AI Act — compliance
Most AI Act provisions apply from 2 August 2026. Does your company have readiness evidence?
Most AI Act provisions apply from 2 August 2026; some bans and duties applied earlier, while full duties for selected high-risk systems fall later. The applicable scope depends on the organisation’s role and use case.
Updated:
2 Aug 2026
most AI Act obligations start to apply (Reg. EU 2024/1689)
EUR 35M
or 7% of turnover — maximum fines (AI Act, Art. 99)
EUR 15M
or 3% of turnover — fines for breaching the remaining obligations (AI Act, Art. 99(4))
2 Dec 2027
deferred deadline for Annex III high-risk systems (Digital Omnibus)
EU AI Act compliance audit
What is an EU AI Act compliance audit?
An EU AI Act compliance audit is a fixed-scope review that establishes how Regulation (EU) 2024/1689 applies to your company. Most AI Act provisions apply from 2 August 2026, but duties depend on whether the organisation is a provider, deployer or GPAI provider and on the use case. The audit inventories systems — including “shadow AI” — and assigns roles, risk and gaps.
Semitora runs it as a working engagement, not a slide deck: typically 2–4 weeks, ending with a documented risk classification and a prioritised plan to close the gaps. It is an implementation-led audit — the result feeds straight into building compliant AI, not a binder for the shelf.
- ✓AI system inventory — every tool in use, including shadow AI
- ✓Deployer / provider classification under the AI Act
- ✓Risk class per system: prohibited / high-risk / limited / minimal
- ✓Gap-closing plan with owners and priorities
- ✓AI literacy scope for staff (Article 4)
- ✓Technical documentation requirements for high-risk systems
Definitions
Key AI Act terms — in one sentence
Deployer (the company using AI)
An organisation that uses an AI system under its authority in a professional context — including off-the-shelf tools like ChatGPT. Most companies using AI are deployers, and have their own AI Act obligations.
Provider
An entity that develops an AI system or model and places it on the market or puts it into service under its own name — including when the build is outsourced. A company can be a provider of some systems and a deployer of others; each role carries different AI Act obligations.
AI literacy (Article 4)
Article 4 requires providers and deployers to take measures to support the development of AI literacy among staff and other people operating AI on their behalf. The measures should reflect their knowledge, experience, the context of use and the people affected. It does not require them to guarantee a specific level of AI literacy.
Human oversight (Article 14)
For high-risk AI systems, Article 14 requires effective human oversight during use: a person who understands how the system works, can question its output and — where appropriate — stop the system before it causes harm.
Shadow AI
AI tools used by employees outside the company's knowledge and control — private ChatGPT accounts, plugins, automations. They increase data-leak risk and can make AI Act or GDPR compliance harder, especially where personal data, regulated decisions or high-risk AI are involved.
Digital Omnibus
Amending Regulation (EU) 2026/1744, published on 24 July 2026, entered into force on 27 July 2026. It defers the full obligations for Annex III high-risk systems to 2 December 2027 and Annex I systems to 2 August 2028. Most AI Act provisions apply from 2 August 2026, and Article 50 has not been postponed.
How we help
Compliance as a process, not a binder.
We don't produce documents for a drawer. We build a working compliance system: inventory, classification, documentation and oversight that survive an inspection and the next regulatory change.
Compliance audit
A review of every AI system and tool in the organisation — including the ones IT doesn't know about.
Mapping & classification
Assigning each system to its AI Act risk category and the obligations that follow.
Technical documentation
Documentation for high-risk systems: data, architecture, oversight, event logging.
“AI literacy” training
Measures supporting employees’ AI literacy (Article 4), tailored to their knowledge, experience and context of use.
Governance & human oversight
AI usage policies, roles and responsibilities, human oversight procedures.
30-day plan
A 30-day AI Act readiness plan
How to go from “we don’t know what we have” to a documented map of your AI systems and a prioritised gap-closing plan in four weeks. Most AI Act provisions apply from 2 August 2026, so the plan structures the current state and sequence of remediation rather than counting down to a deadline.
Week 1
Inventory and shadow AI
We list every AI tool in use — including private ChatGPT accounts and automations IT doesn’t know about. The result is an AI systems register: who, where, on what data and for what purpose.
Week 2
Roles and risk classification
We assign each system your company’s role (deployer / provider) and an AI Act risk category: prohibited, high, limited or minimal. The result is a prioritised risk matrix.
Week 3
AI literacy and human oversight
We tailor measures that support staff AI literacy (Art. 4) and set up human oversight of high-risk systems (Art. 14): someone who understands the system, can challenge its output and stop it. Plus AI usage policies.
Week 4
Documentation requirements and gap backlog
We map the documentation requirements for high-risk systems and close the plan: a prioritised gap-closing backlog, ready to ship as GenAI/RAG implementations on AWS — not a binder on a shelf.
What you get
An audit that ends in an implementation backlog — not slides.
The output of an AI Act audit is a set of working artefacts your board, IT and lawyers actually use — and the starting point for implementation.
AI systems register
A map of every AI system and tool: owner, users, data, purpose and legal basis — including the “shadow AI” we uncover.
Risk matrix
Each system assigned to an AI Act category (prohibited / high-risk / limited-risk / minimal) and to your role: provider or deployer.
