secureskies
Expertise/03 · AI Act & AI Governance

Which AI model runs,
what may it do —
and who is liable?

The transparency obligations of the EU AI Act have applied since 2 August 2026. Most companies do not know how many AI models they use, let alone in which risk class. We record them, classify them, implement the obligations and leave behind an evidence file that holds up in front of the regulator and the auditor.

01 · Starting point

Four risk classes,
six key dates.

The AI Act does not regulate “AI”, it regulates use cases. The same technology is subject to transparency obligations as a customer service chatbot, high-risk in recruitment, and prohibited in emotion recognition at the workplace. Only the classification tells you which obligations apply.

Risk pyramidArt. 5 · Art. 6 · Annex III · Art. 50
Prohibited · Art. 5Manipulation, social scoring, emotion recognition at the workplace. New from 2 December 2026: non-consensual intimate images, CSAM.
High-risk · Art. 6 · Annex I / IIIRecruitment, creditworthiness, critical infrastructure, education, law enforcement. Full provider and deployer obligations.
Transparency obligation · Art. 50Chatbots, synthetic content, deepfakes, emotion recognition. Duty to disclose and to mark, in force since 2 August 2026.
Minimal risk · no specific obligationsSpam filters, recommendation systems, code assistants. What remains: AI literacy under Art. 4, and the GDPR.
Application calendarArt. 113 · as amended by Regulation (EU) 2026/1744
2 February 2025Prohibitions Art. 5, AI literacy Art. 4
2 August 2025GPAI, penalties, supervision
2 August 2026Transparency Art. 50
2 December 2026New prohibitions Art. 5(1)(ba)/(bb); Art. 50(2) deadline for legacy systems
2 December 2027High-risk Annex III
2 August 2028High-risk Annex I (products)
in forceupcoming dateshigh-risk duties
2 February 2025Prohibitions Art. 5, AI literacy Art. 4
2 August 2025GPAI, penalties, supervision
2 August 2026Transparency Art. 50 — in force
2 December 2026New prohibitions Art. 5(1)(ba)/(bb); Art. 50(2) deadline for legacy systems
2 December 2027High-risk Annex III
2 August 2028High-risk Annex I

The Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) postponed only the high-risk dates. Art. 50 was not postponed; the only transition period is the marking obligation under Art. 50(2) for generative systems that were on the market before 2 August 2026, running to 2 December 2026 (Commission guidelines C(2026) 5054, paras. 2 and 153).

02 · Method

The 6-step model.

We treat the AI Act like a security programme, not like a legal opinion: first the inventory, then the class, then the role, then the gap, then the implementation, then the evidence. Stage six does not come to an end. Every new AI system, every model version, every change of role goes through stage one again.

Stage 06 → stage 01 · for every new system, every model version, every change of role↺
Stage 01

Take inventory

Record all AI systems and models, including the bought-in and the unofficial ones: SaaS features, copilots, models inside your own products, shadow AI out of the business units.

AI inventory
Stage 02

Classify

Per system: in scope under Art. 3? Prohibited under Art. 5? High-risk under Art. 6 and Annex I/III? Subject to transparency obligations under Art. 50? GPAI, possibly with systemic risk?

Classification register
Stage 03

Establish the role

Provider, deployer, importer or distributor — often several at once. Anyone who renames a system or substantially modifies it becomes a provider under Art. 25, with everything that follows.

Role matrix
Stage 04

Gap analysis

Obligation by obligation: applicable, met, finding, action. With a key date per obligation and a comparison against existing evidence from the ISMS, the GDPR and NIS2.

Finding register · roadmap
Stage 05

Implement

Technical documentation, risk management, logging, human oversight, transparency notices, FRIA. Run as a programme with a SteerCo and handover to your operations.

Implementation programme
Stage 06

Evidence

One evidence file per system: decisions, date, the people responsible, the proof. Updated each quarter so that management can demonstrate its duty of care.

Evidence file · quarterly report
03 · Obligations

Who must do what —
by role and class.

The matrix is the heart of the gap analysis. It shows at a glance which articles bite for your combination of role and risk class. For the deployer of a bought-in chatbot that is two cells. For the provider of a high-risk system it is the entire row.

