV-03 + ID.IM-04 PL-4 (Plan of Action and Milestones) + SA-15 (Development Process / Standards) §164.316(b)(1) Documentation retention (6 years) + §164.316(b)(2) Availability of documentation Reg (EU) 2024/1689 Art. 11 + Annex IV / NIST SP 800-53 Rev 5 PL-4 SA-15 / 45 CFR §164.316(b)
Art. 12 — Record-keeping / automatic logging MANAGE-4.1 / 4.2 (logging) A.8.4 monitoring + logging Art. 30 records of processing activities CC7.1 / CC7.2 + CC7.3 + CC7.5 DE.CM-01 / DE.CM-03 / DE.CM-09 + PR.PT-01 AU-2 (Audit Events) + AU-12 (Audit Record Generation) + AU-9 (Protection of Audit Info) §164.312(b) Audit Controls + §164.316(b)(2)(i) Hardware / Software / Procedural mechanisms Reg (EU) 2024/1689 Art. 12 / NIST SP 800-53 Rev 5 AU-2 AU-9 AU-12 / 45 CFR §164.312(b)
Art. 13 — Transparency to deployers GOVERN-2.3 (transparency) A.5.8 communication Art. 13 / 14 transparency obligations CC2.2 + CC2.3 + CC9.1 (Confidentiality / Privacy) GV.OC-03 / GV.OC-05 + PR.AT-01 AT-2 (Security Awareness Training) + PL-4 (Plan of Action) + SI-12 (Information Output Handling) §164.520 Notice of Privacy Practices + §164.308(a)(5)(ii)(A) Security reminders + §164.404 Individual Notice Reg (EU) 2024/1689 Art. 13 / GDPR Art. 13 + 14 / NIST SP 800-53 Rev 5 AT-2 SI-12 / 45 CFR §164.520 / §164.404
Art. 14 — Human oversight GOVERN-3.1 + MANAGE-1.1 / 1.2 / 1.3 A.5.10 / A.5.11 human oversight Art. 22(3) right to human intervention CC1.4 + CC4.2 + CC5.1 (Control Activities) GV.OV-01 / GV.SC-04 + PR.AT-02 PS-1 / PS-5 (Personnel Security) + SA-11 (Developer Testing) + AT-3 (Role-Based Training) §164.316(b)(2)(ii) Workforce training documentation + §164.530(b) Privacy training + §164.308(a)(3)(ii)(C) Termination procedures Reg (EU) 2024/1689 Art. 14 / NIST SP 800-53 Rev 5 PS-1 PS-5 SA-11 AT-3 / 45 CFR §164.316(b)(2)(ii) / §164.530(b)
Art. 15 — Accuracy / robustness / cybersecurity MEASURE-1.1 / 1.2 + MANAGE-2.1 A.8.7 / A.8.8 reliability + cybersecurity Art. 32 security of processing CC6.6 + CC7.1 + CC7.3 + CC7.4 + A1.2 (Availability) PR.AC-01 / PR.AC-04 + PR.DS-01 / PR.DS-02 + DE.CM-01 + RS.MI-01 SC-5 (Denial of Service Protection) + SC-28 (Protection of Information at Rest) + SI-3 (Malicious Code Protection) + IR-4 (Incident Handling) §164.312(a)(2)(iv) Encryption &decryption + §164.312(e)(2)(ii) Transmission encryption + §164.402(2) Encryption safe-harbor presumption Reg (EU) 2024/1689 Art. 15 + Recital 96 / NIST SP 800-53 Rev 5 SC-5 SC-28 SI-3 IR-4 / 45 CFR §164.312(a)(2)(iv) / §164.402(2)
Art. 51–55 — GPAI obligations GOVERN-1.1 + MAP-1.1 + MEASURE-1.1 + MANAGE-4.1 A.5.1 / A.6.2 / A.7.5 / A.8.4 Art. 22 + Art. 24 data protection by design CC1.1 + CC2.1 + CC7.1 + P1.1 + P8.1 (Privacy) GV.SC-01 / GV.SC-09 + ID.SC-04 + RS.CO-04 SR-1 / SR-3 / SR-6 (Supply Chain) + MA-2 (Controlled Maintenance) + IR-6 (Incident Reporting) §164.314 BAA organizational requirements + §164.318 Reporting (annual + 60-day breach) + §164.410 Business Associate Notification Reg (EU) 2024/1689 Art. 51–55 + Annex XI / NIST SP 800-53 Rev 5 SR-1 SR-3 SR-6 MA-2 IR-6 / 45 CFR §164.314 / §164.318 / §164.410

Pair this crosswalk with the six pillar references below. Each row can be lifted wholesale into an EU AI Act Article 9–15 evidence cell, an Annex IV technical-documentation section, a NIST AI RMF 1.0 Target Profile cell, an ISO/IEC 42001 Annex A control evidence row, a GDPR Article 22 automated-decision-making cell, or a SOC 2 CC6 logical-access cell — plus the four primary-source families the roadmap item mandates: NIST CSF 2.0 Function/Category/Subcategory binding, NIST SP 800-53 Rev 5 control families (AC/AT/AU/CM/IA/IR/MA/MP/PE/PL/PS/RA/SA/SC/SI/SR), HIPAA Security Rule 45 CFR §164.302-318, and AICPA TSC CC1-CC9 (2022).

