Skip to content

THE DUTIES THAT ARE ACTUALLY YOURS

EU AI Act compliance: what applies to you.

You leave with a written list of the AI your organisation runs, each system classified, and the two or three duties that are genuinely yours today. Most of what you run sits outside the rules for high-risk AI systems, and once that is settled the work you paused can go ahead.

Read it calmly. Act on it now.

Two failure modes dominate the AI Act market. One is panic: suppliers selling urgency around deadlines that have been postponed, and compliance programmes sized for fear rather than exposure. The other is complacency: reading the postponement as permission to wait. Both are expensive.

Our reading is simpler. Some duties are already in force and carry penalties. Some arrive on a fixed calendar, and that calendar is now settled.

And most of the AI your organisation actually runs is probably not high-risk at all. The Act's risk categories are narrower than the market implies, which means the right response is rarely to stop. It is to know what you have, meet the duties that apply today, and use the runway to prepare for the ones that come.

A supplier who sells you fear of a deadline that moved is telling you something about their business model.

The Act's hardest requirements are not technical. Competence, oversight, accountability and documented judgement are organisational obligations. They are settled in the leadership team, not in a development environment. That is where we work.

In force today. AI literacy and prohibitions.

01

A duty to promote AI literacy (Article 4).

If your organisation uses AI, you must take measures to support the AI literacy of the people working with it. AI literacy is the Act's own term for what most people call AI competence. Regulation (EU) 2026/1744 turned this into a duty of effort rather than a guaranteed result, but it still binds, it covers every AI system regardless of risk, and it sits with leadership.

02

Outright prohibitions (Article 5).

A short list of practices is banned outright, and the list binds every provider and every deployer. Only the ban on real-time remote biometric identification is limited by purpose, to law enforcement. The rest are not: social scoring, untargeted scraping of facial images, emotion recognition in the workplace, and the two the Digital Omnibus added on generated child sexual abuse material and non-consensual intimate images. Checking the list is quick. Assuming it cannot reach you is not the same thing.

03

Transparency duties.

People must be told when they are interacting with an AI system, and synthetic content must be identifiable as such. These duties are the nearest milestone on the calendar below. The sanctions behind them are not new: the penalty regime has applied since August 2025.

04

Data protection never went away.

The General Data Protection Regulation (GDPR) is EU law. Most AI questions are still GDPR questions first: legal basis, impact assessments, data flows to model providers. In Sweden, AI governance lands on top of an already tightened environment, not in a vacuum.

On the calendar. The EU AI Act timeline.

High-risk AI systems in defined use areas, among them recruitment, credit scoring, education and essential services, arrive on a fixed runway: risk management, quality management, the fundamental rights impact assessment, and conformity assessment. Product-embedded AI follows later on its own track, and public bodies must have everything they still run in compliance by 2 August 2030.

The fundamental rights impact assessment is where the market's shorthand does most damage. Article 27 names two groups: bodies governed by public law and private entities providing public services, across Annex III apart from critical infrastructure, and every deployer of a creditworthiness or life and health insurance pricing system, commercial ones included. The exemption follows use, not ownership.

The runway is only an advantage if you use it. The GDPR years showed what starting at the deadline costs: when everyone prepares at once, assessors and specialists become the bottleneck, and prices follow.

No harmonised standards under the Act have been published yet. Until then there is no presumption of conformity to lean on, and compliance is demonstrated with your own documentation. Management-system standards are useful, but they are not harmonised standards and give no presumption. Anyone selling you certainty today is selling something the law does not yet contain.

EU AI ACT DEADLINES

What applies, and when.

Verified against primary sources 3 August 2026

In force since 2 February 2025

AI literacy duty (art. 4) and prohibited practices (art. 5), all AI systems regardless of risk level

In force since 2 August 2025

Obligations for general-purpose model providers (ch. V), and the penalty regime (art. 99): up to EUR 35 million or 7 % of global turnover for prohibited practices, EUR 15 million or 3 % for most other infringements, EUR 7.5 million or 1 % for supplying incorrect information

In force since 2 August 2026

Transparency duties (art. 50) and the general application date of the Act, including the market surveillance provisions in articles 73 to 94

2 December 2026

Machine-readable marking of synthetic content for generative systems already on the market, and the two prohibitions the Digital Omnibus added on AI-generated child sexual abuse material and non-consensual intimate images

2 August 2027

Every member state must have at least one AI regulatory sandbox operational (art. 57), moved back a year by the Digital Omnibus

2 December 2027

High-risk obligations, Annex III use areas (recruitment, credit scoring, education, essential services, law enforcement among others): risk management, quality management and conformity assessment. The fundamental rights impact assessment (art. 27) applies from the same date. It binds bodies governed by public law and private entities providing public services, and separately every deployer of creditworthiness or life and health insurance pricing systems, commercial ones included. Critical infrastructure systems are exempt from that duty

2 August 2028

High-risk obligations, Annex I (product-embedded AI: machinery, medical devices among others)

2 August 2030

Public bodies must have existing high-risk systems in compliance with chapter III, including article 27 (art. 111(2)). This backstop belongs to public bodies alone: private operators have no equivalent transition, and the relief for systems left unchanged does not survive it

The amending regulation, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. The dates above reflect it. This module is updated as each milestone passes, and again when the first harmonised standards publish.

