Skip to content
FAQ

Questions worth answering.

Common questions about the regulation, the deadlines, and how ActReady works.

About the EU AI Act

What is the EU AI Act?

The EU AI Act is the world's first broad legal framework for artificial intelligence. It classifies AI systems by risk level and imposes different obligations depending on that classification. It covers providers (companies that build AI), deployers (companies that use AI), importers, and distributors.

When does the EU AI Act take effect?

The EU AI Act has a phased rollout: • February 2, 2025 — Prohibited AI practices ban took effect • August 2, 2025 — GPAI model obligations and governance rules applied • August 2, 2026 — Transparency obligations (Article 50) are now in force • December 2, 2026 — Machine-readable marking of AI-generated content (Article 50(2)) becomes mandatory for systems already on the market before Aug 2, 2026 • December 2, 2027 — High-risk AI obligations (Annex III) apply, extended by the Digital Omnibus The transparency deadline was NOT extended by the Digital Omnibus and applied on schedule.

Does the EU AI Act apply to companies outside the EU?

Yes. If your AI system's output is used in the EU, or if it affects people located in the EU, the Act applies regardless of where your company is based. This includes US, UK, and other non-EU companies serving EU customers. Geographic restrictions in your Terms of Service help but are not bulletproof.

What are the risk categories?

The EU AI Act uses four risk tiers: • Unacceptable risk — Banned outright (social scoring, real-time biometric surveillance, emotion recognition in workplaces/schools) • High-risk — Heavy obligations: technical documentation, risk management, conformity assessment, post-market monitoring. Defined by Annex III use cases (HR, credit, education, healthcare, law enforcement) • Limited risk — Transparency obligations: tell users they're talking to AI, label AI-generated content • Minimal risk — No mandatory obligations, voluntary codes of conduct encouraged

What is the difference between a provider and a deployer?

A provider develops, trains, and places an AI system on the market. A deployer uses someone else's AI system in their business under their own authority. For example, if you use HireVue for screening, HireVue is the provider and you are the deployer. Providers carry heavier obligations (technical documentation, conformity assessment). Deployers have lighter but still binding obligations (human oversight, transparency, log retention).

What are the fines for non-compliance?

Fines are tiered by violation severity: • Prohibited practices: Up to €35 million or 7% of global annual turnover • High-risk non-compliance: Up to €15 million or 3% of global annual turnover • Incorrect information to authorities: Up to €7.5 million or 1% of global annual turnover SMEs and startups get proportionate caps. Beyond fines, non-compliant AI systems can be withdrawn from the EU market entirely.

What did the Digital Omnibus change?

The Digital Omnibus deal extended the Annex III high-risk AI obligations deadline from August 2, 2026 to December 2, 2027 — giving companies 16 extra months. Critically, it did NOT extend Article 50 transparency obligations, which applied on August 2, 2026. It also did NOT change prohibited practices, which are already in effect.

About ActReady

How is ActReady different from hiring a consultant?

Traditional EU AI Act compliance consulting costs €50K–€200K and takes months. ActReady handles the bulk of the work — classification, documentation, obligation tracking — for a fraction of the cost. You still review and approve everything; the software does the heavy lifting, and generates the same documents a consultant would in a fraction of the time.

Is ActReady a substitute for legal advice?

No. ActReady is a compliance management tool, not a law firm. We help you classify systems, generate documentation, track obligations, and organise your compliance work. For complex legal questions — especially around liability, enforcement, or novel use cases — we recommend consulting a qualified legal professional. ActReady gives you most of the compliance structure; legal counsel fills the rest.

What documents does ActReady generate?

The major EU AI Act compliance documents: • Annex IV technical documentation (9 sections) • Risk management plans (Article 9) • Human oversight plans (Article 14) • Transparency notices (Article 50) • Data governance documentation (Article 10) • Post-market monitoring plans (Article 72) Each document is tailored to your specific AI system, risk level, and domain. Export as PDF or Word.

Is the AI classifier really free?

Yes. The guided risk classifier requires no account at all — answer a few questions and get your risk tier instantly with article references. Paid plans add the AI Classifier, which accepts free-text descriptions and uses AI to classify your system. Both classifiers cover all Annex III high-risk categories, prohibited practices, and GPAI rules.

Can I try ActReady before committing?

