Back to Blog
AI

EU AI Act High-Risk Obligations Take Effect: Conformity Assessment and Technical Documentation for Exporters

A practical breakdown of the EU AI Act high-risk obligations applying from 2 August 2026, what the Digital Omnibus does and does not delay, and the technical documentation, logging and conformity assessment requirements facing providers and deployers. Includes a 90-day preparation plan for exporters.

POLYGLOTSOFT Tech Team2026-08-278 min read0
EU AI ActHigh-Risk AIConformity AssessmentCE MarkingAI Regulation

What Applies, and When

The EU AI Act (Regulation (EU) 2024/1689) has been phasing in since it entered into force on 1 August 2024. Prohibited practices applied from 2 February 2025, general-purpose AI (GPAI) model obligations from 2 August 2025, and provider and deployer obligations for Annex III high-risk AI systems apply from 2 August 2026.

A so-called Digital Omnibus package has proposed pushing some Annex III use cases to December 2027. A clear distinction matters here:

  • Under discussion for adjustment: certain standalone Annex III use cases, and the timing for product-embedded AI (Annex I)
  • Not under adjustment: prohibited practices (Art. 5), GPAI model obligations, and market surveillance and incident reporting for systems already placed on the EU market
  • A proposed delay has no legal effect until it is finalised. Slowing your preparation on that assumption carries real risk. Penalties for high-risk violations reach EUR 15 million or 3% of global annual turnover, whichever is higher.

    Determining Whether Your Product Is High-Risk

    There are two routes to a high-risk classification. Annex I covers AI embedded as a safety component in products already regulated by EU harmonisation legislation, such as the Machinery Regulation or the Medical Device Regulation (MDR). Annex III covers standalone use cases across eight areas including biometrics, critical infrastructure, education, employment, access to essential services, and law enforcement.

    Exporters most often misjudge these borderline cases:

  • Manufacturing equipment control: Plain process optimisation or yield prediction is usually not high-risk. But once the AI participates in a machine safety function, such as cobot collision avoidance or press safety decisions, it becomes high-risk via the Annex I route and requires Notified Body involvement.
  • Recruitment: CV screening and interview scoring are clearly high-risk. The argument that "the AI only recommends and a human decides" holds only if you meet the Art. 6(3) exemption conditions and document and register that assessment.
  • Credit scoring: Evaluating an individual's creditworthiness is high-risk, though financial fraud detection is carved out.
  • White-label supply: If an EU partner resells under its own trademark, that company becomes the provider (Art. 25). In practice, however, the contractual duty to supply technical documentation still lands on the original developer.
  • What Providers Must Have in Place

  • Risk management system (Art. 9): an iterative process across the full lifecycle
  • Data governance (Art. 10): documented representativeness and bias checks for training, validation and testing data
  • Technical documentation (Art. 11, Annex IV): nine prescribed items, and by far the largest documentation workload
  • Automatic logging (Art. 12): an event record design that supports traceability
  • Transparency, human oversight and robustness (Art. 13-15), plus a quality management system (Art. 17)
  • From there the sequence runs: conformity assessment (Annex VI internal control or Annex VII) → EU declaration of conformity (Art. 47) → CE marking (Art. 48) → EU database registration (Art. 49). Non-EU providers must appoint an authorised representative in the Union (Art. 22).

    In practice this takes three to six months. Documentation gap analysis alone runs four to six weeks, data governance remediation six to ten weeks, and Notified Body involvement extends the timeline further.

    Obligations for Deployers

    Even if your EU subsidiary or partner only uses the AI, Art. 26 obligations apply. These include following the instructions for use, ensuring input data is relevant insofar as it is under your control, monitoring operation, retaining logs for at least six months, and informing workers before deploying AI in the workplace. Serious incidents must be reported to the provider and market surveillance authorities (Art. 73), and certain deployers such as public bodies must also carry out a fundamental rights impact assessment (Art. 27).

    A 90-Day Plan You Can Start Now

  • Days 1-30 — AI asset inventory: Tabulate every model, use case, data flow, whether EU users are involved, and whether you act as provider or deployer.
  • Days 31-60 — Classification and documentation gap analysis: Turn the nine Annex IV items into a checklist and compare them against what you actually have.
  • Days 61-90 — Prioritised remediation: Tackle the items that require engineering rework first, such as log schemas, human oversight interfaces, and data cards.
  • The key to controlling cost is reuse. Deliverables from Korea's AI Framework Act, which took effect on 22 January 2026, along with privacy impact assessments and ISMS-P certification materials, overlap substantially. ISO/IEC 42001 certification in particular maps directly onto the Art. 17 quality management system requirement.

    Prepare With POLYGLOTSOFT

    The largest expense in conformity assessment is rarely the audit fee. It is the engineering rework needed to reconstruct documentation and logs after the fact. POLYGLOTSOFT builds data lineage tracking, audit log schemas, human oversight touchpoints, and model version control into the architecture from the design phase. We draw on documentation practices proven in production across smart factory vision inspection, logistics forecasting, and enterprise generative AI. If you are preparing for EU export or want to understand the regulatory gaps in an existing AI system, we would be glad to talk.

    Need Technical Consultation?

    Our expert consultants in smart factory, AI, and logistics automation will analyze your requirements.

    Request Free Consultation