Advanced

Compliance in Practice

Knowing your obligations is half the job; sequencing them against the clock and producing the right evidence is the other half. This lesson covers the staged timeline, the documents you must be able to show, the management systems behind them, and who is watching.

✍️ AI School Editorial Team · Lilly Tech Systems 📅 Published Jun 13, 2026 · Reviewed Jun 13, 2026

The Staged Timeline

The Act does not switch on all at once. It phases in over three years, with the riskiest practices regulated first:

DateWhat applies
1 Aug 2024The Act enters into force (the clock starts).
2 Feb 2025Prohibited practices (Lesson 3) and the AI-literacy obligation become applicable.
2 Aug 2025GPAI model obligations (Lesson 5), the governance bodies, confidentiality, and most penalty provisions apply.
2 Aug 2026The bulk of the Act applies - high-risk Annex III obligations (Lesson 4) and the transparency duties (Lesson 6).
2 Aug 2027High-risk systems that are safety components of products already regulated under EU product law get their extended deadline; GPAI models already on the market must be brought into compliance.
💡
Sequence your work to the dates. The prohibitions and AI-literacy duty are already live. GPAI duties are live. The big one for most product teams - high-risk and transparency - lands in August 2026, which in practice means the documentation work needs to be well underway now, not started then.

The AI-Literacy Duty (Easy to Miss)

Since February 2025, providers and deployers must take measures to ensure their staff and others operating AI on their behalf have a sufficient level of AI literacy - appropriate to their role, the systems involved, and the people affected. It is one of the cheapest obligations to meet (training and awareness) and one of the easiest to forget. Document what you do: a short internal training programme and an attendance record go a long way.

The Documentation You Must Be Able to Show

Compliance under the Act is evidenced by documents. For a high-risk system, expect to maintain:

  • Technical documentation - the full description of the system and the proof it meets the seven requirements (Lesson 4), ready before market entry.
  • Risk-management records - the living log of risks identified, evaluated, and mitigated across the lifecycle.
  • Data-governance documentation - dataset provenance, preparation, and representativeness.
  • Automatically generated logs - retained for traceability.
  • Instructions for use - the transparency pack handed to deployers.
  • EU declaration of conformity and evidence of the CE marking.
  • Post-market monitoring plan and incident records.

The Management Systems Behind the Documents

Two systems turn one-off documents into ongoing compliance:

  1. Risk-management system - the continuous process that keeps the risk picture current as the model, data, and usage evolve.
  2. Quality-management system - the organisational backbone that ensures compliance is built into design, development, testing, and change-management, rather than bolted on at release.

Plus two events that gate the market: the conformity assessment (mostly self-assessment for Annex III systems) and registration in the EU public database before placing the system on the market.

Who Enforces It

A layered governance structure backs the Act:

  • The European AI Office - oversees GPAI models at EU level and coordinates implementation.
  • The European Artificial Intelligence Board - coordinates national authorities for consistent application across member states.
  • National competent authorities - market surveillance and enforcement within each member state.
  • Notified bodies - independent assessors for the high-risk systems that require third-party conformity assessment.
  • A scientific panel of independent experts - advises on GPAI and systemic risk.
Lean on standards and codes. Harmonised European standards (CEN/CENELEC) and the GPAI codes of practice are the practical bridge to compliance. Conforming to a relevant harmonised standard gives you a presumption of conformity with the corresponding requirement - the closest thing to a checklist the Act offers.

Post-Market: Compliance Does Not End at Launch

Shipping a high-risk system is the start of the obligation, not the end. Providers must run post-market monitoring, keep the risk-management system current, retain logs, report serious incidents and malfunctions to authorities, and take corrective action (including withdrawal) when a system no longer conforms. Build these feedback loops into operations from day one rather than treating launch as the finish line.

📝
For the broader programme view - mapping AI-Act duties onto frameworks like the NIST AI RMF and ISO 42001, and standing up governance across an organisation - see AI Governance. The next and final lesson turns all of this into a one-page action plan.

Ready to Go Deeper?

Live instructor-led courses from our partners. Affiliate disclosure.