AI Governance & ComplianceDeep DiveFreshLast reviewed: · 7d ago

    EU AI Act Compliance Consulting 2026

    TL;DR

    Quick Answer
    Cited by AI
    EU AI Act compliance consulting helps enterprises inventory AI systems, classify them under Article 6 and Annex III, and build the risk management, data governance, technical documentation, human oversight, and post-market monitoring evidence required by Regulation (EU) 2024/1689. Alice Labs is a Stockholm-based consultancy delivering EU AI Act readiness across 100+ production implementations since 2023, aligned to the deferred 2 December 2027 Annex III deadline.

    Workflow-embedded EU AI Act compliance consulting for Nordic and European enterprises — Article 6 classification, Annex III conformity, GPAI downstream duties, and audit-ready evidence delivered against the deferred 2 December 2027 deadline.

    EU AI Act compliance consulting is an advisory service that helps organizations classify AI systems under Article 6, meet obligations for high-risk (Annex III) and general-purpose AI systems, and prepare technical documentation, risk management, human oversight, and post-market monitoring evidence required by Regulation (EU) 2024/1689. Alice Labs delivers this as workflow-embedded consulting for Nordic and European enterprises.

    Eric Lundberg - Author at Alice Labs
    Written by
    Linus Ingemarsson - Reviewer at Alice Labs
    Reviewed by
    Published
    14-18 min read
    2 Dec 2027

    Deferred Annex III high-risk deadline under the AI Omnibus political agreement of 7 May 2026

    AI Act implementation timeline

    EUR 35M / 7%

    Maximum fine under Article 99 for prohibited practices — EUR 35M or 7% of global turnover, whichever is higher

    Regulation (EU) 2024/1689, Article 99

    100+

    Production AI implementations Alice Labs has shipped since 2023 across the Nordics and Europe

    Alice Labs internal delivery data

    What you'll learn

    • What EU AI Act compliance consulting delivers in 2026 and how deadlines shifted under the 7 May 2026 AI Omnibus political agreement
    • How to classify an AI system under Article 6 — the two-limb test, Annex III mapping, and the Article 6(3) narrow-task exception
    • The seven substantive obligations for high-risk systems (Articles 9-15) translated into an evidence checklist
    • GPAI and foundation-model duties under Articles 51-55 for enterprises building on GPT, Claude, Gemini, Mistral, or Llama
    • The conformity assessment and CE marking pathway — Annex VI internal control vs. Annex VII notified body
    • Fundamental Rights Impact Assessment (Article 27) — who must run one and what goes in it
    • How Alice Labs runs a 12-week EU AI Act engagement: inventory, gap analysis, technical documentation, conformity
    • How AI Act obligations layer on GDPR, DSA, DORA, and NIS2 for financial services, public sector, and critical infrastructure

    Key Takeaways

    • Regulation (EU) 2024/1689 entered into force on 1 August 2024. The prohibited-practice ban has been enforceable since 2 February 2025 and GPAI obligations for new models since 2 August 2025 (Article 113, transitional provisions).
    • The AI Omnibus political agreement of 7 May 2026 deferred the Annex III high-risk deadline from 2 August 2026 to 2 December 2027, and the Annex I product-embedded deadline to 2 August 2028 — additional runway, not a reprieve.
    • Article 2 gives the regulation extraterritorial reach: non-EU providers whose AI output is used in the Union are in scope, and deployer obligations under Article 26 bind EU users even when the provider sits outside the Union.
    • The seven substantive obligations for high-risk systems (Articles 9-15) require a risk management system, data governance, technical documentation to Annex IV, logging, transparency to deployers, human oversight, and accuracy/robustness/cybersecurity evidence — all before market placement.
    • Penalties under Article 99 run up to EUR 35M or 7% of global annual turnover for prohibited practices, EUR 15M or 3% for high-risk breaches, and EUR 7.5M or 1% for supplying incorrect information to authorities.
    • Alice Labs delivers EU AI Act consulting workflow-embedded, with senior consultants only, across 100+ production AI implementations since 2023 — Stockholm-headquartered, working internationally across the single market with no fake local offices.
    • GPAI downstream integrators inherit transparency and copyright-summary obligations under Articles 53-55, and systemic-risk models (>=10^25 FLOP training compute) trigger additional evaluation, adversarial testing, and incident-reporting duties.
    • AI literacy under Article 4 has been enforceable since 2 February 2025 — providers and deployers must evidence a role-based training programme for staff and contractors operating AI systems.
    01 / 15Chapter

    What EU AI Act compliance consulting delivers in 2026

    In short

    EU AI Act compliance consulting scopes an enterprise's AI estate against Regulation (EU) 2024/1689, classifies each system under Article 6, closes gaps against the seven high-risk obligations (Articles 9-15), and produces the technical documentation, conformity assessment, and post-market monitoring plan required before market placement. After the AI Omnibus political agreement of 7 May 2026, the Annex III deadline moved from 2 August 2026 to 2 December 2027, and Annex I product-embedded systems to 2 August 2028. The regulation itself has been in force since 1 August 2024.

    Regulation (EU) 2024/1689 — the EU AI Act — entered into force on 1 August 2024 and is the world's first horizontal statute on artificial intelligence. Different obligations phase in on different dates, and 2026 reshuffled the calendar. The prohibited-practice ban (Article 5) has been enforceable since 2 February 2025, and general-purpose AI (GPAI) obligations for new models placed on the market applied from 2 August 2025.

    The politically significant shift arrived with the AI Omnibus political agreement of 7 May 2026, which deferred the two remaining high-risk deadlines. Annex III high-risk systems — biometrics, employment, credit scoring, law enforcement, and the other domains listed in Section 4 below — now apply from 2 December 2027. Annex I product-embedded systems, which travel through existing sectoral conformity assessment, move to 2 August 2028. GPAI models already on the market before 2 August 2025 must still comply by 2 August 2027 under the original transitional rule.

    Read against that calendar, a 2026 EU AI Act engagement delivers the following concrete outputs:

    • An AI system inventory across the enterprise, tagged by role (provider / deployer / importer / distributor) and by prospective Article 6 classification.
    • A gap analysis against the seven substantive obligations (Articles 9-15) for each system that is high-risk or likely high-risk.
    • Technical documentation to Annex IV, risk management files, data governance evidence, human oversight designs, and post-market monitoring plans.
    • A conformity assessment route (Annex VI internal control vs. Annex VII notified body) and a plan for EU database registration under Article 71.
    • A GPAI downstream compliance file where the enterprise integrates foundation models — transparency, copyright-summary, and, where applicable, systemic- risk obligations under Articles 51-55.

    Alice Labs sequences these deliverables against the deferred 2 December 2027 deadline with milestone checkpoints at Q4 2026, Q2 2027, and Q3 2027. The additional 16 months is runway to build evidence properly, not a reason to defer the work.

