Know which AI Act deadline is yours.

    Build a clear, defensible classification for every AI system so you know exactly which obligations apply.

    app.whisperly.ai / eu-ai-act
    EU AI Act
    Back
    AI Recruitment Scoring Module
    High risk
    MK
    Owner
    Maya Kessler, People Ops
    1
    Classification
    Risk tiering
    2
    Data & training
    Provenance
    3
    Human oversight
    Art. 14
    4
    Technical docs
    Annex IV
    Risk classification
    Scored against risk criteria. Employment and worker management.
    72 / 100
    Data sensitivityHigh
    Automation levelMedium
    Human oversightDocumented
    TransparencyPartial

    The enforcement clock, after the Omnibus.

    The EU AI Act applies in waves. Know what each tier means and what your team must have ready.

    2 Aug 2026
    Next deadline
    Article 50 transparency obligations apply
    Not deferred. Chatbot disclosure, synthetic media labelling, emotion recognition and biometric categorisation notices, and public interest text disclosure all land on this date. Article 50 is several distinct duties on different actors, not one blanket rule, which is where over-compliance and under-compliance both happen.
    Days away
    2 Feb 2025
    In force
    Prohibited practices banned, AI literacy required
    Social scoring, subliminal manipulation, untargeted facial scraping and predictive policing outlawed outright. Untouched by the Omnibus.
    Enforceable
    2 Aug 2025
    In force
    General-purpose AI model rules apply
    Transparency, technical documentation and copyright compliance for GPAI providers. Articles 51 to 55 were not amended, so foundation model work continues as before.
    Enforceable
    2 Dec 2026
    New
    Legacy content marking, and a new prohibition
    Article 50(2) machine-readable marking reaches systems already on the market before August 2026, a four month grace rather than the six originally proposed. The Omnibus also adds a prohibition on AI generating non-consensual intimate imagery and child sexual abuse material.
    Added
    2 Aug 2027
    Upcoming
    Sandboxes and sectoral delegated acts
    Member States must have at least one national AI regulatory sandbox running, and the Commission faces its deadline for delegated acts on Annex I sectoral rules.
    Infrastructure
    2 Dec 2027
    Deferred from Aug 2026
    High-risk obligations, Annex III standalone systems
    Employment, credit and essential services, education, law enforcement and migration. Conformity assessment, risk management, human oversight and technical documentation. Sixteen extra months, and the application date is no longer tied to harmonised standards being finalised.
    Moved
    2 Aug 2028
    Deferred from Aug 2027
    High-risk obligations, Annex I embedded systems
    AI inside products already covered by EU product safety law, such as medical devices, machinery and toys.
    Moved

    Four risk tiers. Different rules for each.

    Everything follows from classification. Get the tier wrong and you either over-document, or miss obligations priced in global revenue.

    Unacceptable

    Banned outright

    Systems posing severe threats to fundamental rights. There is no compliance route, only withdrawal.

    Examples: social scoring, subliminal manipulation, real-time biometric identification, predictive policing.
    €35M or 7%
    Banned since Feb 2025, extended Dec 2026
    High risk

    Strict obligations

    Systems affecting people in sensitive domains. Conformity assessment, risk management and human oversight all apply, now from December 2027.

    Examples: hiring and CV screening, credit scoring, medical diagnostics, education assessment.
    €15M or 3%
    Annex III from Dec 2027, Annex I from Aug 2028
    Limited risk

    Transparency rules

    Systems that interact with people or generate content. The duty is disclosure, not assessment.

    Examples: chatbots, AI-generated content, deepfakes, emotion recognition.
    Disclosure
    Required from Aug 2026, not deferred
    Minimal risk

    Voluntary codes

    Most AI in most businesses. No mandatory obligations, but you still need to have shown the system sits here.

    Examples: spam filters, inventory forecasting, recommendation engines, AI in games.
    None
    Classification still evidenced
    A separate penalty tier covers misleading the authorities.
    Supplying incorrect or incomplete information to regulators carries up to €7.5 million or 1% of global annual revenue, independent of the tier your system falls into.

    Start free, before you start buying.

    Two tools that answer the first two questions any AI governance programme faces: what do we run, and what does the Act require of it.

    Free tool

    EU AI Act Compliance Checker

    Answer a short set of questions about one AI system and get its likely risk tier with the obligations that follow. Useful before a budget conversation, because it turns "we should look at the AI Act" into a specific list of what is owed and by when.

    Indicative risk tier under Annex I and Annex III
    Your role: provider, deployer, importer or distributor
    The deadline that actually applies to you
    Run the free checker
    Free template

    AI Inventory Template

    Every obligation under the Act starts with knowing which AI systems you run, and most organisations cannot say. This template gives you the columns that matter, so a first inventory is an afternoon rather than a project.

    Owner, purpose, data used and deployment context
    Third-party models and APIs captured alongside your own
    Structured so it imports straight into the platform later
    Download the template
    Want the whole picture first?
    The EU AI Act Guidebook walks through classification, obligations by role and the documentation each tier requires.
    Read the Guidebook

    Your role decides your obligations.

    The same AI system carries different duties depending on where you sit in the chain. Most organisations occupy more than one of these positions at once.

    Providers

    You build, train or place an AI system on the market under your own name.

    Heaviest obligations

    Deployers

    You use someone else's AI in your operations, which is most companies. Human oversight, logging and impact assessment apply to you.

    Significant obligations

    Importers and distributors

    You bring non-EU AI systems to the European market and must verify conformity assessment and CE marking.

    Verification duties

    Non-EU organisations

    Your company sits outside the EU but your AI output reaches EU users. The Act reaches you, exactly as the GDPR does.

    Extraterritorial scope

    Four stages. One continuous programme.

    Whisperly runs the Act as a lifecycle rather than a document exercise, and links it to your GDPR programme so a system processing personal data is governed once.

    01

    Discover and register

    Nothing can be governed until it is known. Intake catches new initiatives before they reach production, and discovery finds the AI already running in your stack.

    AI intake and approval workflowPre-launch
    AI inventory and model libraryArt. 49, 60
    Third-party and vendor AISupply chain
    Assess AI vendors →
    02

    Classify

    Each system scored against Annex I and Annex III criteria, with the reasoning recorded. A defensible minimal-risk conclusion is worth as much as a high-risk one.

    Risk classification engineAnnex I, III
    Fundamental rights impact assessmentArt. 27
    Pre-built AI risk libraryBias, safety
    Try the free checker →
    03

    Document

    The Annex IV technical file, human oversight procedures and AI policies generated from what the platform already holds, rather than drafted from scratch per system.

    Technical documentation generatorAnnex IV
    AI policies and oversight proceduresArt. 14
    Shared DPIAs and processing recordsGDPR link
    Connect to GDPR →
    04

    Monitor and prove

    Models change, and a classification made last year may not hold. Drift triggers re-assessment, and every change is timestamped for the file.

    Live monitoring and drift alertsPost-market
    Immutable audit trailEvidence
    Cross-team ownership and approvalsGovernance
    Publish to your Trust Center →

    Frequently asked questions

    Yes. As a deployer you owe human oversight, log retention and, for high-risk systems in certain contexts, a fundamental rights impact assessment. You also need to know what the provider has and has not done, because their conformity assessment does not discharge your duties. This is why the inventory has to include third-party models and APIs, not only what you built.

    Ready for what actually lands.

    Start with the free checker and the inventory template, or see the whole programme running alongside your GDPR work.