AI Act · Regulation (EU) 2024/1689

AI Act compliance for companies: transparency in 2026 and high-risk rules in 2027/2028.

System inventory, risk classification, internal policy, training, transparency and evidence folder before an inspection, audit or incident.

Current text of Regulation (EU) 2024/1689: view on EUR-Lex. Digital Omnibus reform: adopted and signed final act, awaiting publication in the Official Journal.

Next milestone: Article 50 transparency 2 August 2026 ... days to go Start with the Express Diagnosis (€350)
Who it applies to

If your company does any of these things, the AI Act applies to you.

The AI Act applies in phases. AI literacy and prohibited practices have applied since 2 February 2025; Article 50 transparency and much of the general regime apply from 2 August 2026. The specific duties depend on the company's role: provider, deployer, importer or distributor.

You use AI day to day

ChatGPT, Copilot, Gemini, Claude and assistants built into your CRM, invoicing or customer support. Even if AI is used only for drafting, you must support AI literacy and control data; transparency is required when the use falls within Article 50.

You have a customer-facing chatbot, assistant or AI

Website, WhatsApp, automated answering systems and assistants that recommend products. Article 50 requires people to know when they are interacting directly with AI unless this is obvious; the precise duty depends on whether you act as provider or deployer.

You make decisions about people with AI

CV screening, creditworthiness scoring, employee evaluation, insurance, biometrics, education. These are Annex III areas: high risk, with reinforced obligations.

You generate AI content and publish it

Images, videos, synthetic voices and deepfakes. Providers must add machine-readable marking; deployers must disclose deepfakes and certain public-interest content, among the other cases listed in Article 50.

The 4 risk categories

What the AI Act requires of you depending on your AI system's risk

The Regulation classifies AI systems into four levels. Your obligations, and your exposure to penalties, depend on which one each use falls into. This is the basis of every diagnosis.

Risk levelExamplesWhat it requires of you
Unacceptable risk
Prohibited · art. 5
Subliminal manipulation, social scoring, emotion recognition at work or in education, mass scraping of faces.Prohibited since 2 February 2025. Fines of up to €35M or 7% of worldwide turnover.
High risk
Annex III
Staff recruitment, employee evaluation, credit scoring, life or health insurance, biometrics, education, essential services, justice.Risk management, data quality, technical documentation, human oversight, log keeping and conformity assessment. The final Digital Omnibus act sets application from 2 December 2027 for Annex III.
Transparency risk
Art. 50
Customer-facing chatbots, AI-generated content, deepfakes, synthetic voices.From 2 August 2026: providers must enable notices and technical marking; deployers must inform people in the uses listed in Article 50.
Minimal riskAI for drafting, translating, summarising, basic filters or recommenders.No specific product obligations, but staff AI literacy (art. 4) and data control in line with the GDPR are required.

Not sure which category your systems fall into? That's exactly what the Express Diagnosis resolves.

Application timeline

Key AI Act dates

Legislative status: the final Digital Omnibus act was signed on 8 July 2026 and the official procedure file still shows it as awaiting publication in the Official Journal. The 2026-2028 dates below are those in the adopted final text; the reform will enter into force on the third day after publication.

  1. 1 Aug 2024Regulation (EU) 2024/1689 enters into force.
  2. 2 Feb 2025AI literacy (art. 4) and prohibited practices (art. 5).
  3. 2 Aug 2025Obligations for general-purpose AI models (GPAI) and governance.
  4. 2 Aug 2026General application and Article 50 transparency obligations; high-risk rules have separate later dates.
  5. 2 Dec 2026Generative systems placed on the market before 2 August must comply with the technical marking duty in Article 50(2). New prohibitions on non-consensual intimate content and child sexual abuse material also apply.
  6. 2 Dec 2027Annex III high-risk AI systems under the final Digital Omnibus act.
  7. 2 Aug 2028Annex I high-risk AI systems embedded in regulated products under the final Digital Omnibus act.
Why it matters

Real fines, a softer rule for SMEs.

The penalty regime (Articles 99-101 of the AI Act) provides for fines of up to €35M or 7% of worldwide turnover for using AI in prohibited practices, up to €15M or 3% for breaching general obligations, and up to €7.5M or 1% for incorrect information to the authorities. For freelancers and SMEs, Article 99(6) applies the lower amount, not the higher one, but the penalty is still proportional to turnover, and the risk is usually compounded by a GDPR breach that the AEPD penalises separately.

How we work

From diagnosis to a sustainable compliance system.

1Diagnosis

Mapping the AI systems in use, classifying them under Annex III, identifying the role (deployer or provider) and detecting prohibited or high-risk practices.

2Gap analysis

Analysing the applicable obligations and comparing them with the current situation: policies, training, transparency, data control, human oversight and evidence.

