EU AI Act Field Manual
Provable Compliance, Audit-Ready Evidence, and the Post-Omnibus Rules of the Game
Part of AI Literacy Compliance Kit

Why EU AI Act Compliance Matters
In the evolving digital landscape, launching or managing an AI system without a compliance strategy is like driving a supercar blindfolded. The EU AI Act isn’t just a localised set of rules—it is the new global benchmark for artificial intelligence regulation. Organisations worldwide that deploy or sell AI within the European market must align with these strict legal mandates or face staggering penalties of up to €35 million or 7% of global annual turnover.
Beyond avoiding historic fines, AI compliance is quickly becoming a massive competitive differentiator. Companies that bake transparency, accountability, and robust governance into their models early will win the trust of enterprise clients, investors, and consumers alike. AI compliance isn’t a roadblock; it’s the foundation of sustainable innovation.
EU AI Act Field Manual: What’s inside
Twenty-two chapters. Five parts. One test running through all of it: could you hand your AI compliance file to a sceptical stranger with legal powers, leave the room, and let it speak for itself?
Every chapter ends with the exact list of documents an auditor will ask for, and the free toolkit turns those lists into editable templates.
Introduction: Compliance You Can Prove
Why understanding the law and demonstrating compliance are different jobs, and why this book only cares about the second. The state of play after the Digital Omnibus: what is in force, what moved, what is coming. Who this book is for, and who should read something else.
Part I — The Regulatory Landscape
1. The Architecture of the AI Act. The two ideas that organise the whole Regulation: obligations scale with risk, and they attach to roles, not technologies. Why most companies are deployers, and why that matters far less than they hope. You leave with the questions your inventory must answer.
2. Definitions That Decide Everything. Where the AI system definition actually draws its line, and why your twelve-year-old credit scorecard is probably inside it. Models versus systems, substantial modification, and Article 25, the quiet mechanism that turns deployers into providers without telling them. The six misclassifications that cost real money.
3. The Timeline as It Actually Stands. The post-Omnibus calendar, stated plainly: what applied from 2025, what arrives in August 2026, what moved to December 2027 and August 2028. How to build a compliance calendar that runs backwards from each date. And why the deferral is a runway, not a holiday.
4. Prohibited Practices. The eight red lines, the two new ones arriving in December 2026, and the grey zones where ordinary commercial products get caught: workplace analytics, scoring systems, engagement optimisation. How to run and document a prohibition screen in a fortnight.
Part II — Risk Governance
5. Classification: The Load-Bearing Decision. The two routes to high-risk, the Article 6(3) filter and its profiling override, and the artefact almost everyone forgets: the documented negative. Classification as a versioned process with triggers, not a memo that decays from the day it is written.
6. The Risk Management System. What “continuous iterative process” means operationally, and why a risk assessment done once satisfies one of Article 9’s four verbs. The four steps, the hierarchy of measures, the residual risk judgement someone must actually sign. Integrating with the ISO 31000 and ISO 42001 machinery you already run.
7. Data and Data Governance. What “relevant, representative, free of errors” actually says, with its three load-bearing qualifiers. The bias examination duties, the Article 10(5) pathway for sensitive data, and the datasheet: one structured document per data set that an auditor can read without asking anyone anything.
8. Governance Structures and Accountability. The Act mandates no AI officer, which means accountability defaults to nobody. The three-layer structure that survives an audit, the inventory as master record, the deployer’s Article 26 duties, and the fundamental rights impact assessment for those who owe one.
9. AI Literacy, Article 4. What the obligation requires, what the Omnibus did to it, and why the business case survives whatever the final verb says. Literacy as a matrix, not a module: six populations, six content tiers, and the five records that evidence all of it.
Part III — Technical Safeguards
10. Technical Documentation, Article 11 and Annex IV. The nine-part package, section by section, with who owns what. Living documentation versus the binder that dies on a shelf, and the five design choices that keep the file describing the system actually in production.
11. Record-Keeping and Logging, Article 12. What to capture, derived from the five consumers of your logs. Retention beyond the six-month floor, custody in the SaaS pattern, and the one-page logging specification that lawyers can defend and engineers can build.
12. Transparency and Human Oversight, Articles 13 and 14. The instructions for use as a four-job compliance artefact. The three oversight models and how to choose deliberately. Why the interface itself is regulated, and how to prove your human oversight is real rather than decorative, before someone else measures it for you.
13. Accuracy, Robustness and Cybersecurity, Article 15. The declaration mechanism: you set your own number, in writing, in front of witnesses. Robustness as a test plan, the AI-specific attack families and their controls, and what “appropriate level” means while the harmonised standards are still arriving.
14. Transparency for Limited-Risk Systems, Article 50. The chapter with the nearest deadline. Four duties, arriving August 2026 for organisations in every risk tier: chatbot disclosure, synthetic content marking, emotion recognition disclosure, deepfake labelling. Machine-readable marking in practice, and the six-week readiness sequence.
15. GPAI Obligations in the Value Chain. What model providers owe you, what you owe downstream, and when fine-tuning quietly makes you a model provider. The Code of Practice, the systemic-risk regime, and how to read a model provider’s documentation the way a due-diligence lawyer reads a data room: for what is missing.
Part IV — Auditing and Enforcement
16. Conformity Assessment. The surprise at the centre of the Act: for most high-risk systems, the assessor is you. The declaration of conformity as a legal act with a named signatory, CE marking on software, database registration, and the signing pack that lets someone senior sign honestly.
17. The Audit-Ready Organisation. What market surveillance authorities can demand, how inspections actually unfold, and the evidence map: obligation to artefact to owner to location. A complete mock audit methodology, with a worked walkthrough of one firm’s fourteen findings, none exotic, all cheaper fixed today.