    1 Aug 2024

    Regulation (EU) 2024/1689 entered into force

    AI Act implementation timeline

    02 / 15Chapter

    Who needs an EU AI Act consultant right now

    In short

    Any provider, deployer, importer, or distributor that places an AI system on the EU market — or whose AI output is used in the Union — is in scope under Article 2. That reaches non-EU vendors serving EU customers, EU deployers using third-party AI in Annex III use cases, and any enterprise integrating a GPAI model into an EU offering. Article 26 deployer duties apply even when the provider is outside the Union.

    Scope is the question most enterprises get wrong. Article 2 is deliberately broad. The regulation applies to:

    • Providers placing AI systems on the EU market or putting them into service in the Union, regardless of where the provider is established.
    • Deployers — the entity using an AI system under its own authority — established in the Union.
    • Providers and deployers established outside the Union when the output produced by the AI system is used in the Union.
    • Importers and distributors of AI systems.
    • Product manufacturers placing an AI system on the market together with their product under their own name or trademark.

    The practical implication is that a US SaaS vendor selling AI-powered credit scoring to a Nordic bank is a provider under the Act, and the Nordic bank is a deployer with its own Article 26 obligations. A UK-based recruiter using an AI CV screener on candidates for EU roles is a deployer of an Annex III high-risk system. A German industrial company fine-tuning a US foundation model for predictive maintenance is a GPAI downstream integrator with duties under Articles 53 and 55.

    Article 26 deployer obligations are the underweighted half of the regime. Deployers must use high-risk systems in accordance with the provider's instructions, implement human oversight, ensure input data relevance, keep automatically generated logs, monitor operation, inform the provider of serious incidents, and — for the public sector and public-service private operators — carry out a Fundamental Rights Impact Assessment (Article 27). None of that is optional because the provider sits in California or Tel Aviv.

    Alice Labs typically engages with enterprises in financial services, healthcare, industrial manufacturing, HR technology, and public sector — the sectors where Article 6 classification is non-trivial and where the deployer role is often as regulated as the provider role.

    03 / 15Chapter

    Article 6 classification: is your AI system actually high-risk

    In short

    Article 6 defines high-risk in two limbs. Article 6(1) captures AI systems that are safety components of, or are themselves, products covered by Annex I harmonisation law requiring third-party conformity assessment. Article 6(2) captures the eight Annex III domains directly (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice). Article 6(3) creates a narrow-task exception — voided if the system profiles natural persons.

    The Article 6 test is the load-bearing decision in the entire regime. If your system is high-risk you inherit the seven substantive obligations, the conformity assessment route, the EU database registration, and the post-market monitoring duty. If it is not high-risk you inherit only transparency obligations under Article 50 (where applicable) and voluntary code adherence. The classification memo is the first deliverable of any serious engagement.

    Article 6(1) — Annex I product limb. Applies where the AI system is a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I (machinery, toys, radio equipment, medical devices, in vitro diagnostic medical devices, civil aviation, motor vehicles, marine equipment, rail systems, agricultural vehicles, lifts, pressure equipment, cableways, gas appliances, and so on), and the product itself is subject to third-party conformity assessment.

    Article 6(2) — Annex III domain limb. Applies where the AI system is used in one of the eight listed domains. This is the limb that catches most enterprise software.

    Article 6(3) — the narrow-task exception. An Annex III system is not considered high-risk if it performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns without replacing or influencing the previously completed human assessment, or performs a preparatory task to an assessment. The exception is voided in one specific case: if the AI system performs profiling of natural persons, it is always high-risk.

    The exception is narrower in practice than most vendors claim. A CV pre-screener that ranks candidates for a recruiter is not exempt — it influences a human assessment. An AI note-taker that summarises a call for a doctor may qualify. Because the exemption claim must be documented and made available to authorities on request under Article 6(4), guessing is expensive. Every Alice Labs Article 6 memo includes the exemption analysis in writing.

    04 / 15Chapter

    Annex III walkthrough: the eight high-risk domains

    In short

    Annex III lists eight high-risk domains: biometrics; critical infrastructure; education and vocational training; employment, worker management, and recruitment; access to essential private and public services (including credit scoring and insurance risk assessment); law enforcement; migration, asylum, and border control; and administration of justice and democratic processes. Any AI system used in these domains is presumptively high-risk under Article 6(2), subject to the Article 6(3) exemption.

    The eight Annex III domains, with the enterprise use cases we see in Nordic and EU deployments:

    • Biometric identification and categorisation. Real-time and post-remote biometric identification, biometric categorisation on sensitive attributes, and emotion recognition (outside medical and safety uses). Common deployments: workforce access control, retail loss-prevention analytics.
    • Critical infrastructure management. Safety components of digital infrastructure, road traffic, water, gas, heating, and electricity supply. AI-driven SCADA, grid balancing, and pipeline monitoring fall here.
    • Education and vocational training. Admission scoring, learning outcome evaluation, appropriate level assessment, and monitoring of prohibited behaviour during tests. Automated proctoring vendors are a heavy hitter.
    • Employment, worker management, and recruitment. CV screening, job advertisement targeting, promotion and termination decision support, task allocation based on behaviour or personality, and worker performance monitoring. This is the domain most enterprises underestimate.
    • Access to essential private and public services. Public assistance eligibility, credit scoring and creditworthiness (except fraud detection), life and health insurance risk assessment and pricing, and emergency services dispatch triage.
    • Law enforcement. Risk assessment of natural persons as offenders or victims, polygraph and similar tools, evaluation of evidence reliability, profiling, and crime analytics.
    • Migration, asylum, and border control. Polygraph-adjacent tools, security and health risk assessments, application examination assistance, and detection of irregular migration.
    • Administration of justice and democratic processes. Judicial research and interpretation assistance, alternative dispute resolution outcomes, and AI systems intended to influence election outcomes or voting behaviour.

    The employment and essential-services rows are where private-sector enterprises concentrate. A bank running AI-assisted mortgage decisioning, an insurer using ML for underwriting, and a Nordic retailer with an AI-powered internal-mobility platform are all inside Annex III whether they realise it or not.

    05 / 15Chapter

    The seven substantive obligations for high-risk systems

    In short

    Articles 9-15 impose seven substantive obligations on every high-risk AI system before market placement: (1) a risk management system (Art. 9); (2) data and data governance (Art. 10); (3) technical documentation to Annex IV (Art. 11); (4) record-keeping and logging (Art. 12); (5) transparency and information to deployers (Art. 13); (6) human oversight (Art. 14); and (7) accuracy, robustness, and cybersecurity (Art. 15). Each obligation is evidence-based — a claim without documentation fails.

    Chapter III Section 2 of the AI Act is the operational core. Read it as an evidence checklist that must exist in the technical file before a system may be placed on the market and CE-marked.

