EU regulation
EU AI Act: what applies when, and what it asks of product teams
The EU AI Act, Regulation (EU) 2024/1689, is the EU's risk-based law on artificial intelligence. It entered into force on 1 August 2024 and applies in stages; after an amendment adopted in July 2026, the rules for high-risk AI systems apply from 2 December 2027 for the uses listed in Annex III and from 2 August 2028 for AI in products covered by Annex I.
Free plan, no card required.
When does the EU AI Act apply?
Article 113 sets the dates. The regulation was published in the Official Journal on 12 July 2024, entered into force on 1 August 2024 and has a general date of application of 2 August 2026, with some parts earlier and some later. Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026, moved the dates for high-risk AI systems and added two prohibitions.
The original text applied the Annex III high-risk rules from 2 August 2026 and the Annex I product rules from 2 August 2027. The extra time is not a pause: the prohibitions, AI literacy, the general-purpose AI model rules and the transparency obligations already apply.
| Date | What applies |
|---|---|
| 1 August 2024 | Entry into force |
| 2 February 2025 | General provisions, including AI literacy (Article 4), and the prohibited practices (Article 5) |
| 2 August 2025 | Obligations for general-purpose AI models, governance, notified bodies and most penalty provisions |
| 2 August 2026 | General date of application, including the transparency obligations in Article 50 |
| 2 December 2026 | New prohibitions on AI systems that generate non-consensual intimate imagery or child sexual abuse material; Article 50(2) marking for generative systems placed on the market before 2 August 2026 |
| 2 December 2027 | High-risk AI systems in the areas listed in Annex III |
| 2 August 2028 | High-risk AI systems under Article 6(1): safety components of products covered by Annex I, or such products themselves |
What are the EU AI Act's risk categories?
The European Commission describes four levels. Unacceptable-risk practices are banned by Article 5, for example harmful social scoring, untargeted scraping of facial images for recognition databases, and inferring emotions at work or in education except for medical or safety reasons. High-risk systems are allowed but regulated. Transparency-risk systems, such as chatbots and generators of synthetic content, carry disclosure and marking duties. The rest is minimal or no risk.
Under Article 6, an AI system is high-risk if it is a safety component of a product, or itself a product, covered by the EU legislation in Annex I, such as toys, lifts, radio equipment or medical devices, that needs a third-party conformity assessment; or if it is used in an Annex III area such as biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration or justice. An Annex III system that meets the conditions of Article 6(3) can fall outside, but the provider must document that assessment.
What do providers of high-risk AI systems have to do?
A provider places an AI system on the market or puts it into service under its own name; a deployer uses one under its authority in a professional context. Providers of high-risk systems must meet the requirements below and, under Article 16, run a quality management system, complete a conformity assessment, draw up an EU declaration of conformity, affix the CE marking and, for most Annex III systems, register in the EU database.
Article 15 is where security teams come in. High-risk AI systems must be resilient against attempts by unauthorised third parties to alter their use, outputs or performance by exploiting system vulnerabilities. Where appropriate, the measures must address AI-specific attacks: data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and model flaws. In practice, the software around the model is part of that attack surface.
- A risk management system across the lifecycle (Article 9).
- Data and data governance for training, validation and testing data (Article 10).
- Technical documentation (Article 11).
- Record-keeping through automatically generated logs (Article 12).
- Transparency and information for deployers (Article 13).
- Human oversight (Article 14).
- Accuracy, robustness and cybersecurity (Article 15).
How does the EU AI Act relate to the Cyber Resilience Act?
Many AI products are also products with digital elements under the Cyber Resilience Act (CRA), Regulation (EU) 2024/2847. Its Article 12 provides that such a product classified as a high-risk AI system is deemed to meet the cybersecurity requirements of Article 15 of the AI Act where it fulfils the essential requirements in Annex I Part I of the CRA, the manufacturer's processes meet Annex I Part II, and this is demonstrated in the EU declaration of conformity issued under the CRA. The 2026 amendment added the same rule to the AI Act as Article 42(3).