18. Post-Market Surveillance, Incidents and Corrective Action. The monitoring plan that watches the system in the field, the serious incident definition whose third limb catches recruitment and credit systems, the reporting clocks, and recall mechanics for software. Closing the loop so the incident changes the file, not just the model.
19. Penalties and Enforcement Reality. The three fine tiers, the SME inversion that changes the arithmetic for smaller operators, and the GDPR machine already enforcing AI next door. An honest reading of the empty docket, and who gets fined first, and why.
20. Multi-Framework Reality. The AI Act alongside GDPR, DSA, financial services rules, medical devices and machinery. The “which document, when” problem, the document map that cures it, and the argument the whole book builds to: one governance system instead of five.
Part V — Making It Operational
21. The 90-Day Compliance Sprint. The book as a sequenced plan, in three profiles: the deployer-only organisation, the provider SME, and the scale-up becoming a provider without noticing. What to do first when you cannot do everything, ordered by what actually blocks what.
22. Common Failure Modes. The expensive mistakes, named: classification by wishful thinking, vendor-claim reliance, documentation theatre, literacy as a webinar link nobody opened, and five more. Each with its signature and its correction. Closes with the test the whole book serves: the file you can hand over.
Appendix: The Consolidated Evidence Checklist. All 111 artefacts from every chapter’s auditor section, deduplicated, in one list. Available as editable templates in the free toolkit.
It is important to dispel the myth that “governance stifles innovation.” This is not true. In my years of experience delivering industry solutions in Responsible AI, good governance practices have contributed to more innovative products. I use the phrase ‘brakes help you drive faster’ to explain this phenomenon – the ability to stop a car in dangerous situations enables us to feel comfortable driving at fast speeds. Governance is innovation.” — Dr. Rummam Chowdhury
Take the Next Step
The regulatory clock is ticking, and enforcement timelines are already closing in. Preparing your systems now means smoother audits, lower engineering friction, and a massive head start over your competitors.
Be the first to master the new rules of the game. Register today to lock in exclusive Early Bird Pricing and receive bonus compliance templates upon launch.
FAQ
What is the current compliance deadline for high-risk AI systems under the EU AI Act?
Following the recent passage of the 2026 AI Act Digital Omnibus amendments, the compliance deadlines for high-risk AI systems (HRAIS) have been officially extended to give businesses more preparation time:
- December 2, 2027 – Deadline for standalone “Annex III” high-risk AI systems (e.g., AI used in employment, biometrics, education, and critical infrastructure).
- August 2, 2028 – Deadline for “Annex I” product-regulated AI systems (e.g., AI integrated into medical devices, aviation, or machinery safety components).
In EU AI Act Compliance Mastery, we break down these staggered timelines into an agile roadmap so your engineering team meets every milestone without panic.
Which AI systems must comply with the August 2026 transparency obligations?
While high-risk deadlines were extended, Article 50 transparency obligations go into effect on August 2, 2026. This applies to:
AI-Generated Synthetic Content: Systems must output machine-readable, detectable watermarks.
Chatbots & Conversational AI: Must clearly disclose to users that they are interacting with an AI system.
Emotion Recognition / Biometric Systems: Users must be explicitly notified when these systems are active.
Are US and international companies subject to the EU AI Act regulations?
Yes, because EU AI Act has extraterritorial reach, meaning it applies to any organization worldwide if the AI system’s outputs are used or made available within the European Union. Whether you are a Silicon Valley SaaS startup or an enterprise provider based in Asia, if an EU citizen interacts with your model or its data, you must comply or face cross-border enforcement penalties.
What are the maximum financial penalties for violating the EU AI Act?
The EU AI Act enforces some of the steepest regulatory fines in digital history, categorized by severity:
- Prohibited AI Practices: Fines up to €35 million or 7% of global annual turnover (whichever is higher) for deploying banned systems like non-consensual deepfakes or social scoring.
- High-Risk Non-Compliance: Fines up to €15 million or 3% of global annual turnover for failing to meet governance, logging, or data quality standards.
- Incorrect Information: Fines up to €7.5 million or 1.5% of global annual turnover for supplying misleading documentation to regulatory bodies.
How does the EU AI Act distinguish between “prohibited” and “high-risk” AI?
The framework utilizes a strict risk-based classification system:
High-Risk: Systems used in critical sectors like healthcare, hiring, law enforcement, and credit scoring. These are legal but require rigorous data governance, human oversight, and mandatory registration in the EU database.
Prohibited Risk: Systems that pose an unacceptable threat to safety and fundamental rights (e.g., untargeted biometric scraping, subliminal manipulation). These have been illegal since early 2025, with new prohibitions on non-consensual intimate content taking effect in late 2026.
What technical documentation is required to pass an EU AI Act conformity assessment?
To achieve audit-ready compliance for a high-risk AI system, developers must maintain a live, comprehensive technical file containing:
- Detailed system architecture descriptions and algorithmic design specifications.
- Data governance logs mapping data collection, provenance, and bias-testing methodologies.
- Automated continuous logging protocols (traceability metrics) to track system performance and decision-making over time.
- Detailed instructions for use (IFU) outlining necessary human oversight workflows.
How can software teams prepare for EU AI Act audits without slowing down development?
The most effective way to balance compliance with innovation is to implement Compliance-by-Design. Instead of treating audits as a post-development hurdle, engineering teams should automate transparency logging, integrate bias testing into automated CI/CD pipelines, and map user access permissions directly onto role-based hierarchies early.
EU AI Act Compliance Mastery serves as your practical implementation manual, showing your founding and legal teams exactly how to co-author compliance guardrails that accelerate—rather than stall—your product launch.