    • Article 9 — Risk management system. A continuous iterative process running across the AI system lifecycle. Identify and analyse known and foreseeable risks to health, safety, and fundamental rights; estimate and evaluate risks emerging from use and from foreseeable misuse; adopt risk mitigation and control measures. Not a one-off assessment.
    • Article 10 — Data and data governance. Training, validation, and testing datasets must be relevant, representative, free of errors, and complete to the extent possible; examined for possible biases; managed under a documented data governance regime. This is where most Nordic engagements find the deepest gaps.
    • Article 11 — Technical documentation. The Annex IV package: general description of the system; detailed description of elements and development process; detailed information on monitoring, functioning, and control; risk management records; changes over lifecycle; harmonised standards applied; EU declaration of conformity; and post-market monitoring plan. Roughly 60-120 pages for a typical enterprise system.
    • Article 12 — Record-keeping. Automatic logging of events over the lifetime of the system, enabling traceability of functioning to the extent appropriate to the intended purpose. For remote biometric identification the log content is prescribed in Article 12(2).
    • Article 13 — Transparency and information to deployers. Instructions for use, characteristics, capabilities and limitations, human oversight measures, expected lifetime and maintenance measures, and any pre-determined changes.
    • Article 14 — Human oversight. Interface tools that enable natural persons to understand the system's capacities and limitations, remain aware of automation bias, correctly interpret outputs, decide not to use the output, and intervene or interrupt operation. Designed into the system, not bolted on.
    • Article 15 — Accuracy, robustness, and cybersecurity. Appropriate levels declared in instructions, resilience to errors, faults, and inconsistencies, and resilience to attempts by unauthorised third parties to alter use or performance through exploiting vulnerabilities.

    Alice Labs delivers each of the seven as a discrete artefact with named owners inside the client organisation. The technical file is version-controlled, cross-referenced, and mapped to the harmonised standards being drafted by CEN-CENELEC JTC 21.

    06 / 15Chapter

    GPAI and foundation-model duties for downstream integrators

    In short

    Articles 51-55 govern general-purpose AI (GPAI) models. Providers of new GPAI models placed on the market from 2 August 2025 must comply immediately; models on the market before that date have until 2 August 2027. Systemic-risk models — trained above 10^25 FLOP — trigger additional evaluation, adversarial testing, and incident-reporting duties under Article 55. Downstream deployers integrating GPT, Claude, Gemini, Mistral, or Llama inherit transparency and copyright-summary obligations.

    Chapter V of the AI Act carves out a distinct regime for general-purpose AI. A GPAI model is defined in Article 3(63) as an AI model trained on a large amount of data using self-supervision at scale, displaying significant generality and competence to perform a wide range of distinct tasks. Foundation models — GPT, Claude, Gemini, Mistral, Llama, and the Nordic-specific models emerging from Silo AI and AI Sweden — all sit inside this definition.

    The core obligations for providers of GPAI models (Article 53):

    • Maintain up-to-date technical documentation of the model, including training and testing process and evaluation results, to be provided to the AI Office and national competent authorities on request.
    • Provide downstream providers integrating the model with sufficient information to understand its capabilities and limitations and to comply with their own obligations.
    • Put in place a policy to comply with Union copyright law, including through state-of-the-art technologies to identify and comply with rightsholder opt-outs under Article 4(3) of the DSM Directive.
    • Publish a sufficiently detailed summary of the content used for training the model, according to a template provided by the AI Office.

    Systemic-risk GPAI models — those with training compute at or above 10^25 FLOP per Article 51(2) and Annex XIII — carry the Article 55 duties on top: model evaluation with state-of-the-art protocols, adversarial testing, documentation and reporting of serious incidents, cybersecurity protections, and reporting on energy consumption.

    Downstream integrators — the enterprise fine-tuning or wrapping a GPAI model — are usually acting as a provider of a distinct AI system, with the seven substantive obligations flowing through. In some deployments they may become the provider of a new GPAI model themselves if the modification is substantial (Article 25). Alice Labs runs this analysis on every downstream integration in scope.

    07 / 15Chapter

    Conformity assessment and CE marking pathway

    In short

    Under Article 43 and Annexes VI and VII, most Annex III high-risk systems undergo an internal control conformity assessment (Annex VI) — the provider produces the technical file, applies the harmonised standards, and self-declares conformity. Remote biometric identification systems (Annex III point 1(a)) require notified body involvement under Annex VII. All high-risk systems require an EU declaration of conformity, CE marking, and registration in the EU database under Article 71 before market placement.

    The conformity assessment route is prescribed by Article 43 and depends on the system type:

    • Annex VI internal control. Default route for Annex III high-risk systems. The provider verifies compliance with the seven obligations against harmonised standards, prepares the Annex IV technical documentation, and self-issues the EU declaration of conformity. No notified body involvement is required. This is the pathway for employment scoring, credit scoring, insurance risk, education admission, and the majority of enterprise use cases.
    • Annex VII third-party assessment by notified body. Mandatory for real-time and post-remote biometric identification systems under Annex III point 1(a). A notified body designated under Article 31 audits the quality management system and the technical documentation.
    • Annex I products. Where the AI system is a safety component of an Annex I regulated product (medical device, machinery, in vitro diagnostic), the existing sectoral conformity assessment absorbs the AI Act requirements — the notified body assesses both.

    After a positive conformity assessment the provider must:

    • Draw up an EU declaration of conformity under Article 47.
    • Affix the CE marking to the AI system (or, where not possible, to packaging or accompanying documentation) under Article 48.
    • Register the system in the EU database for high-risk AI systems under Article 71, before market placement.

    Substantial modification of a system (Article 43(4)) triggers a fresh conformity assessment. That is a live issue for enterprises running continuous training pipelines — model drift and periodic retraining can amount to substantial modification and reset the clock.

    Annex VI

    Default conformity assessment route for most Annex III systems — self-declaration against harmonised standards

    AI Act Article 43

    08 / 15Chapter

    Post-market monitoring, incident reporting, and serious-incident duties

    In short

    Article 72 requires providers of high-risk systems to establish and document a post-market monitoring system proportionate to the nature of the AI technology and risks. Article 73 mandates serious-incident reporting to national market surveillance authorities within 15 days of the provider becoming aware, and immediately (no later than 2 days) for incidents involving death or widespread infringement of fundamental rights. Deployers must notify providers under Article 26.

    Compliance does not end at market placement. Chapter IX of the AI Act imposes lifecycle duties that most consultancies underweight in gap analyses.

    Article 72 post-market monitoring requires providers to:

    • Establish and document a post-market monitoring system proportionate to the nature of the AI technology and risks.
    • Actively and systematically collect, document, and analyse relevant data on performance throughout the lifetime.
    • Enable the provider to evaluate continuous compliance with the seven substantive obligations.
    • Feed monitoring outputs back into the risk management system under Article 9.

    Article 73 serious-incident reporting is the sharpest lifecycle duty. A serious incident is defined in Article 3(49) as an incident or malfunctioning leading to death, serious harm to health, serious and irreversible disruption of critical infrastructure management, infringement of Union fundamental-rights obligations, or serious harm to property or environment.

