AI Act & compliance insights
Analysis and practical guides on the AI Act, privacy, and operational compliance, built for legal, compliance, and product teams.
Compliance signals
Dated updates on what changed and what to do about it, newest first.
Article 50 Guidelines: what AI agents do not have to mark
The Commission’s Article 50 Guidelines draw a negative scope for agents: intermediate reasoning is not synthetic content. What paragraph 31 still requires.
The EU AI Act on 2 August 2026: What Actually Applies (and What the Omnibus Just Delayed)
Article 50 transparency and AI content-marking apply from 2 August 2026. Exactly what binds now, who it hits as provider or deployer, and the checklist.
The Commission's Final Article 50 Guidelines: What Actually Changes Before 2 August 2026
The Commission adopted its final Article 50 guidelines on 20 July 2026. What changes for chatbot disclosure, machine-readable marking and deepfakes.
EU AI Act Deadlines After the Digital Omnibus (2026)
The Digital Omnibus is in force since 27 July 2026: high-risk moves to 2 December 2027, Annex I to 2 August 2028. The dated timeline for 2026 onward.
EU AI Act Omnibus talks stalled, what SMEs should do now
The Digital Omnibus trilogue did not close on 28 April 2026. What broke, what still applies for August 2026, and five actions you can ship regardless.
EU AI Act Deadline May Move (Digital Omnibus): What SMEs Should Do Now
Reports from April 2026 suggest the EU Digital Omnibus could shift the AI Act’s Annex III high-risk timeline. What changes, what does not, and 7 actions.
Editor’s picks
The most important articles to start with.
EN 301 549 does not make you EAA compliant, and the Official Journal proves it
No harmonised standard is cited in the Official Journal under the EAA, so there is no presumption of conformity. What to anchor your evidence to instead.
Is your online shop in scope of the BFSG? The microenterprise test, and the 2030 date that is not a grace period
Who the BFSG actually binds, how the microenterprise exemption really works, and why the 2030 date is not a grace period for your website.
More articles
Disproportionate burden is not a get-out. It is a document, a five-year clock, and a letter to your regulator
Article 14 and Annex VI of the EAA: what the assessment must contain, why undocumented reliance is itself a breach, and the funding trap that voids it.
The EAA accessibility statement you are copying is the wrong one, and it has to be available orally
Annex V of the EAA is not the public-sector accessibility statement. What Article 13(2) requires, including the oral format almost nobody ships.
prEN 18229-1: What the AI Act Logging Standard Actually Says
The draft European standard for AI logging, read from the source. What Part 1 covers, why Article 12 does not bite until December 2027, and the gap.
The EU Code of Practice on Marking AI-Generated Content: What It Is, and Whether to Sign
The EU Code of Practice on marking AI-generated content was finalised on 10 June 2026. What it requires, why it is not a C2PA mandate, and who may sign.
How to Add an EU AI Act Article 50 AI Disclosure to WordPress (Step by Step)
Step by step: add an EU AI Act Article 50 AI disclosure to WordPress. Pick a style, set the language, enable and verify. Free, local, no account needed.
EU AI Act for WordPress: The Complete Checklist Before 2 August 2026
A WordPress-specific EU AI Act checklist: inventory your AI, disclose chatbots under Article 50, label AI content and meet the Article 4 literacy duty.
Do I Need to Disclose My AI Chatbot Under the EU AI Act? (Article 50)
Yes, in almost all cases. Article 50 requires telling visitors they are talking to an AI from 2 August 2026, with fines to EUR 15M or 3% of turnover.
Is My Medical AI High-Risk Under the EU AI Act? (MDR/IVDR Guide)
Your medical AI is high-risk under the EU AI Act if it needs a notified body under the MDR or IVDR. Class tables, worked examples and the obligation delta.
AI Act for Medical Devices: Deadlines & Omnibus Tracker
Living tracker of EU AI Act dates for medical devices. Annex I products are deferred to 2 August 2028; the Article 6(1) classification logic is stable.
Provider or Deployer? AI Act Roles for Medical AI (MDR Manufacturers)
The medtech company that makes the AI is the provider; the clinic using it is the deployer. Your role, the full value chain, and Article 25. Cited.
Best Vanta Alternative for EU AI Act Compliance (2026)
Vanta automates SOC 2 and ISO well, but treats the EU AI Act as an add-on. The best Vanta alternatives for AI-Act-native, SME-priced compliance in 2026.
Building Medical AI on LLMs: What the EU AI Act Requires (GPAI)
Wrapping GPT or Llama into a medical product does not offload your AI Act duties. You remain the provider; the model owes you Article 53 documentation.
Does the EU AI Act Apply to Vibe-Coded Apps?
You shipped it in a weekend with Cursor, does the EU AI Act still apply? Yes, if your app puts AI in front of EU users. How to tell which tier you are in.
Notified Bodies and AI Medical Devices Under the EU AI Act
There is no separate AI Act notified body. Under Article 43(3) your MDR/IVDR notified body also checks AI Act conformity, once assessed for that scope.
