EU AI Act: the runtime controls, and the deadline that moved
The EU AI Act does not ask for a gateway. It asks providers and deployers to keep records, oversee systems, guard data and report incidents. AI-FW is where those duties become running controls with timestamps rather than intentions in a policy document.
- The instrument
- Regulation (EU) 2024/1689, as amended by the 2026 Digital Omnibus on AI
- Status
- In force; high-risk duties staged into 2027 and 2028
- Who it applies to
- Providers placing AI systems on the EU market and deployers using them, including non-EU organisations whose output reaches EU users.
The timetable that matters
Dates move. These are the ones this page was reviewed against.
- 2 February 2025Prohibited practices and AI literacy duties apply
- 2 August 2025General-purpose AI chapter, with the GPAI Code of Practice
- 2 August 2026Most transparency duties; enforcement milestone for earlier duties
- 2 December 2026Transparency duties for systems already on the market, and further prohibitions
- 2 December 2027Annex III high-risk duties (deferred from 2 August 2026 by the 2026 amendment)
- 2 August 2027Regulatory sandboxes, and GPAI transitional compliance
- 2 August 2028Annex I high-risk duties, for AI embedded in regulated products
Where AI-FW fits
AI-FW is the runtime control plane between your applications, agents and the model providers behind them. It does not classify your AI system, does not perform conformity assessment, and is not a notified body. What it supplies is the technical, evidence-producing layer: input and output screening, record-keeping, oversight gates, incident signals, and access governance that an auditor can inspect after the fact.
What stays with you
Read this list first. It is the boundary of what a product can do for you, and it is where the remaining work sits.
- Classifying each system (prohibited, high-risk, limited-risk, general-purpose) and determining your role under the Act
- The quality management system and technical documentation a provider must hold
- Conformity assessment, CE marking, and registration in the EU database
- The content of a fundamental-rights impact assessment, though it supplies the technical evidence
- AI literacy training, and the records that prove it happened
What the framework asks, and what the product does
The obligations that touch the AI path, paired with the capability that answers each one. Everything else in this framework is organisational work, listed above.
Certain uses are banned outright, from manipulation to social scoring
Inbound and outbound rules for prohibited-use patterns, with a category-aware engine for the cases keyword matching misses, and an audit entry for every match
Automatic logging that stays available for the required period
A record for every transaction and access event: identity, model, tokens, decision, rule, latency and outcome, with retention you set rather than a fixed window
People must know they are dealing with an AI system, and synthetic output must be marked
Outbound rules that detect unlabelled synthetic content, so disclosure becomes an enforceable policy instead of a convention
Systems must remain subject to effective human oversight
An approval queue for sensitive operations and risk thresholds that route work to a person, with the approval recorded against an identity
Systems must be resilient to manipulation and misuse
Prompt-injection and abuse detection, plus per-model reliability policy (retries, failover, distribution) that cannot quietly weaken a guard
Data used by the system must be relevant and safeguarded
Sensitivity classification across personal, payment, health and semantic categories, giving measurable evidence of what actually crossed the gateway
Risk must be tracked after deployment, not only assessed before it
Risk scoring per agent and user with decay over time, violation history, and dashboards that show the trend rather than a single snapshot
Reportable incidents need a defensible timeline
Error and violation telemetry with attribution and timestamps, enough to reconstruct what happened, in what order, and under whose authority
A rule pack to start from
The enforcement that makes the controls real. Severity runs 1 to 5, and a rule that is switched off reports as a gap, so these are meant to be live from day one.
Prohibited practices are already in force, so this carries the highest exposure
Transparency duties: observe first, then block where your policy requires it
Robustness expectations under the accuracy and cybersecurity duty
Data governance, and the privacy overlap with GDPR
Deployers must use a system according to its instructions
The raw signal that feeds incident reporting
What the evidence pack contains
Per period, and without prompt or response content, which is what makes it safe to hand over.
- Framework status and amendment levelWhich version of the duties you assessed against
- Control statusesIncluding the controls that are switched off, which are reported as gaps
- Live rule inventoryEach rule with its enabled state, direction and action
- Logging and retention settingsMatching your documented retention policy
- Approval activityOversight decisions recorded in the period
- Catalogue version and manifest hashTies the pack to the control set it was produced from
Customer responsibilities and sources
- Classify each AI system and establish whether you are a provider, deployer, importer or distributor.
- Maintain the quality management system and the technical documentation, and run conformity assessment and CE marking where they apply.
- Complete the fundamental-rights impact assessment if you are a public-body deployer, and inform workers and affected people.
- Register in the EU database where required, and appoint an authorised representative if you are outside the EU.
- Keep a qualified legal owner accountable for the timetable: the deferral of the high-risk duties is not a pause, and the prohibited-practice and AI literacy duties are already live.
Common questions
No. It produces the technical controls and the evidence for the parts of the Act that touch the AI path. Classification, documentation, conformity assessment and the impact assessment remain yours, and no product can perform them. Treat AI-FW as the runtime half of your answer.
The 2026 Digital Omnibus on AI deferred the Annex III high-risk duties from 2 August 2026 to 2 December 2027. Annex I duties, for AI embedded in regulated products, moved to 2 August 2028. Plenty of organisations are still working from the older timetable, so it is worth checking which dates your own plan uses.
No. Evidence packs carry control statuses, rule state, settings, retention values and inventories. Prompt and response content is excluded by design, which is what makes a pack safe to hand over. Content capture is a separate policy decision you make, and masking applies when it is on.
Validate it yourself with our Technical Plan
Ask us to run this framework against your own environment: the rules that would be created, what the assessment reports, and what the evidence pack contains for a real period.
This page maps product capabilities to published expectations. It is not legal, audit or certification advice, and it creates no compliance representation. Applicability and sufficiency are judgements for your counsel and, where relevant, your auditor, assessor or certification body. Framework details are current as reviewed; check the primary sources above, and the page itself, before relying on a date or a threshold.