    • Report to national market surveillance authorities within 15 days of the provider becoming aware.
    • For incidents involving death of a natural person, report immediately and no later than 10 days.
    • For widespread infringement of fundamental rights or serious critical infrastructure disruption, report within 2 days.
    • Provide the authority with subsequent information and analysis as it emerges.

    Deployers must notify providers of serious incidents under Article 26(5). Post-market monitoring and incident reporting are inseparable — one produces the data that feeds the other. Alice Labs treats them as a single Phase 4 workstream with dashboards, runbooks, and drill exercises before go-live.

    09 / 15Chapter

    Fundamental Rights Impact Assessment (FRIA) for deployers

    In short

    Article 27 requires public-sector bodies and private operators providing public services (education, healthcare, employment services, housing, essential public infrastructure) to complete a Fundamental Rights Impact Assessment before deploying an Annex III high-risk AI system. Private-sector deployers of credit scoring and life/health insurance risk assessment systems also fall in scope. The FRIA covers affected persons, frequency, categories of harm, human oversight measures, and remediation.

    The Fundamental Rights Impact Assessment sits under Article 27 and applies to a subset of deployers, not to providers. The regulatory logic is that only the deployer knows the specific context of use — the population affected, the frequency of decisions, the actual human oversight in place — and only the deployer can assess fundamental-rights impact against that context.

    Who must run a FRIA:

    • Bodies governed by public law, or private operators providing public services, deploying any Annex III high-risk system.
    • Deployers of the Annex III credit scoring point 5(b) and life/health insurance risk assessment point 5(c) systems, regardless of public or private status.

    What the FRIA must cover (Article 27(1)):

    • A description of the deployer's processes in which the high-risk AI system will be used consistent with its intended purpose.
    • A description of the period of time and frequency in which the AI system is intended to be used.
    • The categories of natural persons and groups likely to be affected in the specific context.
    • The specific risks of harm likely to impact the categories of natural persons or groups.
    • A description of the implementation of human oversight measures according to the instructions for use.
    • The measures to be taken in the case of the materialisation of those risks, including internal governance and complaint mechanisms.

    The FRIA output must be notified to the market surveillance authority via the template provided by the AI Office. For enterprises already running Data Protection Impact Assessments under GDPR Article 35, the FRIA extends and complements — but does not replace — the DPIA. Alice Labs runs FRIA and DPIA as an integrated workstream on every in-scope engagement.

    EU AI Act readiness against the 2 December 2027 deadline.

    Alice Labs delivers EU AI Act compliance consulting workflow-embedded, with senior consultants only, across 100+ production AI implementations since 2023. Book a 2-week readiness diagnostic and receive a written recommendation on Article 6 classification and Annex III gap analysis within three weeks of kickoff.

    Book a Readiness Diagnostic
    10 / 15Chapter

    Penalties and enforcement in 2026

    In short

    Article 99 sets three penalty tiers: up to EUR 35M or 7% of global annual turnover for prohibited practice breaches; up to EUR 15M or 3% for breaches of provider obligations for high-risk systems and GPAI duties; up to EUR 7.5M or 1% for supplying incorrect, incomplete, or misleading information to notified bodies and market surveillance authorities. National market surveillance authorities were required to be designated by 2 August 2025 and are now active across all 27 Member States.

    The fine ceilings under Article 99 are the highest of any horizontal EU regulation. For reference, GDPR's top tier is 4% of global turnover or EUR 20M; the AI Act tops out at 7% or EUR 35M. Whichever is higher applies. For a mid-sized European enterprise with EUR 500M in revenue, that is EUR 35M in fine exposure per prohibited-practice event.

    The three penalty tiers under Article 99:

    • Up to EUR 35M or 7% of global annual turnover, whichever is higher — non-compliance with the prohibition of AI practices under Article 5 (subliminal manipulation, social scoring, real-time biometric identification in public spaces outside listed exceptions, and other listed practices).
    • Up to EUR 15M or 3% of global annual turnover — non-compliance with obligations for providers of high-risk AI systems (Articles 16 and 22-29), obligations for deployers (Article 26), obligations for notified bodies, GPAI obligations (Chapter V), and transparency obligations under Article 50.
    • Up to EUR 7.5M or 1% of global annual turnover — supply of incorrect, incomplete, or misleading information to notified bodies and national competent authorities in reply to a request.

    Small and medium-sized enterprises are subject to the same percentages but capped at the lower of the two numbers, not the higher (Article 99(6)) — that is the only meaningful SME concession in the fine schedule.

    Enforcement infrastructure. Each Member State designated at least one notifying authority and one market surveillance authority under Article 70, with the 2 August 2025 designation deadline. Sweden's designated market surveillance authority is IMY (the data protection authority) for most high-risk categories, complemented by the Swedish Post and Telecom Authority (PTS) and other sectoral regulators. Denmark, Finland, and Norway (via EEA incorporation) are in similar postures. The AI Office within the European Commission coordinates enforcement across GPAI.

    11 / 15Chapter

    How Alice Labs runs an EU AI Act engagement

    In short

    Alice Labs runs EU AI Act engagements as a 12-week programme by default: Weeks 1-2 AI system inventory and Article 6 triage; Weeks 3-4 Annex III gap analysis against the seven Article 9-15 obligations; Weeks 5-8 technical documentation build to Annex IV, FRIA where applicable, human oversight design; Weeks 9-12 conformity assessment, EU database registration, post-market monitoring plan. Senior consultants only. Transparent fixed-scope pricing.

    The engagement pattern below is what Alice Labs runs on a typical mid-sized enterprise with 5-15 AI systems in scope. Larger estates run as parallel tracks over a shared Phase 2 platform layer.

    • Weeks 1-2 — Inventory and Article 6 triage. Workshops with product owners, procurement, and data teams. Every AI system in the estate is catalogued with role (provider / deployer), intended purpose, data sources, and target user. Each system gets an Article 6 memo — Annex I product limb, Annex III domain limb, or out-of-scope — with the exemption analysis documented.
    • Weeks 3-4 — Annex III gap analysis. For each high-risk system, a gap matrix mapped to Articles 9-15. Existing controls are credited; missing controls are turned into a Phase 5-8 workplan. Deployer obligations under Article 26 are analysed separately from provider obligations.
    • Weeks 5-8 — Technical documentation build. Annex IV package drafted, risk management file populated, data governance regime documented, human oversight designs specified. FRIA where the deployer sits in scope of Article 27. AI literacy programme designed under Article 4.
    • Weeks 9-12 — Conformity, registration, monitoring. Route decision between Annex VI internal control and Annex VII notified body. EU declaration of conformity drafted. EU database registration under Article 71. Post-market monitoring plan (Article 72) and serious-incident runbook (Article 73). CE marking application prepared.

    Every deliverable is signed off by a senior Alice Labs consultant with named ownership in the SOW. There is no offshore build wall, no undisclosed subcontracting, and no juniors billed at senior rates. The pricing model is fixed-scope with transparent day rates — no back-loaded scope creep.

