RTFCT

European Union

EU AI Act: The Global Standard-Setter

The EU AI Act is the most advanced and comprehensive AI regulation globally. Even with a reduced implementation schedule, it sets the standard for compliance worldwide. Its risk-based approach and extraterritorial reach mean that any business operating in the EU market must comply—or face penalties of up to €35M or 7% of global turnover.

Phased Implementation

EU AI Act Timeline

FEBRUARY 2, 2025

Phase 1: Prohibitions

Unacceptable risk AI systems (e.g., social scoring, biometric categorization) are banned.

AUGUST 2, 2025

Phase 2: GPAI Rules (2nd Wave)

General-Purpose AI (GPAI) systems must comply with transparency and risk management obligations.

AUGUST 2, 2026

Phase 3: Article 50 Transparency (3rd Wave)

Article 50 applies to general-purpose AI systems (transparency, systemic risk evaluation) and chatbot/biometric disclosure obligations. It does not apply to high-risk systems.

DECEMBER 2, 2027

Phase 4: Annex III High-Risk Enforcement

Annex III high-risk systems enter full enforcement — conformity assessments, CE marking, human oversight (Article 14), and post-market monitoring (Article 72) become mandatory. Delayed from August 2026 by the Omnibus agreement (May 2026).

AUGUST 2, 2028

Phase 5: Annex I Safety-Critical

Annex I safety-embedded AI systems enter full enforcement.

Annex III

High-Risk AI Systems

Biometric Identification

Remote biometric identification systems (e.g., facial recognition in public spaces).

Critical Infrastructure

AI systems for managing critical infrastructure (e.g., water, gas, heating, electricity).

Education & Vocational Training

AI systems for determining access to educational institutions or vocational training.

Employment & Worker Management

AI systems for recruitment, performance evaluation, or termination of employment contracts.

Essential Services

AI systems for credit scoring, access to essential private services (e.g., healthcare, insurance).

Law Enforcement

AI systems for assessing the reliability of evidence, polygraphs, or criminal risk assessments.

Mandatory Obligations

Compliance Requirements for High-Risk AI

Risk Management System

Implement a risk management system to identify, evaluate, and mitigate risks throughout the AI system's lifecycle.

Data Governance

Ensure training, validation, and testing datasets are relevant, representative, and free from errors or biases.

Technical Documentation

Maintain comprehensive technical documentation, including system architecture, data provenance, and decision trees.

Human Oversight

Design systems to allow for human intervention or override at any stage of the AI system's operation.

Logging & Record-Keeping

Log all AI system operations for traceability and retain records for at least 10 years.

Transparency Obligations

Inform users when they are interacting with AI systems and provide clear explanations of system capabilities and limitations.

Conformity Assessment

Undergo third-party conformity assessments for high-risk systems and obtain CE marking before market placement.

The Only Structural Solution

RTFCT Covers This Jurisdiction, And Every Other One, From Day One

The EU AI Act is complex, but RTFCT simplifies compliance. Our structural layer automatically enforces risk management, data governance, and transparency obligations—so you can focus on innovation, not regulation.

With RTFCT, you’re not just compliant—you’re future-proof.