AI Act
EU AI Act obligations and what they mean for model and infrastructure choices. Serves buyers mapping regulation to their AI stack.
16 articles
Articles
25 April 2026
EU AI Act Infrastructure Requirements: Deadlines and Duties After the AI Omnibus
European AI teams face a critical regulatory shift. While the initial bans on prohibited practices took effect on 2 February 2025, 2 August 2026 is the date the Regulation applies in general and the date the Commission gains its power to fine general-purpose AI model providers under Article 101. The AI Omnibus, in force since 27 July 2026, then moved the Chapter III obligations for Annex III high-risk systems to 2 December 2027, and high-risk systems captured by Article 6(1), AI systems that are, or are safety components of, products covered by the EU product legislation listed in Annex I, to 2 August 2028. For teams building in sectors like healthcare, critical infrastructure, or employment, the Act requires evidence about the AI system and its operation. The necessary controls depend on the system and the provider's or deployer's role, rather than on a particular cloud architecture. Initial compliance work for a single high-risk system is a material cost line, and ongoing monitoring adds operational overhead on top of it. Moving beyond the 'move fast and break things' era, engineering teams must now treat compliance as a core component of their technical stack.
25 September 2026
Tamper-Evident AI Audit Trails: Hash Chains and Retention
A tamper-evident audit trail ensures any alteration to inference records is mathematically detectable. By building hash-chained logs over metadata and HMAC-SHA-256 digests in the application layer, you can prove system integrity without violating data retention limits.
25 September 2026
Article 50 AI Act: Marking Outputs with C2PA & SynthID
Article 50 of the EU AI Act imposes strict transparency obligations on generative media, splitting machine-readable marking from visible disclosure. Here is how C2PA, SynthID, and embedded metadata satisfy the rule, and why compliance is a pipeline decision you must own.
25 September 2026
Provider or Deployer? AI Act Roles for Inference Engines
For teams building on a third-party inference engine, EU AI Act compliance starts with a counterintuitive fact: you are likely both a deployer of the upstream models and the provider of the AI system you ship.
24 September 2026
Is Your AI System High-Risk? A Decision Tree Through Annex III
Classifying your AI system under the EU AI Act is a rigid decision tree, not a judgement call. This guide maps out the Annex I and Annex III routes, breaking down the 4 conditions for derogation to give engineering teams a definitive exit state and compliance timeline.
22 September 2026
Does Fine-Tuning Make You a GPAI Provider?
Engineering teams worry fine-tuning an open-source model might classify them as a GPAI provider under the EU AI Act. By calculating compute against the Commission’s one-third threshold, you can prove your workload remains safely outside the scope.
23 September 2026
EU AI Act for Developers: A Practical Compliance Checklist (2026)
The EU AI Act assigns strict technical duties based on your role, but reading the legislation isn't practical. This routing hub indexes exactly which compliance obligations apply to your engineering team and links to the specific technical guides for implementation.
21 September 2026
Annex IV Technical Documentation: The ML Team Checklist
Annex IV of the EU AI Act turns technical documentation into a strict legal requirement for high-risk AI systems. This guide translates the 9 mandatory legal points into a concrete checklist for ML engineering teams.
21 September 2026
Do You Need a DPIA for LLM Inference? A Deployer's Guide
Before shipping an LLM feature, you need to know if sending prompts to an API triggers a DPIA. This guide clarifies that the DPIA is a GDPR instrument, not an AI Act one, and maps exactly how to extract the 4 mandatory compliance inputs from your inference provider.
14 September 2026
AI Act Article 26: Deployer Logging & 6-Month Retention Explained
For high-risk AI deployers, Article 26(6) requires keeping system logs for at least six months. When using a zero-retention API, the provider stores nothing, meaning this logging capability must be built entirely within your own application.
14 June 2026
GDPR and EU AI Act Overlap: Technical Guide for AI Infrastructure
Securing personal data is no longer enough. Engineering teams must now architect their machine learning pipelines to meet stringent product safety and risk management standards.
13 June 2026
EU AI Act High Risk System Classification Guide
The EU AI Act introduces strict obligations for high risk AI systems, with penalties reaching 15 million euros. Engineering teams must understand classification rules and infrastructure requirements to avoid regulatory roadblocks.
13 June 2026
EU AI Act Prohibited AI Systems Checklist for Engineering Teams
The grace period for unacceptable risk AI systems ended on February 2, 2025. Engineering teams running models that breach the Article 5 prohibitions now face fines up to €35 million or 7% of global turnover, whichever is higher.
12 June 2026
EU AI Act Compliance Timeline: Navigating the August 2026 Deadlines
August 2026 remains a hard deadline for transparency, GPAI enforcement, and data governance. Engineering teams must secure their infrastructure now to avoid severe penalties.
12 June 2026
EU AI Act Foundation Model Obligations 2026: A Technical Guide
The grace period is ending. By August 2026, the European Commission will actively enforce compliance for foundation models, turning data residency and infrastructure choices into critical engineering constraints.
11 June 2026
EU AI Act Conformity Assessment: The GPU Infrastructure Guide
The high-risk deadlines now fall on 2 December 2027 and 2 August 2028. Your conformity assessment will fail if your underlying GPU infrastructure cannot prove data sovereignty, logging traceability, and strict access controls.