    For enterprises with a shorter runway or narrower scope, Alice Labs runs a 2-week readiness diagnostic as a scoped entry point: inventory, Article 6 triage on the top 3-5 systems, and a written recommendation whether to proceed to a full 12-week programme, defer, or route the work in-house. Roughly one in eight diagnostic engagements ends there — sometimes the answer is that the estate is simpler than the client feared.

    12 / 15Chapter

    Interaction with GDPR, DSA, DORA, and NIS2

    In short

    The AI Act layers on existing EU regulation, it does not replace it. GDPR Article 22 automated-decision-making overlaps with Annex III credit scoring and employment use cases. DORA operational resilience testing applies to financial-sector AI systems. NIS2 supply-chain security obligations cover AI vendors serving essential entities. DSA risk assessments for VLOPs intersect with recommender-system transparency. Alice Labs runs integrated compliance workstreams across all four regimes on financial-services and public-sector engagements.

    The AI Act does not stand alone. Every serious engagement runs an interaction analysis across the four horizontal regimes most likely to overlap.

    • GDPR. Article 22 (automated decision-making with legal or similarly significant effects) overlaps directly with Annex III point 5(b) credit scoring and Annex III point 4 employment scoring. The DPIA under Article 35 and the FRIA under AI Act Article 27 are complementary artefacts. Data governance evidence under AI Act Article 10 must be consistent with lawfulness-of-processing evidence under GDPR Article 6.
    • DORA (Regulation (EU) 2022/2554). Financial-sector AI systems that are ICT third-party services fall inside DORA operational resilience testing, incident classification, and register-of-information duties. AI Act Article 15 robustness testing and DORA threat-led penetration testing overlap in scope for trading, credit, and payments AI.
    • NIS2 (Directive (EU) 2022/2555). Essential and important entities have supply-chain security obligations under Article 21 that reach their AI vendors. A hospital deploying diagnostic AI must reflect that supply-chain in its NIS2 register; the vendor's AI Act evidence feeds the hospital's NIS2 evidence.
    • DSA (Regulation (EU) 2022/2065). Very Large Online Platforms and Very Large Online Search Engines have Article 34 systemic-risk assessments that overlap with AI Act recommender-system transparency obligations. Content moderation AI carries obligations under both regimes.

    For Nordic financial services engagements, Alice Labs runs a single integrated compliance workstream across AI Act, GDPR, and DORA — the artefacts share evidence, and running them as separate projects duplicates work and creates internal inconsistency. For public-sector engagements, NIS2 supply-chain obligations shape the vendor-selection criteria that then feed the AI Act deployer file.

    13 / 15Chapter

    AI literacy obligations under Article 4

    In short

    Article 4 requires providers and deployers to take measures to ensure sufficient AI literacy of staff and other persons dealing with AI systems on their behalf, taking into account their technical knowledge, experience, education, training, and the context of use. The obligation has been enforceable since 2 February 2025. There is no prescribed curriculum, but evidence of a role-based training programme is expected. Alice Labs runs literacy tracks for executives, product, engineering, and risk.

    Article 4 is a small article that has outsized operational reach. It applies to every provider and deployer, regardless of high-risk status, and became enforceable on 2 February 2025 — the same date as the Article 5 prohibited-practice ban.

    The regulation deliberately does not prescribe a curriculum. What is required is "sufficient AI literacy" proportionate to the role, technical background, and context of use. The evidence expected by market surveillance authorities is:

    • A documented training programme with role-based tracks, updated as the AI estate evolves.
    • Records of who has completed training and when, retained for the working duration of the AI systems in question.
    • Content that covers the specific AI systems the trainee interacts with, not generic AI literacy slideware.
    • Integration with human oversight duties under Article 14 — trained operators are the precondition for effective human oversight.

    Alice Labs runs role-based literacy tracks on every engagement:

    • Executives — regulatory landscape, risk exposure, board-level decisions, and the two questions to ask before signing off an AI deployment.
    • Product and business owners — Article 6 classification, intended purpose specification, FRIA where applicable, and how to write a compliant SOW.
    • Engineering — Article 9-15 obligations translated into build requirements, logging under Article 12, robustness testing under Article 15.
    • Risk, legal, and compliance — post-market monitoring, serious- incident reporting, EU database registration, and interaction with GDPR / DORA / NIS2.
    14 / 15Chapter

    Nordic and cross-border considerations

    In short

    Sweden, Denmark, and Finland apply the AI Act in full as EU Member States. Norway and Iceland — inside the EEA but not the EU — will incorporate the AI Act into the EEA Agreement with an expected lag; the Norwegian government has confirmed intent, and preparatory work is ongoing. Alice Labs is Stockholm-headquartered and works internationally across the single market with no fake local offices. Nordic engagements typically require cross-border deployer analysis under Article 26.

    The Nordic regulatory posture in mid-2026:

    • Sweden, Denmark, Finland. Full application as EU Member States. Market surveillance authorities designated by 2 August 2025. Swedish designation routed largely through IMY (data protection authority) and sectoral regulators (Finansinspektionen for financial services, MPA for medical). Finnish designation through Traficom and Traficom-adjacent authorities. Danish designation through Datatilsynet and sectoral regulators.
    • Norway. Inside the EEA but not the EU. The Norwegian government (Regjeringen.no) has confirmed that the AI Act will be incorporated into the EEA Agreement, though the incorporation is expected to lag behind EU application by 6-18 months per typical EEA precedent. Enterprises operating in Norway should plan against the EU calendar as a working assumption and confirm the EEA-adopted date closer to the event.
    • Iceland. Same EEA path as Norway.
    • United Kingdom. Outside the EU and outside the EEA. The UK has taken a principles-based, sectoral approach that diverges from the AI Act. UK enterprises selling into the EU are captured by AI Act Article 2 as third-country providers regardless of the domestic UK regime.

    Alice Labs is Stockholm-headquartered and works internationally across the single market. We do not run fake local offices in Oslo, Copenhagen, or Helsinki. On cross-border Nordic engagements — a Swedish bank selling into Norway, a Finnish HR-tech vendor serving Danish employers — the deployer analysis under Article 26 is often the deciding factor in project scope, and it needs to be run per jurisdiction of use, not per jurisdiction of provider establishment.

    15 / 15Chapter

    How to choose an EU AI Act consultant

    In short

    Four filters separate real EU AI Act consultants from Big 4 pyramid teams and adjacent regulatory shops: (1) ask for evidence of a full Annex IV technical documentation package delivered end-to-end, not a template; (2) verify a senior-only staffing model — named engineers and consultants in the MSA, no offshore juniors; (3) confirm workflow-embedded delivery inside the client build team, not slide-deck consulting; (4) demand transparent fixed-scope pricing with published rate cards, not on-request quotes.

    The EU AI Act consulting market grew fast in 2024-2026 and now contains three kinds of firms. Big 4 practices, adjacent regulatory shops from GDPR and DORA backgrounds, and AI-native boutiques that added a compliance workstream to existing build engagements. Buyer education is uneven and the fit between claim and delivered evidence is often poor.

