FEBRUARY 2, 2025
Phase 1: Prohibitions
Unacceptable risk AI systems (e.g., social scoring, biometric categorization) are banned.
European Union
The EU AI Act is the most advanced and comprehensive AI regulation globally. Even with a reduced implementation schedule, it sets the standard for compliance worldwide. Its risk-based approach and extraterritorial reach mean that any business operating in the EU market must comply—or face penalties of up to €35M or 7% of global turnover.
Phased Implementation
FEBRUARY 2, 2025
Unacceptable risk AI systems (e.g., social scoring, biometric categorization) are banned.
AUGUST 2, 2025
General-Purpose AI (GPAI) systems must comply with transparency and risk management obligations.
AUGUST 2, 2026
Article 50 applies to general-purpose AI systems (transparency, systemic risk evaluation) and chatbot/biometric disclosure obligations. It does not apply to high-risk systems.
DECEMBER 2, 2027
Annex III high-risk systems enter full enforcement — conformity assessments, CE marking, human oversight (Article 14), and post-market monitoring (Article 72) become mandatory. Delayed from August 2026 by the Omnibus agreement (May 2026).
AUGUST 2, 2028
Annex I safety-embedded AI systems enter full enforcement.
Annex III
Remote biometric identification systems (e.g., facial recognition in public spaces).
AI systems for managing critical infrastructure (e.g., water, gas, heating, electricity).
AI systems for determining access to educational institutions or vocational training.
AI systems for recruitment, performance evaluation, or termination of employment contracts.
AI systems for credit scoring, access to essential private services (e.g., healthcare, insurance).
AI systems for assessing the reliability of evidence, polygraphs, or criminal risk assessments.
Mandatory Obligations
Implement a risk management system to identify, evaluate, and mitigate risks throughout the AI system's lifecycle.
Ensure training, validation, and testing datasets are relevant, representative, and free from errors or biases.
Maintain comprehensive technical documentation, including system architecture, data provenance, and decision trees.
Design systems to allow for human intervention or override at any stage of the AI system's operation.
Log all AI system operations for traceability and retain records for at least 10 years.
Inform users when they are interacting with AI systems and provide clear explanations of system capabilities and limitations.
Undergo third-party conformity assessments for high-risk systems and obtain CE marking before market placement.
The Only Structural Solution
The EU AI Act is complex, but RTFCT simplifies compliance. Our structural layer automatically enforces risk management, data governance, and transparency obligations—so you can focus on innovation, not regulation.
With RTFCT, you’re not just compliant—you’re future-proof.