// Verified Compliance Intelligence Hub

EU AI Act, cross-checked & UK-aware

Built for engineering, product, and risk teams: verified Regulation (EU) 2024/1689 timeline milestones, role-based obligation mapping, and explicit scope logic so UK organisations are not incorrectly flagged as EU-only unless EU market triggers apply.

Regulation (EU) 2024/1689 VerifiedArticle 113 Timeline LogicUK Extraterritorial GuardrailsArticles 99 & 101 Fine Engine
5 MilestonesEntry into force to Aug 2027
UK != EUExtraterritorial scope check
4 RolesProvider, deployer, importer, distributor
Fine CalculatorArticles 99 & 101 with SME caps

Enforcement Roadmap (Article 113)

Current date context: 2026-09-20. Main application date: 2 August 2026.

1 Aug 2024Entered into Force
2 Feb 2025Prohibitions Live
2 Aug 2025GPAI Duties Live
2 Aug 2026Main Application Date
2 Aug 2027Product Safety Art 6(1)

1. Interactive Scope Checker (UK-vs-EU first)

1. Jurisdiction2. EU trigger3. Role4. Risk5. Annex III6. Date
1) Jurisdiction

Where are you operating from?

UK alone does not trigger EU AI Act duties.

2) EU market trigger

Placed on EU market / put into service in EU?

If Yes, obligations apply under Article 2 extraterritoriality.

3) Operator role

Role in value chain

Role changes obligations and penalty liabilities.

4) Risk profile

Primary risk band

When uncertain, start at limited and test scenarios.

5) Annex III signal

Likely Annex III high-risk use case?

A Yes here triggers mandatory Articles 9-15 high-risk controls.

6) Date context

Assessment date (ISO)

Timeline-sensitive obligations are date-dependent.

EU AI Act likely not directly applicable (UK-only context)

Timeline stage: Phase 3 — main obligations apply (since 2 Aug 2026) · EU applicability: Unlikely (UK Domestic Only)

  1. Document why your offering is UK-only and not placed on the EU market — and that its output is not used in the EU.
  2. Run UK baseline controls: UK GDPR / Data Protection Act 2018, Equality Act 2010, sector rules.
  3. Use ICO AI guidance for accountability, explainability, and DPIA-style risk controls.
  4. Re-run this check if you expand to EU customers — the answer changes the moment you target the EU market.

Why this result

  • Jurisdiction is UK and EU-market trigger is set to No.
  • No current signal of placing system/model on EU market or EU use context.
Verify EUR-Lex Text
Compliance intelligence only, not legal advice. Use this as a triage engine, then run legal sign-off for declarations and conformity evidence.

2. Fine & Liability Calculator (Articles 99 & 101)

Calculate your legal maximum exposure based on global annual turnover and company type. Under Article 99(6), SMEs and startups benefit from the LOWER of the fixed Euro cap vs percentage rate.

Art. 99(4)

Estimated Maximum Fine Ceiling

0.3M

Fixed Euro Cap:15.0M

Turnover Rate (3%):0.30M

Rule Applied: SME / Startup Rule (Art. 99(6)): Capped at whichever is LOWER (€15.0M vs 3% of turnover).

3. Searchable Prohibited & High-Risk Rules Explorer

Search terms across the 8 banned practices and 8 Annex III high-risk domains.

The 8 Prohibited Practices (Article 5 — Live since Feb 2025)

🎭 BANNED

Harmful manipulation & deception

Psychological / Behavioral

Subliminal techniques or deceptive tactics distorting behavior and impairing informed decisions to cause significant harm (Art. 5(1)(a)).

🎯 BANNED

Exploitation of vulnerabilities

Social / Vulnerability

Exploiting age, disability, or specific social/economic situation to distort behavior causing harm (Art. 5(1)(b)).

📊 BANNED

Social scoring

Social / Profiling

Evaluating or classifying natural persons over time based on social behavior or personal traits causing detrimental treatment (Art. 5(1)(c)).

🔮 BANNED

Criminal-offence risk prediction

Justice / Profiling

Predicting an individual's risk of committing a crime based solely on profiling or personality traits (Art. 5(1)(d)).

📷 BANNED

Untargeted facial-image scraping

Biometrics / Privacy

Creating or expanding facial recognition databases via untargeted scraping of internet or CCTV footage (Art. 5(1)(e)).

😐 BANNED

Emotion recognition at work & school

Workplace / Education

Inferring emotions of natural persons in workplace and educational institutions, except for medical or safety reasons (Art. 5(1)(f)).

🧬 BANNED

Biometric categorisation of protected traits

Biometrics / Discrimination

Categorising natural persons based on biometric data to deduce race, political opinions, trade union membership, religious/philosophical beliefs, or sexual orientation (Art. 5(1)(g)).

👁️ BANNED

Real-time remote biometric ID in public

Biometrics / Law Enforcement

Live remote biometric identification in publicly accessible spaces for law enforcement, unless strictly necessary for narrow exceptions (Art. 5(1)(h)).

Annex III High-Risk Categories (Articles 6 & 9-15 — Live Aug 2026)

⚠️ HIGH RISK

Safety components in critical infrastructure

Infrastructure

Digital or safety components in road traffic, water, gas, heating, electricity where failure endangers life and health.

