Full enforcement began August 2026. Fines reach up to €35M or 7% of global turnover. African fintech and healthtech companies serving EU customers are already covered.
Systems that make or influence decisions about credit, hiring, biometrics, or access to essential services fall into Annex III high-risk categories. High-risk providers must complete a conformity assessment before the system reaches the EU market.
A documented assessment of your system against the Act's requirements, supported by technical documentation, a risk management system, and evidence of human oversight.
If you build on, fine-tune, or provide a general-purpose AI model, separate transparency and documentation obligations apply on top of your use-phase duties.
The Act follows the output, not the headquarters. If your AI system's output is used in the EU, you are within reach regardless of where you are registered.
Any system whose results reach EU users, including systems you did not build yourself but deploy under your own brand.
Clinical decision support, triage, diagnostics, and patient-risk scoring sit close to the Act's high-risk categories.
Creditworthiness, fraud scoring, and automated lending decisions are named high-risk uses. This is where enforcement is expected first.
Recommendation, pricing, and personalisation systems carry transparency duties, and profiling raises the risk tier.
Each AI system you run is reviewed and placed against the Act's risk tiers, from prohibited through to minimal risk.
A written report scoring your current position against the obligations that apply to your role as provider or deployer, with gaps ranked by severity.
A sequenced plan with owners and timelines, ordered so the obligations carrying the largest penalty exposure are closed first.
Run the free EU AI Act scope diagnostic. Ten questions, and you get a scope classification, an exposure level, and the next steps that apply to your role.
$2,500
Classification and gap report.
$7,500
Diagnostic plus remediation.
Book a compliance check, or request the EU AI Act exposure checklist first.
Assessment against the EU AI Act risk tiers, Annex III high-risk categories, and the obligations applying to providers and deployers.
This check identifies exposure and prepares your organisation to meet it. It is not legal advice, and it is not a certification. Penalty figures are the statutory maxima set out in the Act.
Africa's first AI governance testing framework, built on AI Verify's five principles.
Prepare for the first certifiable AI management standard before your competitors do.
Fixed pricing across every ARETE readiness, governance and compliance product.