Obligations matrixExtract · only the text of the regulation is binding
Risk
management
Data &
documentation
Logging &
oversight
Transparency
Conformity &
registration
Literacy &
fundamental rights
Provider · high-risk
Art. 9
Art. 10 · 11
Annex IV
Art. 12 · 14 · 15
Art. 13 · 50
Art. 17 · 43 · 47 · 48 · 71
Art. 4
Deployer · high-risk
Art. 26(5)
Art. 26(6) logs
Art. 26(1)–(4)
Art. 26(7) · (11) · 50
Art. 26(8) registration (public bodies)
Art. 4 · 27 FRIA
Provider · transparency
—
—
—
Art. 50(1) · (2)
—
Art. 4
Deployer · transparency
—
—
—
Art. 50(3) · (4)
—
Art. 4
GPAI provider
Art. 55 (systemic)
Art. 53 · Annex XI · XII
Art. 55(1)(c)
Art. 53(1)(b) · (d)
Art. 54 authorised representative
Art. 4
All · minimal
—
—
—
—
—
Art. 4
Core obligationMaterial obligationAccompanying obligationNot applicable
04 · Service catalogue

Twelve modules,
singly or as a programme.

Every module has a fixed output document and an article reference. You book what your classification requires — a deployer without a high-risk system does not need module 06. Modules 01 to 09 and 11 are mandates with an output document; modules 10 and 12 are ongoing services. Where a statement of ours needs legal review, it is marked as such.

01

AI inventory & scoping

Art. 3 · Art. 2 scope

Structured recording of all AI systems and models through interviews, contract review, the SaaS register and technical discovery in cloud accounts. The result is an inventory with purpose, data sources, the business unit that deploys it, provider and supply chain for every system. Shadow AI is actively searched for, not merely asked about.

Output
  • AI inventory (register)
  • Scoping memo: in scope / out of scope, with reasons
  • Supply chain overview
ForEvery company using AI
02

Risk classification

Art. 5 · Art. 6 · Annex I / III · Art. 50 · Art. 51

A documented classification for every system: prohibited, high-risk, subject to transparency obligations, minimal — plus GPAI status and systemic risk (10²⁵ FLOPs). We examine the exemption under Art. 6(3) and document it under Art. 6(4) where you rely on it. Borderline cases we mark as borderline and recommend legal review, rather than smoothing them over.

Output
  • Classification register with reasons for every system
  • Art. 6(3) documentation, where used
  • List of borderline cases for legal advice
ForAll; the mandatory basis for modules 04–08
03

Role determination & supply chain

Art. 3(3)–(8) · Art. 25

Provider, deployer, importer, distributor, authorised representative — per system and per contractual relationship. Examined with particular care: when does fine-tuning, white-labelling or a change of purpose make you a provider under Art. 25? Which obligations does your supplier owe you, and are they in the contract?

Output
  • Role matrix per system
  • Art. 25 risk list
  • Contract clause checklist for procurement and legal
ForCompanies that buy AI in and pass it on
04

Prohibition review

Art. 5(1)(a)–(h) · new (ba), (bb) · Art. 5(1a)

A targeted review against the prohibited practices, with the emphasis on the borderline cases: emotion recognition in the workplace, biometric categorisation, manipulative design in customer interfaces. For generative systems, additionally the new practices from 2 December 2026 and the question of whether prohibited outputs are a foreseeable result or a purpose.

Output
  • Review record for each prohibited practice
  • Remediation items with a deadline
  • Escalation recommendation to management, where needed
ForHR tech, retail, security services, generative applications
05

Transparency obligations

Art. 50(1)–(5) · guidelines C(2026) 5054 · Code of Practice 10 June 2026

In force since 2 August 2026. We review and design: the disclosure that a user is interacting with AI; the machine-readable marking of synthetic audio, image, video and text content; deepfake disclosure; informing the people affected where emotion recognition is used. Implemented in your interfaces and output pipelines, not only in a document.

Output
  • Transparency findings per system
  • Disclosure wording and marking specification
  • Evidence of implementation (screenshots, configuration)
ForEvery chatbot, every generative application
DeadlineLegacy systems Art. 50(2): 2 December 2026
06

High-risk · provider obligations

Art. 8–22 · Art. 43 · Art. 47–49 · Art. 71 · Annex IV

The full programme for providers of high-risk systems: risk management system (Art. 9), data governance (Art. 10), technical documentation under Annex IV (Art. 11), logging (Art. 12), instructions for use (Art. 13), human oversight (Art. 14), accuracy, robustness and cybersecurity (Art. 15), quality management (Art. 17), conformity assessment, EU declaration of conformity, CE marking, registration in the EU database. We lead the programme and build the documentation; conformity assessment by a notified body remains that body’s task wherever it is prescribed.