§9 Frequently Asked Questions

What is the EU AI Act and which of the four risk tiers applies to my company?
ComplianceStack tracks the EU AI Act (Regulation (EU) 2024/1689, entered into force August 1, 2024) as the world’s first horizontal AI regulation. The Act organizes AI systems into four risk tiers tied to the use case and the data subject affected. Tier 1 — Unacceptable Risk (Prohibited, Art. 5): subliminal manipulation beyond a person’s consciousness, exploitation of vulnerabilities of specific groups, social scoring by public authorities, real-time remote biometric identification in publicly accessible spaces for law enforcement, predictive policing based solely on profiling, untargeted scraping of facial images, emotion recognition in the workplace or in education, biometric categorization inferring sensitive attributes. Tier 2 — High Risk (Art. 6 + Annex III): biometric ID, critical infrastructure, education / vocational training, employment / worker management, essential private and public services, law enforcement, migration / asylum / border control, administration of justice and democratic processes — plus the Annex I product-safety AI components (medical devices, machinery, etc.). Tier 3 — Limited Risk (Art. 50 transparency obligations): chatbot disclosure, AI-generated content labeling, deepfake disclosure, emotion recognition notification. Tier 4 — Minimal Risk (no mandatory requirements): most consumer AI tooling. ComplianceStack tracks each EU Member State DPA designation (Germany BNetzA, France ARCOM/CNIL, Netherlands RDI, Spain AESIA, Italy AgId/AGCOM, Ireland CCPC) and pairs each compliance obligation with the responsible national authority.
When does EU AI Act enforcement begin for high-risk AI systems and what is the August 2, 2026 deadline?
ComplianceStack tracks the EU AI Act enforcement timeline under Article 113 and the May 7, 2026 AI Omnibus provisional deal. The phased enforcement schedule: (1) February 2, 2025 — Prohibited Art. 5 practices and Art. 4 AI literacy enforcement began. (2) August 2, 2025 — GPAI model obligations under Chapter V (Art. 51–55) enforcement began. (3) August 2, 2026 — Originally the Annex III high-risk-system enforcement date PLUS Art. 50 transparency obligation enforcement; the AI Omnibus deferred the Annex III high-risk enforcement 16 months to December 2, 2027. (4) The Annex I product-safety high-risk enforcement date moved to August 2, 2028. (5) New NCII / nudifier ban effective December 2, 2026. (6) Watermarking / content marking moved to December 2, 2026. (7) National sandbox deadline extended to August 2027; new EU-level sandbox created with SME / start-up priority. The August 2, 2026 Art. 50 transparency obligations remain unchanged — chatbot disclosure, AI-generated content labeling, deepfake disclosure. ComplianceStack pairs the August 2, 2026 Art. 50 transparency deadline with the September-October 2026 Commission Code of Practice consultation close and the December 2, 2027 deferred high-risk-system deadline so the 14-month window between is the readiness runway for the Annex IV / Annex VII conformity assessment work.
