What is EU AI Act?
EU AI Act (Regulation (EU) 2024/1689). Providers and deployers of AI systems placed on the EU market: developers of general-purpose AI, providers of high-risk AI in safety, hiring, education, credit scoring, biometric ID, law enforcement, migration, justice, and any deployer using a high-risk AI in those sectors.
When the AI Act applies
As of 1 October 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved the high-risk deadlines; the earlier milestones stay as they were.
- 2 February 2025: prohibited practices (Article 5).
- 2 August 2025: obligations for general-purpose AI models.
- 2 August 2026: most transparency obligations (Article 50), governance and penalties.
- 2 December 2027: high-risk AI systems listed in Annex III (employment, education, credit, essential services, biometrics, critical infrastructure, law enforcement, migration, justice). Previously 2 August 2026.
- 2 August 2028: high-risk AI that is a product or safety component under the Annex I harmonisation legislation. Previously 2 August 2027.
Sources: Regulation (EU) 2024/1689 on EUR-Lex and Regulation (EU) 2026/1744 on EUR-Lex. Read the AI Act timeline after the Digital Omnibus for what moved and why.
Who needs to comply
- Providers of high-risk AI systems listed in Annex III (employment, education, credit, biometric ID, critical infrastructure, justice, migration)
- Providers of general-purpose AI models, including those with systemic risk
- Deployers of high-risk AI systems in their own operations
- Importers and distributors of AI systems on the EU market
- Public authorities deploying AI in regulated contexts
Key EU AI Act controls covered by Dazr
What auditors look for
Market-surveillance authorities check three things: that you classified your system correctly (prohibited / high-risk / limited / minimal), that the technical documentation in Annex IV exists and is current, and that the post-market monitoring and serious-incident reporting (Article 73) actually runs. Dazr holds the evidence.
How Dazr helps with EU AI Act
Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. EU AI Act is one of its eleven frameworks, included in Enterprise, €499 a month. In practice that means:
- Record the classification of each AI system you provide or deploy, with the reasoning, as evidence on the Article 6 control
- Hold the Annex IV technical documentation links and refresh on cadence
- Run the risk-management system as recurring controls per Article 9
- Track post-market monitoring metrics and reviews per Article 72
- Log serious incidents in the incident register with timestamps and authority case references, against the Article 73 deadlines
- Hand the market-surveillance authority a single-PDF audit trail or read-only view
Back to the full Dazr Compliance overview › | Sign up free ›