Who supervises and enforces in Sweden.

The AI Act is EU law and applies identically across the union, but enforcement is national: each member state names its own supervisory authorities. Sweden has not finished doing so.

The government has given the Swedish Post and Telecom Authority (Post- och telestyrelsen, PTS) an interim mandate as national competent authority until 31 December 2026. A public inquiry has proposed PTS for the permanent role, and that proposal is not law yet.

The Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) covers AI that processes personal data, the Swedish Financial Supervisory Authority (Finansinspektionen) the financial sector, and the Swedish Medical Products Agency (Läkemedelsverket) medical devices and care.

The Swedish Board for Accreditation and Conformity Assessment (Styrelsen för ackreditering och teknisk kontroll, Swedac), the national accreditation body, accredits the notified bodies.

For most organisations the practical consequence is simple: AI supervision will largely arrive through authorities you already know.

IMY has an inspection of a region's AI transcription service in primary care underway, opened in May 2026. It rests on data protection law rather than on the AI Act, which is the useful lesson: the first supervisory pressure on AI in Sweden arrives through the GDPR.

A Swedish implementing act and a regulatory sandbox are still to come. We track both.

What we do about it. EU AI Act compliance in practice.

01

Transparency readiness.

A small, fast, fixed-price review: which of your systems interact with people or generate content, what disclosure and marking they require, and which of those you already meet. Weeks, not months.

02

High-risk runway programme.

For organisations with use cases on the high-risk list: risk management, quality management, FRIA processes and documentation, built in calm tempo against the calendar. We sell the head start, never the panic. Our methodology tracks the standards as they publish; we will never sell you a presumption that does not yet exist.

03

AI Readiness Assessment.

Risk classification under the Act is built into every assessment from the start, so what you decide to build is compliant by design, not audited after.

04

Executive and leadership team sessions.

The competence duty starts where accountability sits. We work directly with boards and leadership teams: what the Act makes you responsible for, what your AI portfolio actually contains, and which decisions are yours to make. Delivered by Ampliro, in the boardroom.

05

Role-specific competence programmes for the wider organisation.

For managers and staff: role-specific tracks, documented completion, and annual updates as tools and rules change. Delivered through AIUC, our education arm.

QUESTIONS

Before you classify your systems.

The EU AI Act treats two groups as high-risk. Annex III lists standalone uses: recruitment, creditworthiness assessment of natural persons, education, essential public services, law enforcement, migration and justice. Annex I covers AI acting as a safety component in an already regulated product, from machinery to medical devices. Annex III duties apply from 2 December 2027, Annex I from 2 August 2028. Most AI in daily operation falls outside both.

Parts of the EU AI Act already bind you. The AI literacy duty in Article 4 and the prohibited practices in Article 5 have applied since 2 February 2025, and the obligations for general-purpose model providers and the penalty regime in Article 99 since 2 August 2025. Transparency duties in Article 50 follow on 2 August 2026, and the high-risk duties on 2 December 2027 and 2 August 2028.

Waiting is only safe for the high-risk duties themselves, which Regulation (EU) 2026/1744 moved to 2 December 2027 and 2 August 2028. Nothing else moved: Article 4 and Article 5 have applied since 2 February 2025, the penalty regime since 2 August 2025, and Article 50 transparency arrives on 2 August 2026. Near a deadline, assessors and specialists become the bottleneck, and prices follow.

Yes, the EU AI Act still applies. The AI literacy duty in Article 4 has bound every organisation using AI since 2 February 2025, whatever the risk level, and transparency duties may apply from 2 August 2026 depending on what the embedded feature does. Embedded AI also belongs in your inventory: you cannot classify what you have not written down.

The EU AI Act requires it of a private company in two situations. Article 27 binds private entities providing public services exactly as it binds bodies governed by public law, across Annex III apart from critical infrastructure. It also binds every deployer of a system assessing the creditworthiness of natural persons, or pricing and assessing risk in life and health insurance, purely commercial ones included. Outside those two it does not apply. The date is 2 December 2027.

A public body must have its existing high-risk systems compliant with chapter III of the EU AI Act, Article 27 included, by 2 August 2030 under Article 111(2). That deadline holds whether or not the systems have been changed, and the relief for systems left substantially unchanged belongs to other deployers. New systems follow the ordinary dates, 2 December 2027 for Annex III.

ISO/IEC 42001 does not by itself make you compliant with the EU AI Act. It is a useful management-system standard, but it is not a harmonised standard under the Act and gives no presumption of conformity. No harmonised standards under the Act have been published yet, so compliance is demonstrated with your own documentation. We build that documentation so that it tracks the standards as they publish.

Know where you stand.

One conversation usually settles the two questions that matter: which of your systems the Act actually touches, and which duty is nearest. If the honest answer is that you have little to do, we will say so.