What Applies, and When
The EU AI Act (Regulation (EU) 2024/1689) has been phasing in since it entered into force on 1 August 2024. Prohibited practices applied from 2 February 2025, general-purpose AI (GPAI) model obligations from 2 August 2025, and provider and deployer obligations for Annex III high-risk AI systems apply from 2 August 2026.
A so-called Digital Omnibus package has proposed pushing some Annex III use cases to December 2027. A clear distinction matters here:
A proposed delay has no legal effect until it is finalised. Slowing your preparation on that assumption carries real risk. Penalties for high-risk violations reach EUR 15 million or 3% of global annual turnover, whichever is higher.
Determining Whether Your Product Is High-Risk
There are two routes to a high-risk classification. Annex I covers AI embedded as a safety component in products already regulated by EU harmonisation legislation, such as the Machinery Regulation or the Medical Device Regulation (MDR). Annex III covers standalone use cases across eight areas including biometrics, critical infrastructure, education, employment, access to essential services, and law enforcement.
Exporters most often misjudge these borderline cases:
What Providers Must Have in Place
From there the sequence runs: conformity assessment (Annex VI internal control or Annex VII) → EU declaration of conformity (Art. 47) → CE marking (Art. 48) → EU database registration (Art. 49). Non-EU providers must appoint an authorised representative in the Union (Art. 22).
In practice this takes three to six months. Documentation gap analysis alone runs four to six weeks, data governance remediation six to ten weeks, and Notified Body involvement extends the timeline further.
Obligations for Deployers
Even if your EU subsidiary or partner only uses the AI, Art. 26 obligations apply. These include following the instructions for use, ensuring input data is relevant insofar as it is under your control, monitoring operation, retaining logs for at least six months, and informing workers before deploying AI in the workplace. Serious incidents must be reported to the provider and market surveillance authorities (Art. 73), and certain deployers such as public bodies must also carry out a fundamental rights impact assessment (Art. 27).
A 90-Day Plan You Can Start Now
The key to controlling cost is reuse. Deliverables from Korea's AI Framework Act, which took effect on 22 January 2026, along with privacy impact assessments and ISMS-P certification materials, overlap substantially. ISO/IEC 42001 certification in particular maps directly onto the Art. 17 quality management system requirement.
Prepare With POLYGLOTSOFT
The largest expense in conformity assessment is rarely the audit fee. It is the engineering rework needed to reconstruct documentation and logs after the fact. POLYGLOTSOFT builds data lineage tracking, audit log schemas, human oversight touchpoints, and model version control into the architecture from the design phase. We draw on documentation practices proven in production across smart factory vision inspection, logistics forecasting, and enterprise generative AI. If you are preparing for EU export or want to understand the regulatory gaps in an existing AI system, we would be glad to talk.