What are the GPAI and GPAI-systemic-risk obligations under Articles 51–55?
ComplianceStack tracks the GPAI (general-purpose AI) model provider obligations under Art. 51 (downstream provider transparency — provide downstream integrators with information on model capability / limitation / risks), Art. 52 (technical documentation per Annex XI maintainable for 10 years), Art. 53 (downstream AI system provider cooperation — the integration tier can’t escape responsibility), Art. 54 (authorization for systemic-risk GPAI models above the 10^25 FLOPs training-compute threshold), and Art. 55 (serious-incident reporting to the AI Office within 15 days of becoming aware). Systemic-risk classification triggers at 10^25 FLOPs training-compute under Art. 51. Member State DPAs designated under the Act’s NCA listings plus the Commission AI Office (a centralized enforcement body inside DG CONNECT). The Commission Code of Practice on AI-generated content (consultation open from May 2026 — closing October 2, 2026) sets the practical transparency obligations under Art. 50: chatbot disclosure, deepfake labeling, emotion-recognition notification, AI-generated content marking. ComplianceStack pairs every GPAI provider obligation with the specific Art. 51 / 52 / 53 / 54 / 55 citation and pairs the 10-year Annex XI document retention with the standard practice for high-cap ML model vendors.
How does ComplianceStack build a 90-day EU AI Act gap-checklist ready for the August 2, 2026 / December 2, 2027 high-risk enforcement?
ComplianceStack packages the EU AI Act readiness program as a 90-day gap checklist mapped to the eight Articles 9–15 high-risk obligations and the Article 51–55 GPAI obligations. Day 0–14 covers Article 9 risk-management system + Article 10 data-governance: AI system register established across every EU deployment, Annex III classification decision documented per AI system, training / validation / testing data provenance with bias examination, FAIR-Data-aligned dataset documentation, data-quality review. Day 15–30 covers Article 11 technical documentation + Article 12 record-keeping: technical documentation per Annex IV with system description, design choices, capabilities / limitations, intended purposes, risk-management measures, post-market monitoring plan; automatic logging over the system lifetime with traceability, technical robustness, preventability-of-harm attributes. Day 31–45 covers Article 13 transparency + Article 14 human oversight: instructions for use that are concise, complete, correct, and clear; human oversight measures (effective / interactive / understood). Day 46–60 covers Article 15 accuracy / robustness / cybersecurity: AI-system levels defined across accuracy, robustness (resilience to errors / faults / inconsistencies), cybersecurity (resilience to adversarial attacks as defined in Recital 96 / Annex IV). Day 61–90 covers Annex IV self-assessment submission preparation + Annex VII Notified Body engagement (only for biometric ID and Annex I products with a safety component) + Article 72 post-market monitoring plan + Article 73 serious-incident reporting procedure aligned to the 15-day AI Office notification window.
How does ComplianceStack build a 2026 EU AI Act readiness roadmap for SaaS / GTM AI / GPAI providers?
ComplianceStack builds three sector-specific 2026 EU AI Act readiness roadmaps stacked against the August 2, 2026 Art. 50 transparency deadline and the December 2, 2027 deferred high-risk-system deadline. Pattern 1 — SaaS deploying AI systems to EU users with high-risk classification under Annex III: full Annex IV technical documentation; risk-management system per Art. 9; data governance per Art. 10; transparency per Art. 13; CE marking alignment; 90-day program covers all eight Articles 9–15 obligations. Pattern 2 — GTM / Sales AI deployers (chatbot, deepfake, AI-generated content, emotion recognition): Article 50 transparency obligations only — chatbot user disclosure (user knows they’re talking to an AI), AI-generated content labeling, emotion-recognition notification, deepfake disclosure; no Annex IV / Annex VII conformity assessment required; 30-day program covers the Art. 50 implementation and the Code of Practice orientation. Pattern 3 — GPAI providers (foundation-model providers above the 10^25 FLOPs threshold): Art. 51–55 obligations — model evaluation, adversarial testing, cybersecurity, serious-incident reporting to AI Office within 15 days; 10-year Annex XI technical documentation; Downstream integration support obligations under Art. 53. ComplianceStack pairs all three patterns with the conformity-assessment-path selector and the Member State DPA designation matrix.
