AI Act

EU AI Act obligations and what they mean for model and infrastructure choices. Serves buyers mapping regulation to their AI stack.

16 articles

Articles

25 April 2026

EU AI Act Infrastructure Requirements: Deadlines and Duties After the AI Omnibus

European AI teams face a critical regulatory shift. While the initial bans on prohibited practices took effect on 2 February 2025, 2 August 2026 is the date the Regulation applies in general and the date the Commission gains its power to fine general-purpose AI model providers under Article 101. The AI Omnibus, in force since 27 July 2026, then moved the Chapter III obligations for Annex III high-risk systems to 2 December 2027, and high-risk systems captured by Article 6(1), AI systems that are, or are safety components of, products covered by the EU product legislation listed in Annex I, to 2 August 2028. For teams building in sectors like healthcare, critical infrastructure, or employment, the Act requires evidence about the AI system and its operation. The necessary controls depend on the system and the provider's or deployer's role, rather than on a particular cloud architecture. Initial compliance work for a single high-risk system is a material cost line, and ongoing monitoring adds operational overhead on top of it. Moving beyond the 'move fast and break things' era, engineering teams must now treat compliance as a core component of their technical stack.

25 September 2026

Tamper-Evident AI Audit Trails: Hash Chains and Retention

A tamper-evident audit trail ensures any alteration to inference records is mathematically detectable. By building hash-chained logs over metadata and HMAC-SHA-256 digests in the application layer, you can prove system integrity without violating data retention limits.

25 September 2026

Article 50 AI Act: Marking Outputs with C2PA & SynthID

Article 50 of the EU AI Act imposes strict transparency obligations on generative media, splitting machine-readable marking from visible disclosure. Here is how C2PA, SynthID, and embedded metadata satisfy the rule, and why compliance is a pipeline decision you must own.

25 September 2026

Provider or Deployer? AI Act Roles for Inference Engines

For teams building on a third-party inference engine, EU AI Act compliance starts with a counterintuitive fact: you are likely both a deployer of the upstream models and the provider of the AI system you ship.

24 September 2026

Is Your AI System High-Risk? A Decision Tree Through Annex III

Classifying your AI system under the EU AI Act is a rigid decision tree, not a judgement call. This guide maps out the Annex I and Annex III routes, breaking down the 4 conditions for derogation to give engineering teams a definitive exit state and compliance timeline.

22 September 2026

Does Fine-Tuning Make You a GPAI Provider?

Engineering teams worry fine-tuning an open-source model might classify them as a GPAI provider under the EU AI Act. By calculating compute against the Commission’s one-third threshold, you can prove your workload remains safely outside the scope.

23 September 2026

EU AI Act for Developers: A Practical Compliance Checklist (2026)

The EU AI Act assigns strict technical duties based on your role, but reading the legislation isn't practical. This routing hub indexes exactly which compliance obligations apply to your engineering team and links to the specific technical guides for implementation.

21 September 2026

Annex IV Technical Documentation: The ML Team Checklist

Annex IV of the EU AI Act turns technical documentation into a strict legal requirement for high-risk AI systems. This guide translates the 9 mandatory legal points into a concrete checklist for ML engineering teams.

21 September 2026

Do You Need a DPIA for LLM Inference? A Deployer's Guide

Before shipping an LLM feature, you need to know if sending prompts to an API triggers a DPIA. This guide clarifies that the DPIA is a GDPR instrument, not an AI Act one, and maps exactly how to extract the 4 mandatory compliance inputs from your inference provider.

14 September 2026

AI Act Article 26: Deployer Logging & 6-Month Retention Explained

For high-risk AI deployers, Article 26(6) requires keeping system logs for at least six months. When using a zero-retention API, the provider stores nothing, meaning this logging capability must be built entirely within your own application.

14 June 2026

GDPR and EU AI Act Overlap: Technical Guide for AI Infrastructure

Securing personal data is no longer enough. Engineering teams must now architect their machine learning pipelines to meet stringent product safety and risk management standards.

13 June 2026

EU AI Act High Risk System Classification Guide

The EU AI Act introduces strict obligations for high risk AI systems, with penalties reaching 15 million euros. Engineering teams must understand classification rules and infrastructure requirements to avoid regulatory roadblocks.

13 June 2026

EU AI Act Prohibited AI Systems Checklist for Engineering Teams

The grace period for unacceptable risk AI systems ended on February 2, 2025. Engineering teams running models that breach the Article 5 prohibitions now face fines up to €35 million or 7% of global turnover, whichever is higher.

12 June 2026

EU AI Act Compliance Timeline: Navigating the August 2026 Deadlines

August 2026 remains a hard deadline for transparency, GPAI enforcement, and data governance. Engineering teams must secure their infrastructure now to avoid severe penalties.

12 June 2026

EU AI Act Foundation Model Obligations 2026: A Technical Guide

The grace period is ending. By August 2026, the European Commission will actively enforce compliance for foundation models, turning data residency and infrastructure choices into critical engineering constraints.

11 June 2026

EU AI Act Conformity Assessment: The GPU Infrastructure Guide

The high-risk deadlines now fall on 2 December 2027 and 2 August 2028. Your conformity assessment will fail if your underlying GPU infrastructure cannot prove data sovereignty, logging traceability, and strict access controls.

Your next workload starts here