    Four filters to run against any prospective consultant:

    • Ask for a shipped Annex IV package. A real EU AI Act consultant can show you (redacted) a full Annex IV technical documentation package they built for a client. Not a template. Not a table of contents. The full 60-120 page artefact with risk management records, data governance evidence, and human oversight designs. If they cannot show one, they have not delivered one.
    • Verify senior-only staffing. Named individuals in the MSA with substitution requiring client approval. Ask who will be on the ground in Week 5 when the Annex IV drafting starts. If the answer requires qualification, you are buying pyramid staffing dressed as end-to-end.
    • Confirm workflow-embedded delivery. The consultant sits inside the build team during technical documentation work. They observe the actual system being built, they interview the engineers, and they produce evidence that reflects the real product. Slide-deck consultants write generic content mapped to your logo.
    • Demand transparent pricing. Published day rates, fixed-scope proposals per phase, no on-request quoting theatre. Compliance work has known scope and known effort — a firm that cannot publish rates is protecting margin, not serving a genuinely bespoke need.

    For a full ranked comparison of the EU AI Act consulting market see our EU AI Act compliance consultants 2026 guide and the CIO-audience view at best AI governance consultants for CIOs 2026. For the operational checklist that any engagement must close see the EU AI Act compliance checklist 2026.

    Alice Labs is a Stockholm-headquartered enterprise AI consultancy delivering EU AI Act readiness across 100+ production AI implementations since 2023. Senior-only staffing. Workflow-embedded delivery. Transparent fixed-scope pricing. Book a 2-week readiness diagnostic to receive a written recommendation within three weeks of kickoff.

    About the Authors & Reviewers

    Published
    Written by
    Eric Lundberg - Co-Founder, Alice Labs at Alice Labs
    Eric Lundberg

    Co-Founder, Alice Labs

    Co-Founder at Alice Labs. Builds AI automation, agent workflows and integration systems that hold up in real business operations.

    • AI automation & agent systems lead
    • Workflow design across 100+ deployments
    • Specialist in RAG, integrations & APIs
    Reviewed by
    Linus Ingemarsson - Co-Founder, Alice Labs at Alice Labs
    Linus Ingemarsson

    Co-Founder, Alice Labs

    Co-Founder at Alice Labs. Author of 7 research reports on AI adoption, governance and labor markets cited across EU, OECD and US benchmarks.

    • 8+ years in AI strategy & implementation
    • Top-5 AI Speaker, Sweden (Mindley 2025)
    • 100+ enterprise AI engagements
    Published
    Reviewed for technical accuracy, methodology and source integrity.·All claims trace to public sources cited in-line.

    Frequently Asked Questions

    What is EU AI Act compliance consulting?

    EU AI Act compliance consulting is advisory work that helps enterprises meet Regulation (EU) 2024/1689. It covers AI system inventory, Article 6 classification, Annex III gap analysis, technical documentation to Annex IV, risk management, human oversight design, conformity assessment, EU database registration, and post-market monitoring. Alice Labs delivers this workflow-embedded, with senior consultants only, across 100+ production AI implementations since 2023, and aligns programmes to the deferred 2 December 2027 Annex III deadline.

    When do the main EU AI Act obligations apply?

    The regulation entered into force on 1 August 2024. Prohibited practices under Article 5 and AI literacy under Article 4 have been enforceable since 2 February 2025. GPAI obligations for new models applied from 2 August 2025. Following the AI Omnibus political agreement of 7 May 2026, high-risk Annex III systems must comply by 2 December 2027, and Annex I product-embedded systems by 2 August 2028. Existing GPAI models on the market before 2 August 2025 must comply by 2 August 2027. Alice Labs sequences engagements against these milestones.

    Who needs an EU AI Act consultant?

    Any provider, deployer, importer, or distributor placing an AI system on the EU market or whose output is used in the Union is in scope under Article 2. That includes non-EU vendors serving EU customers, deployers using third-party AI in Annex III use cases, and enterprises integrating GPAI models. Alice Labs typically engages with Nordic and European enterprises in financial services, healthcare, industrial manufacturing, HR technology, and public-sector contexts where Article 6 classification is non-trivial.

    How much does EU AI Act compliance consulting cost?

    Costs vary by AI estate size, but Alice Labs runs transparent fixed-scope engagements: a 2-week readiness diagnostic, a 12-week programme covering inventory through conformity assessment for a mid-sized estate, and ongoing post-market monitoring retainers. We publish rate cards rather than quoting on request, and we do not bill juniors at senior rates. Programme cost is typically a fraction of the up to EUR 15M or 3% global turnover fine for high-risk breaches under Article 99, and a fraction of the EUR 35M / 7% ceiling for prohibited-practice breaches.

    What is the difference between a high-risk and a general-purpose AI system?

    High-risk systems are defined by Article 6: safety components in Annex I products or use cases listed in Annex III (biometrics, employment, credit scoring, law enforcement, and so on). General-purpose AI (GPAI) models are foundation models trained on broad data with general capability, governed by Articles 51-55. A single deployment can trigger both regimes: a bank fine-tuning a GPAI model for credit scoring faces GPAI downstream duties and Annex III obligations. Alice Labs maps both layers in the Article 6 memo.

    Does the EU AI Act apply to companies outside the EU?

    Yes. Article 2 extends the regulation to providers established outside the Union that place AI systems on the EU market, and to any provider or deployer whose AI output is used in the Union. A US SaaS vendor selling to EU enterprises, or a UK deployer serving EU customers, is in scope. Third-country providers must appoint an authorised representative in the Union under Article 22. Alice Labs advises non-EU clients on scope determination and authorised-representative arrangements.

    What did the AI Omnibus political agreement of 7 May 2026 actually change?

    The Omnibus deferred implementation deadlines. The Annex III high-risk deadline moved from 2 August 2026 to 2 December 2027, and the Annex I product-embedded deadline to 2 August 2028. Substantive law did not change — Article 6 classification, Articles 9-15 obligations, and the Article 99 penalty ceilings remain intact. Enterprises that waited for the Omnibus expecting a rewrite are now compressing the same evidence-build work into a 16-month window.

    Who runs a Fundamental Rights Impact Assessment (FRIA)?

    Under Article 27, FRIAs are a deployer duty for public-sector bodies, private operators providing public services (education, healthcare, employment services, housing, essential public infrastructure), and private-sector deployers of credit scoring and life/health insurance risk assessment systems. Providers cannot pre-write it because only the deployer knows the affected population, the frequency of decisions, and the actual human oversight in place. Alice Labs runs FRIA and DPIA as an integrated workstream on in-scope engagements.

    How does the EU AI Act interact with GDPR?

    The AI Act layers on GDPR, it does not replace it. Article 22 GDPR automated decision-making overlaps with Annex III credit scoring and employment scoring. The DPIA under GDPR Article 35 complements — but does not replace — the FRIA under AI Act Article 27. Data governance evidence under AI Act Article 10 must be consistent with lawfulness-of-processing under GDPR Article 6. Alice Labs runs integrated compliance workstreams so evidence is shared, not duplicated.