⚠️ HIGH RISK

Education & vocational training

Education

AI determining access, admission, assignment, or evaluating learning outcomes and exam scoring.

⚠️ HIGH RISK

Employment & worker management

Employment

CV-sorting, recruitment tooling, performance evaluation, task allocation, promotion, or termination decisions.

⚠️ HIGH RISK

Access to essential private & public services

Essential Services

Credit scoring, risk assessment for life/health insurance, dispatching emergency first responders.

⚠️ HIGH RISK

Remote biometric identification & categorisation

Biometrics

Post remote biometric identification systems and emotion recognition not banned under Art 5.

⚠️ HIGH RISK

Law enforcement decision support

Law Enforcement

Assessing criminal risk, polygraphs/lie detectors, evidence reliability scoring, profiling during detection.

⚠️ HIGH RISK

Migration, asylum and border control

Migration

Polygraphs, risk assessment for border entry, visa application examination, asylum eligibility verification.

⚠️ HIGH RISK

Administration of justice & democratic processes

Justice

Assisting judicial authorities in researching and interpreting facts and law, or influencing election outcomes.

4. Provider Obligations for High-Risk Systems (Articles 9-15)

01

Risk management system (Art. 9)

Continuous iterative risk assessment, testing, and mitigation across the entire lifecycle.

02

Data & data governance (Art. 10)

High-quality training, validation, and testing datasets with bias mitigation and representative sampling.

03

Technical documentation (Art. 11)

Detailed up-to-date documentation proving conformity before placement on the EU market.

04

Record-keeping & logging (Art. 12)

Automatic logging of events enabling traceability, auditability, and monitoring across operation.

05

Transparency & deployer info (Art. 13)

Clear instructions for use, capabilities, limitations, and operational specifications for deployers.

06

Human oversight (Art. 14)

Built-in interface controls allowing human operators to oversee, override, or interrupt output.

07

Accuracy, robustness & cybersecurity (Art. 15)

Resilience against adversarial prompt injection, cyber threats, data poisoning, and performance drift.

5. Article 50 Transparency & Disclosure Snippet Generator

Required from 2 August 2026: Implement user-facing disclaimers and machine-readable synthetic content watermarks.

<!-- Article 50(1) Interactive AI User Disclaimer -->
<div class="ai-disclosure-banner" role="status" aria-live="polite">
  <span class="ai-icon">🤖</span>
  <p><strong>Notice:</strong> You are interacting with an automated AI assistant powered by synthetic intelligence.</p>
</div>

6. Frequently Asked Questions

Does the EU AI Act apply to UK companies?

Not automatically — the UK is not in the EU. But the Act has extraterritorial reach (Article 2): it applies to any UK firm that places AI systems or GPAI models on the EU market, puts them into service in the EU, or where the system's output is used in the EU. UK-only operations follow domestic UK rules (UK GDPR, Equality Act 2010, ICO guidance, sector regulators).

What took effect on 2 August 2026?

Under Article 113, the main bulk of the AI Act became active and enforceable on 2 August 2026 — including Annex III high-risk system duties, Article 50 transparency obligations, deployer rules, and notified body workflows. The European AI Office also issued GPAI Codes of Practice, establishing operational compliance benchmarks for frontier model providers. Carve-outs remain: Article 6(1) product-safety classification applies from 2 August 2027.

How does the SME / Startup penalty rule work?

Under Article 99(6), for SMEs and startups (defined under EU Recommendation 2003/361/EC), fine ceilings are capped at whichever of the two amounts (the fixed Euro cap vs the percentage of global annual turnover) is LOWER, rather than higher.

Which AI practices are already banned?

Eight practices have been prohibited since 2 February 2025 — including harmful manipulation, social scoring, untargeted facial scraping, workplace/school emotion recognition, and real-time remote biometric identification for law enforcement (narrow exceptions).

Do GPAI model rules already apply?

Yes. Obligations for general-purpose AI model providers (Chapter V) have applied since 2 August 2025 — transparency, technical documentation, EU copyright law compliance, and training content summaries, plus extra requirements for models with systemic risk (>10^25 FLOPs).

Is this page formal legal advice?

No. It is compliance intelligence for engineering, product, and legal triage. For binding conformity declarations, filings, and legal sign-off, consult qualified EU/UK legal counsel and verify against Regulation (EU) 2024/1689.

7. Cross-Fact-Check Sources

European AI Office GPAI Code of Practice (2026)
Official operational guidance and harmonised compliance benchmarks for general-purpose AI models.
Official EU policy page (European Commission)
Risk tiers, the 8 prohibited practices, high-risk categories, transparency timing, GPAI policy context.
Regulation (EU) 2024/1689 — full official text (EUR-Lex)
The binding legal text in all 24 EU languages — the ultimate authority.
AI Act Article 113 explorer (text mapped to OJ version)
Entry into force and staged application dates.
EU AI Act Service Desk (Commission)
Official single information platform for AI Act questions.
UK Government white paper (DSIT)
UK principles-based approach; no single horizontal UK AI Act in that framework.
ICO AI guidance index
UK data protection compliance resources for AI systems.