Output
  • Annex IV documentation package
  • Risk management and QMS manual
  • Conformity roadmap to 2 December 2027 / 2 August 2028
ForManufacturers, software providers, groups with in-house development
FormatProgramme mandate with a SteerCo
07

High-risk · deployer obligations & FRIA

Art. 26 · Art. 27

For companies that use high-risk systems: operation in line with the instructions for use, assignment and training of human oversight, control of input data, log retention, informing employees and the people affected. Where Art. 27 bites — public bodies, creditworthiness, insurance pricing — we carry out the fundamental rights impact assessment and interlock it with the DPIA under the GDPR.

Output
  • Deployer obligations register with named owners
  • FRIA report under Art. 27(1)(a)–(f)
  • Human oversight concept and training evidence
ForBanks, insurers, HR, the public sector
Deadline2 December 2027
08

GPAI provider obligations

Art. 51–55 · Annex XI–XIII · GPAI Code of Practice

For companies that make their own foundation models available, or adapt someone else’s far enough to count as a provider: technical documentation, information for downstream providers, copyright policy, summary of the training data. Where there is systemic risk, additionally model evaluation, incident reporting and cybersecurity of the model and its infrastructure.

Output
  • Annex XI/XII documentation
  • Downstream information package
  • Code of Practice reconciliation
ForModel providers, AI product companies
SupervisionEU AI Office
09

AI literacy

Art. 4

Since 2 February 2025, providers and deployers must ensure that their staff are sufficiently AI-literate — graded by role and context. We draw up the literacy concept, run training for management, the business units and the oversight staff, and document attendance in a form that works as evidence.

Output
  • Literacy concept by role
  • Training modules (management, business unit, oversight)
  • Evidence of attendance and content
ForAll providers and deployers
Since2 February 2025, in force
10

Secure AI platform in the cloud

Art. 12 · Art. 15 · Art. 26(6) · service, not a mandate

The obligations on logging, robustness and cybersecurity are infrastructure tasks. We build the environment your AI systems run in: a separate landing zone on AWS or Azure, infrastructure as code with Terraform, Pulumi or Ansible, logging and metrics with Grafana, Prometheus, Datadog or Dynatrace, retention under Art. 26(6). On request with 24/7 operation and a named point of contact.

Output
  • Reference architecture and IaC repository
  • Logging concept with retention periods
  • Handover to operations, or managed service
ForDeployers and providers with their own infrastructure
11

Interfaces · GDPR, NIS2, DORA

Art. 2(7) · Art. 27(4) · ISO/IEC 42001

The AI Act does not stand alone. A FRIA builds on the DPIA, Art. 15 cybersecurity on the ISMS, incident reporting under Art. 73 on the NIS2 and DORA reporting channels. We map the overlaps so that you produce evidence once and use it several times — and we show where a management system to ISO/IEC 42001 makes sense and where it does not.

Output
  • Control mapping AI Act ↔ GDPR ↔ NIS2 ↔ DORA
  • Integrated reporting channel for AI incidents
  • Recommendation on ISO/IEC 42001, with reasons
ForRegulated companies, KRITIS, the financial sector
12

Ongoing AI governance

Stage 06 of the model · Art. 9(2) ongoing · Art. 72 · service, not a mandate

After the implementation, running the governance begins: keep the inventory current, classify new systems, reassess model versions, post-market monitoring, follow up incidents. The management receives a report each quarter on a fixed date — in the same format as the cyber governance report, so that both are discussed in one meeting.

Output
  • Quarterly AI governance report
  • Updated inventory and registers
  • Evidence file per system
ForLeadership team, Beirat (advisory board), Aufsichtsrat (supervisory board)
05 · Consequence

What is at
stake.

Art. 99 grades the fines by severity. In each case the higher amount applies — the fixed sum or the percentage of worldwide turnover in the preceding year; for SMEs, the lower one. On top of that comes what no schedule of fines captures: a system withdrawn from the market, the standstill of a process that depends on it, and the personal question to management of whether it can evidence its duty of care.

Fine ranges under Art. 99Maximum amounts · fixed sum or share of turnover
Breach of the prohibitions under Art. 5
€35mor 7 % of turnover
Breach of the other obligations (providers, deployers, importers, distributors, notified bodies)
€15mor 3 % of turnover
Incorrect, incomplete or misleading information given to authorities
€7.5mor 1 % of turnover

Secureskies does not provide legal advice. We structure, document and implement technically; legal assessments in borderline cases, conformity assessment by notified bodies and coordination with the regulator happen with your legal department or law firm. Official self-assessment: the European Commission’s AI Act Service Desk. Harmonised standards (CEN-CENELEC JTC 21) have not yet been published; the Commission’s guidelines on high-risk classification exist as a draft dated 19 May 2026.

Do you know how many
AI models run in your organisation?