    What is the conformity assessment route for a typical high-risk AI system?

    Most Annex III high-risk systems follow the Annex VI internal control route: the provider verifies compliance against harmonised standards, prepares the Annex IV technical documentation, and self-issues the EU declaration of conformity. Remote biometric identification systems under Annex III point 1(a) require Annex VII third-party assessment by a notified body designated under Article 31. Both routes end in an EU declaration of conformity, CE marking, and EU database registration under Article 71.

    What has to be in the Annex IV technical documentation?

    Annex IV requires: a general description of the AI system; a detailed description of elements and development process (methods, choices, design specifications, computational resources, dataset descriptions); detailed information on monitoring, functioning, and control; a description of the risk management system under Article 9; the changes made to the system through its lifecycle; the harmonised standards applied or the technical solutions adopted; a copy of the EU declaration of conformity; and a detailed description of the post-market monitoring system. Alice Labs delivers this as a 60-120 page package per system.

    How does GPAI compliance work for downstream integrators?

    Enterprises integrating a foundation model (GPT, Claude, Gemini, Mistral, Llama) are usually acting as a provider of a distinct AI system, so the seven high-risk obligations flow through if the resulting system is Annex III. Where the modification is substantial under Article 25, the downstream integrator may itself become a provider of a new GPAI model with Chapter V duties. Providers of the upstream model owe the integrator sufficient documentation under Article 53(1)(b). Alice Labs runs this analysis on every downstream integration in scope.

    What is a serious incident under Article 73 and how fast must it be reported?

    A serious incident is defined in Article 3(49) as an incident or malfunctioning leading to death, serious harm to health, serious and irreversible disruption of critical infrastructure management, infringement of Union fundamental-rights obligations, or serious harm to property or environment. Reporting deadlines to national market surveillance authorities: within 15 days of the provider becoming aware in general; within 10 days for incidents involving death; and within 2 days for widespread fundamental-rights infringement or serious critical-infrastructure disruption.

    Does Norway apply the EU AI Act?

    Not yet in force domestically. Norway is inside the EEA but not the EU. The Norwegian government (Regjeringen.no) has confirmed intent to incorporate the AI Act into the EEA Agreement, with incorporation expected to lag EU application by 6-18 months per typical EEA precedent. Enterprises operating in Norway should plan against the EU calendar as a working assumption and confirm the EEA-adopted date closer to the event. Norwegian entities serving EU customers are already in scope under Article 2 regardless of EEA timing.

    What are the AI literacy obligations under Article 4?

    Article 4 requires providers and deployers to take measures to ensure sufficient AI literacy of staff and other persons dealing with AI systems on their behalf, proportionate to their technical knowledge, experience, education, training, and the context of use. The obligation has been enforceable since 2 February 2025. There is no prescribed curriculum, but market surveillance authorities expect a documented role-based training programme with completion records. Alice Labs runs literacy tracks for executives, product, engineering, and risk.

    How large are the AI Act fines relative to GDPR?

    The AI Act ceiling is higher than GDPR. Prohibited-practice breaches under Article 99(3) can reach EUR 35M or 7% of global annual turnover, whichever is higher — versus GDPR's 4% or EUR 20M cap. High-risk obligation breaches sit at EUR 15M or 3%. Supply of incorrect information sits at EUR 7.5M or 1%. SMEs face the same percentages capped at the lower of the two numbers, per Article 99(6). Fines are the floor of the enforcement toolkit — prohibition orders and market withdrawal under Article 74 are the ceiling.

    Can Alice Labs help with just one AI system, not the full estate?

    Yes. Single-system engagements are the most common scoping shape for enterprises that already have a compliance function and need targeted senior expertise on a specific high-risk system. A single-system engagement runs 6-8 weeks and delivers Article 6 memo, Annex IV technical documentation, human oversight design, conformity assessment route decision, and the post-market monitoring plan. Ideal when the system is on the critical path but the surrounding estate is out of scope for this cycle.

    How does the AI Act layer on DORA for financial services?

    Financial-sector AI systems that qualify as ICT third-party services fall inside DORA (Regulation (EU) 2022/2554) — operational resilience testing, incident classification, and register-of-information duties. AI Act Article 15 accuracy, robustness, and cybersecurity requirements overlap with DORA threat-led penetration testing. Alice Labs runs financial-services engagements as a single integrated workstream across AI Act, GDPR, and DORA so evidence is shared and internal consistency holds across regulators.

    Do I need a notified body?

    For most Annex III high-risk systems, no. The Annex VI internal control route allows the provider to verify compliance against harmonised standards and self-issue the EU declaration of conformity. Notified body involvement under Annex VII is mandatory only for remote biometric identification systems (Annex III point 1(a)) and for AI systems that are safety components of Annex I products requiring third-party assessment. Alice Labs makes the route decision in Weeks 9-12 of the standard engagement.

    How do I get started with Alice Labs?

    The most common entry point is a 2-week readiness diagnostic. We scope the estate, run Article 6 triage on the top 3-5 AI systems, and produce a written recommendation on whether to proceed to a full 12-week programme, defer, or route the work in-house. If the diagnostic warrants proceeding, we contract the 12-week programme under the same MSA. If it does not, the engagement ends there with no penalty. Delivered by the same senior team who would run the full programme.

    Where is Alice Labs based and where do you deliver?

    Alice Labs is Stockholm-headquartered and works internationally across the single market. We deliver in Sweden, Denmark, Finland, Norway (via EEA), Iceland, and the broader EU. We do not run fake local offices in Oslo, Copenhagen, or Helsinki — engagements are staffed from Stockholm with on-site presence where the work needs it. Founders Eric Lundberg and Linus Ingemarsson remain client-facing on every engagement.

    Previous in AI Governance & Compliance

    Best AI Governance Consultants for CIOs 2026 | Alice Labs

    Further reading

    Related reading

    pillar

    EU AI Act Compliance Consultants 2026

    Ranked buyer's guide to the EU AI Act consulting market — Big 4, boutiques, and regulatory shops compared against Annex IV delivery evidence.

    deepdive

    EU AI Act Compliance Checklist 2026

    Operational checklist for Articles 6-17, 26, and 50 — the compliance floor for any high-risk AI system in the EU.

    deepdive

    EU AI Act Timeline 2026

    Full implementation calendar including the AI Omnibus deferrals of 7 May 2026 — Annex III to December 2027, Annex I to August 2028.

    deepdive

    EU AI Act Risk Categories

    The four-tier risk model — prohibited, high-risk, limited-risk transparency, minimal risk — with worked classification examples.

    deepdive

    EU AI Act for Financial Services

    How Annex III credit scoring and insurance risk assessment obligations layer on DORA, GDPR, and existing sectoral supervisory expectations.

    deepdive

    AI Risk Management Framework

    The Article 9 risk management system as a continuous iterative process — templates, controls, and integration with ISO 42001 and NIST AI RMF.

    deepdive

    End-to-End AI Consulting

    The single-partner delivery model — how EU AI Act compliance fits inside a full-lifecycle enterprise AI engagement.