Best OneTrust Alternative for AI Act Compliance (2026)
Looking for a OneTrust alternative for the EU AI Act? Compare 5 AI governance tools by price, scope and fit, plus the best self-serve option for SMEs.
Who Owns AI-Generated Code? Copyright, Licensing, and the Copyleft Trap
Can you use AI-written code commercially and safely? Copyright that may not exist, tool terms worth reading, and copyleft that quietly contaminates.
GDPR × AI Act × MDR: Health Data Rules for Medical AI
GDPR, the AI Act and MDR/IVDR all touch your patient data at once. How they stack, plus DPIA against FRIA and the role mismatch. Cited.
Do I Need to Comply With the EU AI Act? (2026)
Do you need to comply with the EU AI Act? Yes if you're a provider, deployer, importer or distributor with an EU nexus, even non-EU firms. Check your scope.
Is the Code Your AI Wrote Safe, and Compliant, to Ship?
AI-generated code leaks secrets, pulls in copyleft licenses and can quietly trigger EU AI Act duties. A pre-ship checklist with the cited Articles.
ISO 42001 and ISO 13485 Alongside the EU AI Act (Medical AI)
Your ISO 13485 QMS is the backbone for the AI Act quality duty (Article 17), with ISO/IEC 42001 as the AI layer. MDCG 2025-6 says integrate, not duplicate.
Best EU AI Act Compliance Software for Startups (2026)
The best EU AI Act compliance software for startups and SMEs in 2026: AI-Act-native depth, EU hosting, self-serve and real pricing, compared.
DiGA and the EU AI Act: What German Digital Health Apps Need to Know
An AI-based DiGA is high-risk under the EU AI Act once it is MDR Class IIa or higher. The MDR, BfArM fast-track and GDPR tracks, with worked examples.
Annex IV Technical Documentation for Medical AI (EU AI Act)
For medical AI you extend your MDR/IVDR technical file to cover Annex IV, assessed inside the existing conformity assessment under Article 43(3).
EU AI Act Log Retention: The 6-Month Rule (In Practice)
How long must you keep EU AI Act logs? At least 6 months, for providers (Article 19) and deployers (Article 26(6)). What to log and who is responsible.
Do You Need a FRIA for Your Medical AI? (EU AI Act Article 27)
Medical devices are high-risk via Article 6(1), the product route, so they sit outside the FRIA duty in Article 27. What you need instead is a GDPR DPIA.
AI Act Article 50 Transparency: disclosure checklist + copy/paste templates (Disclosure Pack v1)
Article 50 guide for product teams: when disclosure applies, UX placement, copy-paste strings, marking options, logging fields and evidence artifacts.
Agentic AI Governance and Compliance
Guide to agentic AI governance: the Singapore framework, the EU AI Act applied to AI agents, accountability gaps and technical controls.
EU AI Act Compliance Software Tools Compared (2026)
EU AI Act compliance tools compared for 2026: GRC platforms, AI governance, open-source scanners and workflow tools, with pricing and criteria.
Colorado AI Act and US State AI Laws Guide
Complete guide to Colorado SB 205 AI Act and US state AI laws. Algorithmic discrimination, developer and deployer duties, NIST defense, and compliance steps.
AI Regulation Compared: EU, US, UK, China (2026)
Global AI regulation compared in 2026: the EU AI Act against the US, UK and China, plus a multi-jurisdiction compliance strategy. Updated July 2026.
CE Marking and EU Database for AI Systems
Guide to CE marking requirements and EU database registration for AI systems. Article 48, Article 49, Annex VIII, conformity declaration, and market access.
AI Act for Education and EdTech Compliance
EU AI Act compliance guide for education and EdTech. High-risk AI in admissions, grading, proctoring, prohibited emotion recognition, and school obligations.
AI Act for Financial Services Compliance
EU AI Act compliance guide for banking, insurance, and fintech. Credit scoring, insurance pricing, fraud detection, and high-risk AI obligations.
AI Act for Healthcare and Medical AI Compliance
EU AI Act compliance guide for healthcare and medical device AI. MDR/IVDR overlap, high-risk classification, and SaMD obligations explained.
AI Act for HR and Recruitment: Compliance Guide
EU AI Act compliance guide for HR and recruitment AI. High-risk classification, banned practices, vendor obligations, and bias testing for hiring.
EU AI Act for Startups and SMEs: Compliance Guide
Practical EU AI Act compliance guide for startups and SMEs. Reduced penalties, regulatory sandboxes, simplified docs, and budget planning.
DPIA vs FRIA: AI Impact Assessment Guide
DPIA vs FRIA comparison for AI systems. Legal basis, triggers, who must conduct each, overlap, and practical combined methodology for EU AI Act compliance.
NIST AI RMF vs ISO 42001 vs EU AI Act
Side-by-side comparison of NIST AI RMF, ISO 42001, and the EU AI Act. Framework crosswalk, overlap areas, critical gaps, and alignment strategy.
