AI Capability · HellasAGI PatentZeus Consulting has acquired certified technical capability for the HellasAGI AI patent — enabling advanced AI in complex EU research projects.
Learn more
Back to Insights
Technology & Policy April 2026 11 min

EU AI Act Compliance Guide for SMEs and Research Organisations in 2026

The EU AI Act is the world's first binding AI regulation — and its high-risk AI system requirements apply from August 2026. This guide explains risk classification, conformity assessment, technical documentation, and human oversight obligations for organisations deploying AI systems.

Regulation (EU) 2024/1689 — the EU Artificial Intelligence Act — is the world's first comprehensive, legally binding framework governing artificial intelligence systems. It entered into force on 1 August 2024 and is being phased in over a 36-month transition period. For organisations that develop, import, or deploy AI systems in the EU, understanding your obligations under this Regulation is now a legal necessity — not an option.

Key dates: Prohibited AI practices banned from 2 February 2025. GPAI model obligations applicable from 2 August 2025. High-risk AI system requirements fully applicable from 2 August 2026. Penalties: up to €35 million or 7% of global annual turnover for the most serious violations.

The Risk-Based Classification System

The EU AI Act structures obligations around a four-tier risk pyramid. Understanding which tier your AI system falls under is the first and most critical compliance step.

  • Unacceptable Risk (Prohibited): AI systems that pose an unacceptable threat to fundamental rights are banned entirely. Examples: social scoring by public authorities, real-time biometric identification in public spaces (with narrow exceptions), AI that manipulates persons through subliminal techniques, and systems that exploit vulnerabilities of specific groups.
  • High Risk: AI systems deployed in eight defined critical areas face the most rigorous obligations. Critical infrastructure (electricity, water, transport); education (determining access, assessment); employment (recruitment, performance monitoring, work allocation); essential services (credit scoring, insurance); law enforcement; migration and border management; administration of justice; democratic processes.
  • Limited Risk: AI systems with specific transparency risks — chatbots, emotion recognition, deep fakes — must disclose their AI nature to users but face no further mandatory obligations.
  • Minimal Risk: The vast majority of AI systems — spam filters, recommender systems, AI in video games — have no mandatory requirements but are encouraged to follow voluntary codes of conduct.

Obligations for High-Risk AI System Providers

If your organisation develops and places on the market (or puts into service) a high-risk AI system, you are a Provider under the AI Act and face the following obligations:

  • Risk management system: Establish, implement, document and maintain a risk management system throughout the AI system's lifecycle.
  • Data governance: Training, validation and testing data must meet quality criteria — representative, free from errors, appropriate for the intended purpose.
  • Technical documentation: Comprehensive documentation of the system's design, development choices, performance metrics, and post-market monitoring plan.
  • Record-keeping: Automatic logging of events during operation to enable post-incident analysis.
  • Transparency and user information: Clear instructions for use, including system capabilities and limitations, accuracy metrics, and human oversight requirements.
  • Human oversight: AI systems must be designed to allow effective human oversight, including the ability to override, interrupt, or correct system outputs.
  • Accuracy and robustness: Systems must achieve appropriate levels of accuracy and be resilient to errors and adversarial attacks.
  • Registration: High-risk AI systems must be registered in the EU database before being placed on the market.

Obligations for Deployers

Deployers — organisations that use a high-risk AI system in a professional context — also have specific obligations that many organisations are not yet aware of:

  • Use the system only as intended according to provider instructions.
  • Ensure human oversight by designating competent individuals with authority to interpret, override, and where necessary shut down the system.
  • Conduct a Fundamental Rights Impact Assessment (FRIA) before deploying high-risk systems in certain areas (public bodies, banking, insurance).
  • Notify and inform affected individuals, staff works councils, and supervisory bodies as required.
  • Report serious incidents and malfunctions to the market surveillance authority.
  • Retain logs generated by the system for minimum periods specified in the Act.

General Purpose AI (GPAI) Models

Large foundation models with broad applicability — including large language models, multimodal AI, and foundation models used as components in other AI systems — face obligations under Title VIII of the AI Act, applicable from August 2025. Providers must maintain technical documentation, provide information to downstream AI system providers, and comply with EU copyright law. Models trained with compute exceeding 10^25 FLOPs face additional systemic risk obligations including adversarial testing and mandatory incident reporting.

Practical Compliance Roadmap for SMEs and Research Organisations

  • Step 1 — AI System Inventory: Catalogue all AI systems currently developed, deployed, or procured. Include purpose, data inputs, outputs, decision-making authority, and affected groups.
  • Step 2 — Risk Classification: Map each system against the AI Act's prohibited, high-risk, limited risk, and minimal risk categories.
  • Step 3 — Gap Analysis: For high-risk systems, identify which obligations are not yet met and what actions are required.
  • Step 4 — Documentation: Begin building technical documentation, risk management records, and data governance frameworks.
  • Step 5 — Human Oversight: Review existing processes to ensure adequate human oversight mechanisms are in place.
  • Step 6 — Ongoing Monitoring: Establish post-market monitoring and incident reporting procedures.

Zeus Consulting provides structured EU AI Act compliance assessments for organisations across Europe — including AI system inventory, risk classification, gap analysis, and compliance roadmaps. Contact our team to arrange an initial consultation.

ZEUS Consulting · Subject-matter expertise

Meet the experts behind our advisory work.

Explore the documented expertise that connects ZEUS Consulting’s services with European programmes, project roles and practical insights.