Absolutely. The free plan gives you full access to the risk classifier with no signup. All paid plans include a 14-day free trial with full access to every feature. Save 20% with annual billing, and you can cancel anytime before the trial ends with no charge.

How does pricing work?

Four plans: • Free (€0) — Risk classifier, no signup needed • Starter (€29/mo or €23/mo annual) — Up to 3 AI systems, 5 documents/month, obligation tracker • Pro (€79/mo or €63/mo annual) — Unlimited systems and documents, risk map, AI training, Trust Center • Enterprise (€199/mo or €159/mo annual) — Multi-org, white-label reports, vendor risk, dedicated support All paid plans include a 14-day free trial.

Is my data secure?

Yes. ActReady uses Supabase for database hosting (SOC 2 Type II certified), Clerk for authentication (SOC 2 Type II), and Vercel for deployment. All data is encrypted in transit (TLS 1.3) and at rest. We never share your data with third parties. When we use AI to generate documents, your system descriptions are processed but never stored by the AI provider.

Compliance Process

Where do I start with EU AI Act compliance?

Start with classification. Use our free risk classifier to determine whether your AI system is minimal, limited, or high-risk. This drives everything else — your obligations, your timeline, and your budget. Once you know your risk tier, the compliance roadmap in the dashboard shows you exactly what to do next.

How long does compliance take?

It depends on your risk tier and how many AI systems you have: • Minimal risk: No mandatory obligations — classification takes a few minutes and you're done • Limited risk: Transparency disclosures take 1–3 days of engineering work • High-risk (deployer): 1–2 weeks of structured work covering human oversight, monitoring, and transparency • High-risk (provider): 3–6 months for full compliance including documentation, risk management system, and conformity assessment ActReady significantly reduces these timelines by automating document generation and providing guided workflows.

What if I have multiple AI systems?

Each AI system needs its own classification and compliance treatment. ActReady lets you register multiple systems, classify each one independently, generate separate documentation for each, and track obligations per system. The dashboard gives you an aggregated view across all systems.

Do I need a conformity assessment?

Only if you are a provider of a high-risk AI system. Most high-risk systems can use self-assessment (internal conformity assessment under Annex VI). Biometric identification systems used for law enforcement require a third-party assessment by a notified body. Deployers do not need conformity assessments.

What is the EU database registration?

Article 49 requires providers and deployers of high-risk AI systems to register in the EU database before placing the system on the market or putting it into service. The database is public and includes information about the system, its provider, and its intended purpose. ActReady helps you prepare the required Annex VIII information.

What about GPAI models (GPT-4, Claude, Gemini)?

If you use a GPAI model in your product, the model provider (OpenAI, Anthropic, Google) has their own obligations. But if you integrate a GPAI model into a high-risk system, you become the provider of that high-risk system and carry the full provider obligations. Using a foundation model does not exempt you from EU AI Act obligations for your downstream system.

Deadlines & Enforcement

Article 50 transparency is now in force. What do I actually need to have in place?

Article 50 transparency obligations have been in force since August 2, 2026. You need: • AI interaction notices — tell users when they're interacting with AI • Emotion recognition disclosures — if applicable • Biometric categorisation disclosures — if applicable • Synthetic content labeling — mark AI-generated text, images, audio, and video as AI-generated These apply to ALL AI systems that interact with users or generate content, regardless of risk level.

What happens if I miss the transparency deadline?

Enforcement varies by member state, but the regulation allows fines of up to €15 million or 3% of global annual turnover for transparency violations. In practice, early enforcement will likely focus on complaints and the most visible violations. But waiting for enforcement to begin is not a compliance strategy — the obligations are binding from day one.

Is enforcement actually happening?

Yes. Member states are required to designate national competent authorities, and the EU AI Office is already operational. While large-scale enforcement campaigns are unlikely on day one, the infrastructure is being built. More importantly, enterprise customers are already asking about EU AI Act compliance in procurement — market pressure may hit before regulatory pressure.

Do I need to worry about the EU AI Act if I only have a chatbot?

A chatbot is limited risk, not high-risk. Your only mandatory obligation is transparency: tell users they are interacting with an AI system. That's typically a banner, a label, or a disclosure in your interface. No conformity assessment, no technical documentation, no risk management system. A developer can implement this in a day.

Still have questions?

The blog has 60-plus in-depth guides covering every corner of the Act. Or reach out directly.