ISO 42001: AI Management System Certification
Complete guide to ISO 42001 AI management system certification. Requirements, certification process, mapping to EU AI Act, and integration with ISO 27001.
AI Act Post-Market Monitoring and Incident Reporting
Guide to EU AI Act post-market monitoring (Article 72) and serious incident reporting (Article 73). Obligations, timelines, and templates.
AI Governance Framework: Build Your AI Program
How to build an AI governance framework aligned with the EU AI Act, NIST AI RMF, and ISO 42001. Roles, policies, risk tiers, and board reporting.
AI Training Data Requirements: Article 10
Guide to AI Act Article 10 data governance: training data requirements, bias detection, data provenance and the GPAI transparency template.
AI Risk Management System: Article 9 Guide
Complete guide to AI Act Article 9 risk management system. Continuous risk assessment, residual risk, testing protocols, and lifecycle compliance.
Human Oversight for AI: Article 14 Guide
Complete guide to implementing human oversight for high-risk AI under Article 14. HITL, HOTL, HIC models, automation bias, and deployer obligations explained.
AI Act Transparency: Article 50 and Deepfake Rules
Guide to EU AI Act Article 50 transparency obligations. Chatbot disclosure, deepfake labeling, AI content marking, and the Code of Practice explained.
AI Bias Testing for EU AI Act Compliance (2026)
Practical guide to AI bias testing under EU AI Act Article 10. Fairness metrics, protected attributes, testing tools, and compliance workflows.
AI Act FRIA: Fundamental Rights Impact Assessment
Step-by-step AI Act FRIA guide under Article 27. Who must conduct one, mandatory fields, FRIA vs DPIA comparison, and a practical template.
AI Act Prohibited Practices: Article 5 Guide
The 8 prohibited AI practices under Article 5 of the EU AI Act: examples, penalties, enforcement since February 2025 and a compliance checklist.
GPAI Obligations Under the EU AI Act Explained
Complete guide to general-purpose AI model obligations under the EU AI Act. Documentation, transparency, copyright, and systemic risk requirements.
AI Systems Inventory for EU AI Act Compliance
How to build an AI systems inventory for EU AI Act compliance. Shadow AI discovery, required fields, prioritisation, and templates.
AI Act Conformity Assessment: Self vs Notified Body
Complete guide to EU AI Act conformity assessment. Compare self-assessment (Annex VI) vs notified body (Annex VII), costs, timelines, and CE marking.
AI Act Technical Documentation: Annex IV Guide
EU AI Act Annex IV technical documentation guide. All 9 sections, practical examples, SME simplifications, and a preparation checklist.
EU AI Act vs GDPR: Differences and Overlap Guide
EU AI Act vs GDPR comparison for compliance teams. Fines, roles, impact assessments, overlaps, and 5 strategies for integrated compliance.
EU AI Act Compliance Checklist 2026: Full Guide
Practical EU AI Act compliance checklist: risk classification, documentation, conformity assessment and monitoring, with the deferred 2027 and 2028 dates.
EU AI Act Penalties and Fines Explained (2026)
Complete breakdown of EU AI Act fines up to EUR 35M or 7% of turnover. Covers penalty tiers, enforcement, SME adjustments, and risk reduction.
AI Act Provider vs Deployer Obligations Compared
Complete comparison of EU AI Act provider and deployer obligations for high-risk AI. Covers Article 25, supply chain roles, and compliance.
Is My AI System High-Risk Under the EU AI Act?
Step-by-step guide to classifying AI systems as high-risk under the EU AI Act. Covers Article 6, Annex III domains, exceptions, and compliance.
Free AI Act Risk Classification in 5 Minutes
Use this free AI Act risk classification tool to determine your AI system's risk tier, applicable obligations, and next compliance steps.
Privacy Policy Checklist for AI Companies (2026)
A complete privacy policy checklist for companies using AI, covering GDPR Articles 13-14, AI Act Article 50, and AI-specific disclosures.
GDPR Compliance for AI Companies: Getting Started
A practical GDPR compliance guide for AI companies, covering lawful bases, training data, automated decisions, DPIAs, and AI Act alignment.
EU AI Act Timeline: Key Dates and Deadlines (Updated July 2026)
EU AI Act timeline 2024-2028 after the Digital Omnibus: high-risk deferred to 2 December 2027, Annex I to 2 August 2028, Article 50 live since 2 August 2026.
Understanding the EU AI Act: A Complete Guide
A complete guide to understanding the EU AI Act, its risk-based approach, who it applies to, key deadlines, and what companies must do to comply.
Run your free AI Act assessment
No credit card required. No login needed. Start with a practical, defensible first compliance output.
✓ AI Act risk classification • ✓ Obligation mapping • ✓ Documentation export path
Not legal advice: Results are informational and require human/legal review.


























