Documentation requirements
The documents and mechanisms required for high-risk systems: data, architecture, human oversight, event logging.
Implementation & PoC backlog
A prioritised list of actions that close the gaps — ready to ship as GenAI/RAG implementations on AWS, not to be shelved.
Then we build the backlog: RAG on your documents, production AI systems. See also the AI Act readiness checklist.
Polish law
The Polish angle: a national act and a new regulator (KRiBSI)
Poland’s Act of 3 July 2026 on artificial intelligence systems was published on 27 July 2026 as Journal of Laws 2026, item 1003. It takes effect in stages: Article 125(4) from 28 July 2026, most remaining provisions from 11 August 2026, and Articles 8–18 plus Chapters 3–5, 8 and 9 from 28 October 2026. Official ELI record: https://api.sejm.gov.pl/eli/acts/DU/2026/1003.
The Act establishes the national supervisory system, including the Commission for the Development and Security of Artificial Intelligence (KRiBSI). Powers and procedures start according to the Act’s staged timetable; independently, most provisions of the EU AI Act apply from 2 August 2026.
- ✓KRiBSI combines existing regulators: UOKiK, KNF, KRRiT and UKE; the Sejm appoints its chair with consent of the Senate
- ✓Powers: company inspections, handling complaints, supervising high-risk AI systems and issuing statutory decisions
- ✓Regulatory sandboxes and individual opinions — a path for companies piloting AI
- ✓The Act has staged dates — 28 July, 11 August and 28 October 2026 — so the applicable provision must be checked before action
Go deeper
The AI Act in practice — from our blog
FAQ
Common questions about the AI Act
Yes. As a “deployer” you have obligations: ensuring employees' AI literacy (Article 4), overseeing how AI is used and — depending on the use case — further requirements. The key is establishing what AI is really used for in your company, including “shadow AI”.
Maximum fines reach EUR 35M or 7% of global annual turnover (prohibited practices) and EUR 15M or 3% (other violations). Beyond fines, the practical risk is disputes with business partners, who increasingly require compliance in contracts.
With an inventory: what uses AI, where and why — including tools employees adopted on their own. Then risk classification and a gap-closing plan. That is exactly the scope of our audit.
AI tools used by employees outside the company's knowledge and control — private ChatGPT accounts, plugins, automations. The risks: leakage of company and customer data, and harder AI Act or GDPR compliance, especially where personal data or high-risk AI are involved. A shadow-AI inventory is the first week of our audit.
Typically 2–4 weeks, depending on the number of systems and the size of the organisation. It ends with a report containing risk classification and an action plan — a working document, not a decorative one.
Any company in the EU that develops or uses AI systems in a professional context — in practice almost every company using tools like ChatGPT, Copilot or a custom model. You are a “deployer” even when you only use off-the-shelf AI, and deployers have their own obligations. An audit is most urgent where AI touches personal data, regulated decisions or high-risk use cases.
An inventory of the AI systems in use (including shadow AI), each system’s deployer/provider classification and risk category, evidence of AI literacy measures for staff (Article 4), human-oversight and AI usage policies, and — for systems whose obligations apply by then — the technical documentation those obligations require. A compliance audit maps exactly what each system needs and where the gaps are, with a plan to close them.
GPAI (general-purpose AI) models — large models like GPT or Gemini — carry AI Act obligations such as technical documentation, a copyright policy and a training-data summary. These apply from 2 August 2025 and, as a rule, fall on the model provider (e.g. OpenAI, Google), not on a company that merely uses the model. Your company can itself become a GPAI provider if it fine-tunes or substantially modifies such a model and places it on the market under its own name. Models with systemic risk carry extra obligations (evaluations, testing, incident reporting). The audit determines whether you are only a deployer or cross the GPAI-provider threshold.
Yes. It was published on 27 July 2026 as Journal of Laws 2026, item 1003. Article 125(4) applies from 28 July 2026; most remaining provisions take effect on 11 August 2026; Articles 8–18 and Chapters 3–5, 8 and 9 on 28 October 2026. It establishes KRiBSI and national supervision procedures. Official record: https://api.sejm.gov.pl/eli/acts/DU/2026/1003.
In four weeks you can build the readiness foundation: a register of the AI systems you use (including shadow AI), role and risk classification, the scope of AI literacy (Art. 4) and human oversight (Art. 14), and a prioritised gap backlog. It is not a guarantee of full compliance — gaps are closed through implementation and documentation, and timing depends on role and system class. Most provisions apply from 2 August 2026; full duties for some high-risk systems fall later.
Open register
See every AI system and use case in one portfolio view.
Record owners, stage, data, integrations, supplier, volume, error impact and the next review date. Roles and risk remain explicitly marked for verification.
Free tool
Is your organisation ready for a bounded AI PoC?
Answer 24 questions about process, data, shadow AI, ownership, risk and governance. The result points to the next step without claiming automatic conformity.
Open governance template
Separate accountability for an AI system from decision authority.
Complete a 7-stage × 7-role matrix and decision rights covering the decider, required input, evidence, escalation and response time. Every stage has exactly one Accountable.
Check the implementation status of AI Act duties on your own systems.
The audit delivers a system inventory, role and risk classification, and a prioritised gap backlog. It is not a guarantee of full compliance.