The AI Act's conformity assessment procedure then generally applies, with exceptions in Article 12(3) of the CRA for certain important and critical products. The timelines differ: CRA reporting has applied since 11 September 2026 and most other CRA obligations apply from 11 December 2027, while the AI Act's high-risk rules apply from 2 December 2027 or 2 August 2028.
What are the fines under the EU AI Act?
Article 99 sets maximum administrative fines, which Member States enforce. For each tier, the maximum is the fixed amount or the share of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs, including start-ups, it is whichever is lower, and since the 2026 amendment the same applies to small mid-cap enterprises for the second and third tiers.
| Infringement | Maximum fine |
|---|---|
| Prohibited AI practices (Article 5) | EUR 35 million or 7% of worldwide annual turnover |
| Obligations of providers, authorised representatives, importers, distributors, deployers and notified bodies, and the transparency obligations (Article 50) | EUR 15 million or 3% |
| Incorrect, incomplete or misleading information to notified bodies or national competent authorities | EUR 7.5 million or 1% |
How should an AI product team prepare?
Start with an inventory of the AI systems and general-purpose AI models you build, buy or use, and record for each your role (provider, deployer, importer or distributor), its intended purpose, and whether it touches a prohibited practice, an Annex III area or an Annex I product. Cover what already applies: AI literacy, the prohibitions and transparency. For systems that may be high-risk, use the time before the 2027 and 2028 dates to build the evidence Articles 9 to 15 ask for, starting with what also serves the CRA: a component inventory, vulnerability handling and security testing.
Available in KROMSE today
KROMSE is not an EU AI Act tool today; it covers the software security of an AI product.
- Checks the dependencies of your AI product against OSV.dev and flags packages listed in the OpenSSF Malicious Packages database.
- Source analysis for 11 languages, and secrets detection in the code at the scanned commit.
- Exports a CycloneDX JSON and an SPDX JSON SBOM for every scan.
- A CRA readiness view from the latest scan and, on paid plans, CRA Article 14 report drafts that a person approves and submits; KROMSE never submits them.
Coming next
On the roadmap, not available yet. Dates are targets, not promises; this page changes the day a capability is live.
- Coming · Q1 2027 (January)EU AI Act module. An EU AI Act module will add an inventory of AI systems, risk classification and documentation for a person to complete.
- Coming · Q1 2027AI agent and model security. KROMSE will produce an AI bill of materials, review the tools and permissions your agents can use, and detect unsafe model files.
Frequently asked questions
When does the EU AI Act apply?
It entered into force on 1 August 2024. Prohibitions and AI literacy have applied since 2 February 2025, obligations for general-purpose AI models since 2 August 2025 and most other rules since 2 August 2026. Under Regulation (EU) 2026/1744, the high-risk rules apply from 2 December 2027 for Annex III uses and from 2 August 2028 for AI in Annex I products.
Did the Digital Omnibus delay the EU AI Act?
In part. Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products, and added prohibitions that apply from 2 December 2026. The general date of 2 August 2026, the prohibitions already in force and the general-purpose AI model rules were not postponed.
Does the EU AI Act apply to companies outside the EU?
Often, yes. Article 2 covers providers that place AI systems or general-purpose AI models on the EU market wherever they are established, and providers and deployers outside the EU where the output of the AI system is used in the EU. Importers, distributors and product manufacturers that place an AI system on the market with their product are covered too.
Is an AI product also covered by the Cyber Resilience Act?
It can be. The CRA covers products with digital elements, and its Article 12 deals with those that are also high-risk AI systems: meeting the CRA's essential requirements, demonstrated in the EU declaration of conformity, counts as meeting the cybersecurity requirements of Article 15 of the AI Act. Whether either law applies depends on the product.
Can KROMSE make my AI system compliant with the EU AI Act?
No. KROMSE does not classify AI systems, certify compliance or decide whether the AI Act applies. Today it scans the software of an AI product for known vulnerabilities, malicious packages and secrets, and exports SBOMs. An EU AI Act module is on the roadmap.