How does ComplianceStack run an EU AI Act risk classification for an AI system?
ComplianceStack runs an EU AI Act risk classification in two passes that mirror the four-tier taxonomy. First, the ComplianceStack EU AI Act risk report at compliancestack.ai/eu-ai-act-report (no signup, no email required, results in under 60 seconds; $19 paid deliverable adds PDF + interactive dashboard) scores every AI system in scope against the Article 5 prohibited list and the Annex III high-risk list; classifies by tier (Prohibited / High-risk / Limited-risk / Minimal-risk); and surfaces the most-cited Article 9–15 deficiency categories — missing risk-management system under Art. 9, missing training-data bias examination under Art. 10, missing Annex IV technical documentation under Art. 11, missing automatic logging under Art. 12, missing human-oversight measures under Art. 14, missing adversarial-attack resilience under Art. 15. Second, the ComplianceStack deep EU AI Act audit at compliancestack.ai/eu-ai-act-audit ($199 deliverable, multi-framework, runs EU AI Act alongside the GDPR Article 22 automated-decision overlap, NIST AI RMF 1.0 GOVERN/MAP/MEASURE/MANAGE, SOC 2 CC6, ISO/IEC 42001 Annex A) produces a prioritized 8-obligation gap remediation backlog with conformity-path selection (Annex IV self / Annex VII Notified Body / Art. 48 Presumed Conformity), 90-day Art. 9–15 implementation timeline, CE marking alignment deliverable, and an Article 99 Penalty Exposure Estimate across the three penalty tiers.
How do the EU AI Act Articles 9–15 map to NIST AI RMF 1.0, ISO/IEC 42001, GDPR Art. 22, and SOC 2 CC6?
ComplianceStack maintains an EU AI Act framework crosswalk that pairs every Article 9–15 high-risk obligation with its NIST AI RMF 1.0 function counterpart, its ISO/IEC 42001:2023 Annex A control, its GDPR Art. 22 automated-decision overlap, and its SOC 2 CC6 logical-access cell. Article 9 (risk-management across full lifecycle) maps to NIST AI RMF GOVERN-1.1/1.2/2.1/2.2 + ISO/IEC 42001 A.5.1 + A.5.7 + SOC 2 CC1.1 + CC3.1. Article 10 (data governance + training / validation / testing sets + bias examination) maps to NIST AI RMF MAP-1.1/1.2/1.3 + MEASURE-2.1/2.2/2.3 + ISO/IEC 42001 A.6.2/A.6.3 + GDPR Art. 22(1) profiling logic + SOC 2 P1.1/P2.1. Article 11 (Annex IV technical documentation) maps to NIST AI RMF GOVERN-4.1 + ISO/IEC 42001 A.7.5 + SOC 2 CC2.1/CC2.3. Article 12 (automatic logging over system lifetime) maps to NIST AI RMF MANAGE-4.1/4.2 + ISO/IEC 42001 A.8.4 + SOC 2 CC7.1/CC7.2. Article 13 (transparency to deployers) maps to NIST AI RMF GOVERN-2.3 + ISO/IEC 42001 A.5.8 + GDPR Art. 13/14 transparency + SOC 2 CC2.2. Article 14 (human oversight — effective / interactive / understood) maps to NIST AI RMF GOVERN-3.1 + MANAGE-1.1/1.2/1.3 + ISO/IEC 42001 A.5.10/A.5.11 + SOC 2 CC1.4. Article 15 (accuracy / robustness / cybersecurity) maps to NIST AI RMF MEASURE-1.1/1.2 + MANAGE-2.1 + ISO/IEC 42001 A.8.7/A.8.8 + SOC 2 CC6.6/CC7.3. ComplianceStack pairs the crosswalk table with outbound pillar links to /pillar/gdpr + /pillar/soc2 so a single Art. 10 data-governance evidence cell resolves to its NIST AI RMF MEASURE-2.3 row, its GDPR Art. 22 decision-automated cell, and its SOC 2 CC6 logical-access cell in the same deliverable.