    Sources

    1. Regulation (EU) 2024/1689 — Implementation TimelineEuropean Union · artificialintelligenceact.eu“Regulation (EU) 2024/1689 entered into force 1 August 2024. Article 5 prohibited practices and Article 4 AI literacy enforceable from 2 February 2025. GPAI obligations for new models from 2 August 2025. AI Omnibus political agreement of 7 May 2026 deferred Annex III high-risk deadline to 2 December 2027 and Annex I product-embedded deadline to 2 August 2028.”(accessed 2026-08-04)
    2. AI Act Article 6 — Classification Rules for High-Risk AI SystemsEuropean Union · artificialintelligenceact.eu“Article 6 defines the two-limb high-risk test: Annex I product limb (safety components or products requiring third-party conformity assessment) and Annex III domain limb (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice). Article 6(3) narrow-task exception is voided where the system profiles natural persons.”(accessed 2026-08-04)
    3. AI Act Annex III — High-Risk AI System DomainsEuropean Union · artificialintelligenceact.eu“Annex III lists the eight high-risk domains: biometric identification and categorisation; critical infrastructure management; education and vocational training; employment, worker management, and recruitment; access to essential private and public services; law enforcement; migration, asylum, and border control; administration of justice and democratic processes.”(accessed 2026-08-04)
    4. AI Act Chapter III Section 2 — Requirements for High-Risk AI Systems (Articles 9-15)European Union · artificialintelligenceact.eu“Articles 9-15 impose seven substantive obligations: risk management system (Art. 9), data and data governance (Art. 10), technical documentation (Art. 11 with Annex IV), record-keeping (Art. 12), transparency and information to deployers (Art. 13), human oversight (Art. 14), accuracy, robustness, and cybersecurity (Art. 15).”(accessed 2026-08-04)
    5. AI Act Chapter V — General-Purpose AI Models (Articles 51-55)European Union · artificialintelligenceact.eu“Providers of new GPAI models placed on market from 2 August 2025 must comply immediately; models on market before must comply by 2 August 2027. Systemic-risk models (>=10^25 FLOP training compute) trigger additional Article 55 duties: model evaluation, adversarial testing, serious-incident reporting, cybersecurity protections, energy reporting.”(accessed 2026-08-04)
    6. AI Act Article 26 — Obligations of Deployers of High-Risk AI SystemsEuropean Union · artificialintelligenceact.eu“Deployer obligations under Article 26 apply even when the provider is outside the EU. Deployers must use high-risk systems in accordance with instructions, implement human oversight, ensure input data relevance, keep automatic logs, monitor operation, and inform the provider of serious incidents. Extraterritorial reach under Article 2.”(accessed 2026-08-04)
    7. AI Act Article 27 — Fundamental Rights Impact AssessmentEuropean Union · artificialintelligenceact.eu“Article 27 mandates FRIA for public-sector bodies and private operators providing public services deploying Annex III systems, plus deployers of credit scoring (Annex III point 5(b)) and life/health insurance risk (point 5(c)). FRIA covers affected persons, frequency, harms, human oversight, and remediation. Output notified via AI Office template.”(accessed 2026-08-04)
    8. AI Act Article 43 — Conformity AssessmentEuropean Union · artificialintelligenceact.eu“Annex VI internal control is the default conformity assessment route for most Annex III systems; Annex VII notified body assessment is mandatory for remote biometric identification. EU declaration of conformity and CE marking required before market placement. Registration in the EU database for high-risk AI systems under Article 71.”(accessed 2026-08-04)
    9. AI Act Article 73 — Reporting of Serious IncidentsEuropean Union · artificialintelligenceact.eu“Serious-incident reporting deadlines to national market surveillance authorities: within 15 days of provider becoming aware in general; within 10 days for incidents involving death; within 2 days for widespread fundamental-rights infringement or serious critical-infrastructure disruption. Post-market monitoring plan required under Article 72.”(accessed 2026-08-04)
    10. AI Act Article 99 — PenaltiesEuropean Union · artificialintelligenceact.eu“Three penalty tiers: up to EUR 35M or 7% of global annual turnover for prohibited practices; up to EUR 15M or 3% for high-risk provider and deployer obligation breaches and GPAI duties; up to EUR 7.5M or 1% for supplying incorrect information. SMEs face the same percentages capped at the lower of the two numbers per Article 99(6).”(accessed 2026-08-04)
    11. AI Act Article 4 — AI LiteracyEuropean Union · artificialintelligenceact.eu“Providers and deployers must ensure sufficient AI literacy of staff and contractors operating AI systems, proportionate to technical knowledge, experience, education, training, and context of use. No prescribed curriculum but evidence of a documented role-based training programme is expected. Enforceable since 2 February 2025.”(accessed 2026-08-04)
    12. Regulatory Framework for AIEuropean Commission · European Commission“European Commission overview of the AI Act framework, risk-based approach, and interaction with GDPR, DSA, DORA, and NIS2. The AI Act layers on existing EU regulation and does not replace it. AI Office coordinates enforcement across GPAI and cross-border cases.”(accessed 2026-08-04)
    13. Artificial Intelligence — Policy and EEA PositionGovernment of Norway · Regjeringen.no“Norwegian government confirms intent to incorporate the EU AI Act into the EEA Agreement. Incorporation is expected to lag EU application by 6-18 months per typical EEA precedent. Norwegian entities serving EU customers are already in scope under AI Act Article 2 regardless of EEA timing.”(accessed 2026-08-04)
    14. Alice Labs — ServicesAlice Labs · Alice Labs“Alice Labs is Stockholm-headquartered and delivers EU AI Act compliance consulting across the Nordics and broader Europe. 100+ production AI implementations shipped since 2023. Senior-only staffing, workflow-embedded delivery, transparent fixed-scope pricing, founders client-facing on every engagement.”(accessed 2026-08-04)
    15. EU AI Act Compliance Consultants 2026Alice Labs · Alice Labs“Ranked comparison of the EU AI Act consulting market. Four filters separate real consultants from adjacent shops: shipped Annex IV package evidence, senior-only staffing model, workflow-embedded delivery, transparent fixed-scope pricing with published rate cards.”(accessed 2026-08-04)

    Next scheduled review:

    Ready to Build EU AI Act Evidence, Not Templates?

    Alice Labs has delivered EU AI Act readiness across 100+ production AI implementations since 2023 — Stockholm-headquartered, senior-only staffing, workflow-embedded delivery, transparent fixed-scope pricing. Article 6 classification, Annex III conformity, GPAI duties, and audit-ready evidence aligned to the deferred 2 December 2027 deadline.

    Book an EU AI Act Consultation
    Share

    Get in Touch!

    The lab usually responds within 24 hours.

    Need help with AI?Get in touch