3Documentation

Internal AI-use policy, literacy plan, transparency templates for chatbots and synthetic content, provider register and a risk-assessment model.

4Rollout and training

Staff training session (AI literacy, art. 4), implementation of controls, provider review and internal sign-off of the policy.

5Ongoing governance

Annual review, updates in response to regulatory changes, support for specific cases and response to incidents or requests from the AESIA or the AEPD.

Why with a forensic expert witness

The same professional who brings your AI into compliance can defend the evidence before the AESIA or a court.

Your AI Act compliance is signed off by Manuel Navarro Rajoy, DPD/DPO certified by the AEPD (registration A2025166DPD) and Forensic IT Expert Witness TIP 639 AEPEJU. It is not just documentation: if an AESIA or AEPD inspection, a formal request or litigation over an algorithmic decision arrives, you have the very expert who analysed your system preparing and ratifying the forensic evidence. That is the difference between an agency that fills in templates and a professional who upholds your compliance before whoever challenges it.

See forensic IT reports
Plans

Four models depending on the size of the organisation and actual AI use

The amounts are indicative and are finalised after the initial assessment. The final invoice depends on the number of AI systems involved, the risk level and how much prior documentation already exists.

VAT not included. First assessment free within 24 business hours.

Express Diagnosis

For freelancers and micro-businesses with light AI use

€350one-off payment

  • Initial inventory of AI tools
  • Risk classification (deployer / Annex III)
  • Executive report with priorities
  • Recommendations to start documenting
Request diagnosis

Comprehensive Compliance

For companies with extensive use or high-risk systems

€2,400 - €5,500one-off payment

  • Everything in Basic Compliance
  • Analysis of providers and integrations
  • Impact assessment for high-risk systems
  • Design of human oversight and log keeping
  • Coordination with the DPO/CISO/Legal team
  • Executive report for management
Request comprehensive compliance

Ongoing Governance

Permanent maintenance and support

From €240per month (annual commitment)

  • Half-yearly review of inventory and risks
  • Policy updates in response to regulatory changes
  • Support for specific cases by email/phone
  • Response to incidents or AESIA/AEPD requests
  • Annual staff training
Activate ongoing governance
Deliverables

Documentation that stands up to an inspection.

AI inventory

A list of systems, tools, providers, data processed, purpose and the company's role.

Internal policy

A document signed by staff covering usage rules, prohibited data, oversight and review.

Risk assessment

A per-system matrix with classification (prohibited, high risk, transparency, low risk) and obligations.

Transparency templates

Wording for chatbots, AI-generated content, deepfakes and notices to customers and workers.

Training plan

Materials and an attendance record to demonstrate the AI literacy required by Article 4.

Evidence folder

A file structure ready to hand over to an authority or auditor upon request.

Frequently asked questions

Frequently asked questions

What kind of projects need AI Act adaptation?

Especially those where AI is involved in sensitive processes, automated decisions, video surveillance or activities with significant impact on people and business.

Is the adaptation only documentary?

No. The documentary part is important, but must be aligned with controls, owners and real governance of the system.

Can it integrate with privacy and security?

Yes. In fact, AI Act, GDPR, cybersecurity and data management usually need to be coordinated so the system is sustainable.

How much does it cost to adapt my business to the AI Act?

It depends on your size and on how much you actually use AI. For freelancers and micro-SMEs with light use we offer an Express Diagnosis for €350. For SMEs with regular use, Basic Compliance from €980. For companies with high-risk systems, Full Adaptation from €2,400. Continuous governance starts at €240/month with an annual commitment. First assessment free within 24 h.

Do you coordinate the AI Act with GDPR and cybersecurity?

Yes. Most AI systems process personal data (GDPR) or run on critical infrastructure (cybersecurity). The service is coordinated internally with external DPO, GDPR audit and ENS / ISO 27001 so the company has a single point of contact instead of several providers that do not talk to each other.

What happens when all the obligations come into force?

The timeline is public. AI literacy and prohibited practices took effect on 2 February 2025, general-purpose AI model rules on 2 August 2025 and Article 50 transparency obligations on 2 August 2026. The final Digital Omnibus act, adopted and signed but still awaiting publication in the Official Journal, sets 2 December 2026 for certain transitional marking duties and new prohibited practices, 2 December 2027 for Annex III high-risk AI and 2 August 2028 for Annex I high-risk AI embedded in products. AESIA is the national supervisory authority, without prejudice to the AEPD's powers when personal data is involved.

Direct contact

If your company already uses AI, getting compliance in order now is worth more than reacting later.

Tell me which AI systems you use, in which processes and with what data. I prepare a free initial assessment within 24 business hours, with scope, plan and a fixed price before any work begins.

WhatsApp