Skip to content

EU AI Act — Customer Guide

Last updated: 2026-05-21 (Plan 145 v1)

What is the EU AI Act, and why does it matter to you?

The EU AI Act is Regulation (EU) 2024/1689, the European Union's horizontal AI law. It applies to providers and deployers of AI systems placed on the market or put into service in the EU, regardless of where the provider is established. For high-risk systems the operative date is 2 August 2026, and the penalty bracket under Article 99 reaches EUR 35 million or 7% of worldwide annual turnover for the prohibited-AI infringements in Article 5. The quickest way to take pressure off your team is to have the evidence your market-surveillance authority asks for — the inventory, the classification, the risk register, the human- oversight record — ready before 2 August 2026 rather than after.

What EU AI Act-specific features does Secruna ship?

  • Rule book v1 — 19 rules at rule_book/v1/eu-ai-act/ covering Annex III high-risk triggers plus the deployer / provider obligations in Articles 9-16, 26 and 50. Loader picks it up via KNOWN_FRAMEWORKS["eu_ai_act"].
  • Annex III classification surface — every discovered AI system is mapped to an Annex III point (or marked out of scope) and rendered on /systems/<id> with the citation.
  • FRIA workspace — Article 27 Fundamental Rights Impact Assessment template per in-scope system, pre-populated from the Annex III classification and any linked GDPR Article 35 DPIA.
  • Risk register (Article 9) — per high-risk system, two-person sign-off on every change, dated review cycle.
  • Human-oversight queue (Article 14) — four-eye review on every classification, named oversight role per high-risk system.
  • Serious-incident workflow (Article 73) — incident drafting with a visible 15-day / 2-day countdown against the causal-link timestamp.
  • Evidence pack export — PDF / CSV per system: classification rationale, risk register, oversight record, reviewer signatures and audit trail.
  • Exposure view — live €35M / 7%, €15M / 3% and €7.5M / 1% exposure per Article-99 bracket against your declared turnover.

Limitations (v1)

  • No conformity-assessment body integration. Article 43 conformity assessment for some high-risk Annex III categories requires a notified body. Secruna assembles the technical documentation; the customer engages the notified body.
  • No automatic post-market monitoring report generation. Article 72 post-market monitoring is scaffolded but the periodic report is drafted by the operator from the platform record.
  • No GPAI Article 51 model coverage. General-purpose AI model obligations are tracked separately; v1 focuses on the Annex III high-risk system path used by Secruna's primary buyers.

What the EU AI Act is

Regulation (EU) 2024/1689 was adopted on 13 June 2024, entered force on 1 August 2024, and is being phased in over 2025-2027. Key dates:

  • 2 February 2025 — Chapter I (general) + Chapter II (prohibited practices, Article 5) applicable.
  • 2 August 2025 — General-purpose AI (Article 51 et seq.) applicable.
  • 2 August 2026 — High-risk systems (Annex III) and most remaining obligations applicable. The headline deadline.
  • 2 August 2027 — High-risk systems already on the market before 2 August 2026 must comply (with limited grandfathering — substantial modifications void the grandfather).

Three layers matter for Secruna customers:

  1. Article 5 prohibited AI — subliminal manipulation, social scoring by public authorities, real-time remote biometric identification in public spaces (narrow exceptions), and the rest of the Article 5 list. Top penalty bracket.
  2. Annex III high-risk — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice, democratic processes. Most Secruna verdicts land here.
  3. Article 50 limited-risk — transparency obligations for chatbots, emotion-recognition systems and AI-generated content.

What Secruna covers

Secruna ships the EU AI Act as a live rule book. Each Article becomes one or more rules with a citation, a connector signal match, and a customer-facing description.

The v1 rule book covers:

  • Article 5 — prohibited practices detector (subliminal manipulation, social scoring, real-time biometric ID).
  • Article 9 — risk-management system, per high-risk system.
  • Article 10 — data governance posture.
  • Article 11 — technical documentation (Annex IV) generator.
  • Article 12 — record-keeping / logging obligation.
  • Article 13 — transparency to deployers.
  • Article 14 — human-oversight roles and override history.
  • Article 15 — accuracy, robustness and cybersecurity posture.
  • Article 16 — provider obligations matrix.
  • Article 26 — deployer obligations matrix.
  • Article 27 — Fundamental Rights Impact Assessment workspace.
  • Article 50 — limited-risk transparency obligations.
  • Article 72 — post-market monitoring scaffolding.
  • Article 73 — serious-incident reporting workflow.
  • Annex III §1-§8 — high-risk classification triggers.

How verdicts map to AI Act categories

Secruna verdict EU AI Act outcome What it means
prohibited Article 5 — system must not be placed on the EU market Stop-the-line obligation.
high_risk Annex III high-risk Full obligation set (Articles 9, 10, 11, 12, 13, 14, 15) applies.
limited_risk Article 50 transparency Transparency obligations apply; full Annex III duties do not.
minimal_risk Out of Annex III, out of Article 5 Documented but not subject to the high-risk obligation set.

Using the evidence pack

The evidence pack is generated from the dashboard under Exports → EU AI Act Evidence Pack (org_admin role required). The file is a per-system PDF / CSV bundle:

  • Cover — system name, Annex III point, generation timestamp, document ID.
  • §1. Classification rationale — the rule that fired, with citation.
  • §2. Article 9 risk register — current entries with reviewer.
  • §3. Article 14 oversight record — named role, training record, recent overrides.
  • §4. Article 27 FRIA — for systems where Article 27 applies.
  • §5. Audit trail — last 90 days of platform activity material to the pack.

Filename: secruna-eu-ai-act-{system_id}-{date}.pdf.

What Secruna does NOT cover

  • The notified-body procedure under Article 43. Conformity assessment by a notified body is out of platform scope.
  • Periodic post-market monitoring reports. Operator-drafted.
  • GPAI Article 51-55 model obligations. Separate pack.
  • The CE marking process itself. Secruna assembles the technical file; the customer files for the CE mark.

Frequently asked

Q. We deployed before 2 August 2026. Are we grandfathered? For high-risk systems already in service, limited grandfathering applies — and substantial modifications void it. Most production AI systems are modified continuously. Treat 2 August 2026 as the date your existing fleet must be documented.

Q. We use a US AI provider. Does the Act still apply? Yes, if the system's output is used in the EU. As deployer, you carry the operational obligations. The US provider must appoint an EU authorised representative under Article 22.

Q. Do we need a FRIA and a GDPR Article 35 DPIA? For most high-risk AI systems, yes — they answer different questions. Secruna maps the two so the underlying evidence is shared.