How does the EU AI Act map to NIST CSF 2.0, NIST SP 800-53 Rev 5, HIPAA §164.302-318, and SOC 2 TSC CC1–CC9?
ComplianceStack extends the EU AI Act §8a framework crosswalk with the four primary-source families the roadmap item mandates. Article 9 (risk-management) maps to NIST CSF 2.0 GV.RM-01 / GV.RM-04 + ID.RA-01 / ID.RA-04, NIST SP 800-53 Rev 5 RA-3 (Risk Assessment) + PM-9 (Risk Management Strategy), HIPAA 45 CFR §164.308(a)(1)(ii)(A) Risk Analysis + §164.308(a)(1)(ii)(B) Risk Management, and AICPA TSC CC1.1 + CC2.3 + CC3.1 + CC3.2 (2022). Article 10 (data governance + bias examination) maps to NIST CSF 2.0 ID.AM-05 / ID.AM-07 + PR.DS-01 + PR.IP-06, NIST SP 800-53 Rev 5 AC-16 (Security Attributes) + SI-7 (Software / Firmware Integrity) + SR-4 (Provenance), HIPAA §164.502 Uses / Disclosures of PHI + §164.514 de-identification standard + §164.308(a)(6) Security Incident Procedures, and AICPA TSC CC2.1 + P1.1 + P2.1 + P3.5 (Privacy). Article 11 (Annex IV technical documentation) maps to NIST CSF 2.0 GV.OV-01 / GV.OV-03 + ID.IM-04, NIST SP 800-53 Rev 5 PL-4 (Plan of Action and Milestones) + SA-15 (Development Process / Standards), HIPAA §164.316(b)(1) Documentation retention (6 years) + §164.316(b)(2) Availability of documentation, and AICPA TSC CC2.1 + CC2.3 + CC4.1. Article 12 (automatic logging) maps to NIST CSF 2.0 DE.CM-01 / DE.CM-03 / DE.CM-09 + PR.PT-01, NIST SP 800-53 Rev 5 AU-2 (Audit Events) + AU-9 (Protection of Audit Info) + AU-12 (Audit Record Generation), HIPAA §164.312(b) Audit Controls + §164.316(b)(2)(i) Hardware / Software / Procedural mechanisms, and AICPA TSC CC7.1 + CC7.2 + CC7.3 + CC7.5. Article 15 (accuracy / robustness / cybersecurity) maps to NIST CSF 2.0 PR.AC-01 / PR.AC-04 + PR.DS-01 / PR.DS-02 + DE.CM-01 + RS.MI-01, NIST SP 800-53 Rev 5 SC-5 (Denial of Service Protection) + SC-28 (Protection of Information at Rest) + SI-3 (Malicious Code Protection) + IR-4 (Incident Handling), HIPAA §164.312(a)(2)(iv) Encryption & decryption + §164.312(e)(2)(ii) Transmission encryption + §164.402(2) Encryption safe-harbor presumption, and AICPA TSC CC6.6 + CC7.1 + CC7.3 + CC7.4 + A1.2 (Availability). ComplianceStack pairs every row of the §8a crosswalk with outbound pillar links to /pillar/nist-csf, /pillar/hipaa-security-privacy, /pillar/cmmc, /pillar/pci-dss, /pillar/gdpr, and /pillar/soc2 so a single Art. 15 accuracy / cybersecurity evidence cell resolves to its NIST CSF 2.0 PR.AC-01 / PR.DS-01 counterpart, its NIST SP 800-53 Rev 5 SC-28 cell, its §164.312(a)(2)(iv) HIPAA encryption safeguard, and its SOC 2 CC6.6 logical-access counterpart in the same deliverable.