Home › Frameworks › EU AI Act

EU AI Act compliance software for high-risk AI providers and deployers.

The AI Act obligations as 27 recurring controls with evidence: prohibited practices, high-risk classification, technical documentation, human oversight, transparency, post-market monitoring and serious-incident reporting. Dates updated for the Digital Omnibus. EU-built, EU-hosted. Included in Enterprise, €499 a month.

At a glance

  • Article 5: Prohibited AI practices: subliminal manipulation, social scoring, real-time remote biometric ID with narrow exceptions.
  • Articles 6-15: High-risk AI requirements: risk management system, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy &…
  • Article 16-22: Provider obligations: quality management system, conformity assessment, EU declaration of conformity, CE marking, registration in the EU database.
  • Article 26-27: Deployer obligations: appropriate use, monitoring, logging, fundamental-rights impact assessment for some sectors.

On this page

  1. What is EU AI Act?
  2. When the AI Act applies
  3. Who needs to comply
  4. Key EU AI Act controls covered by Dazr
  5. What auditors look for
  6. How Dazr helps with EU AI Act

What is EU AI Act?

EU AI Act (Regulation (EU) 2024/1689). Providers and deployers of AI systems placed on the EU market: developers of general-purpose AI, providers of high-risk AI in safety, hiring, education, credit scoring, biometric ID, law enforcement, migration, justice, and any deployer using a high-risk AI in those sectors.

When the AI Act applies

As of 1 October 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved the high-risk deadlines; the earlier milestones stay as they were.

  • 2 February 2025: prohibited practices (Article 5).
  • 2 August 2025: obligations for general-purpose AI models.
  • 2 August 2026: most transparency obligations (Article 50), governance and penalties.
  • 2 December 2027: high-risk AI systems listed in Annex III (employment, education, credit, essential services, biometrics, critical infrastructure, law enforcement, migration, justice). Previously 2 August 2026.
  • 2 August 2028: high-risk AI that is a product or safety component under the Annex I harmonisation legislation. Previously 2 August 2027.

Sources: Regulation (EU) 2024/1689 on EUR-Lex and Regulation (EU) 2026/1744 on EUR-Lex. Read the AI Act timeline after the Digital Omnibus for what moved and why.

Who needs to comply

  • Providers of high-risk AI systems listed in Annex III (employment, education, credit, biometric ID, critical infrastructure, justice, migration)
  • Providers of general-purpose AI models, including those with systemic risk
  • Deployers of high-risk AI systems in their own operations
  • Importers and distributors of AI systems on the EU market
  • Public authorities deploying AI in regulated contexts

Key EU AI Act controls covered by Dazr

Article 5Prohibited AI practices: subliminal manipulation, social scoring, real-time remote biometric ID with narrow exceptions.
Articles 6-15High-risk AI requirements: risk management system, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy & robustness, cybersecurity.
Article 16-22Provider obligations: quality management system, conformity assessment, EU declaration of conformity, CE marking, registration in the EU database.
Article 26-27Deployer obligations: appropriate use, monitoring, logging, fundamental-rights impact assessment for some sectors.
Article 50Transparency obligations: notify users when interacting with AI, label deepfakes, mark synthetic content.
Article 72-73Post-market monitoring system and serious-incident reporting within 15 days (or 2-10 days for severe events).

What auditors look for

Market-surveillance authorities check three things: that you classified your system correctly (prohibited / high-risk / limited / minimal), that the technical documentation in Annex IV exists and is current, and that the post-market monitoring and serious-incident reporting (Article 73) actually runs. Dazr holds the evidence.

How Dazr helps with EU AI Act

Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. EU AI Act is one of its eleven frameworks, included in Enterprise, €499 a month. In practice that means:

  • Record the classification of each AI system you provide or deploy, with the reasoning, as evidence on the Article 6 control
  • Hold the Annex IV technical documentation links and refresh on cadence
  • Run the risk-management system as recurring controls per Article 9
  • Track post-market monitoring metrics and reviews per Article 72
  • Log serious incidents in the incident register with timestamps and authority case references, against the Article 73 deadlines
  • Hand the market-surveillance authority a single-PDF audit trail or read-only view

Back to the full Dazr Compliance overview › | Sign up free ›

EU AI Act questions, answered.

When does the AI Act actually apply?

The Regulation entered into force on 1 August 2024. The Article 5 prohibitions apply from 2 February 2025 and the obligations for general-purpose AI models from 2 August 2025. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) postponed the high-risk rules: high-risk systems listed in Annex III now apply from 2 December 2027, and AI in products covered by the Annex I harmonisation legislation from 2 August 2028. Most Article 50 transparency obligations were not postponed. As of 1 October 2026.

Are we a provider or a deployer?

Provider if you put an AI system on the EU market under your name or trademark. Deployer if you use one supplied by someone else under your authority. The obligations differ; Dazr lets you record the role per AI system.

Does Dazr classify our AI system for us?

No. Classification is a legal judgment based on Annex III and the system's intended purpose. Dazr lets you record the classification, the reasoning, and any change. We do not give legal advice.

Where is data hosted?

European Union only. Workspace records are encrypted at rest with AES-256-GCM at the application layer; uploaded evidence files rely on the storage provider's at-rest encryption. Italian entity, EU jurisdiction.

Ready to start your EU AI Act program?

EU AI Act is included in Enterprise (€499/mo, self-serve via Mollie, excl. VAT, cancel any time). Free and Basic cover ISO 27001, GDPR and NIS2; Pro adds NEN 7510, ISO 27701, ISO 22301 and SOC 2. Custom is the only tier on a contract, priced on request.