AI Act — compliance
Application of most AI Act provisions starts on 2 August 2026. Is your company ready?
From 2 August 2026, most AI Act obligations apply (some bans and duties already apply earlier). They also reach companies that “merely use” off-the-shelf AI tools.
Updated:
2 Aug 2026
most AI Act obligations start to apply (Reg. EU 2024/1689)
EUR 35M
or 7% of turnover — maximum fines (AI Act, Art. 99)
EUR 15M
or 3% of turnover — fines for breaching the remaining obligations (AI Act, Art. 99(4))
2 Dec 2027
deferred deadline for Annex III high-risk systems (Digital Omnibus)
EU AI Act compliance audit
What is an EU AI Act compliance audit?
An EU AI Act compliance audit is a fixed-scope review that establishes how the EU AI Act (Regulation 2024/1689) applies to your company and what to put in place before the obligations apply — most of them from 2 August 2026. For most companies in Poland and the EU it confirms their role as a deployer (and sometimes provider), inventories every AI system in use — including “shadow AI” — and assigns each one a risk category.
Semitora runs it as a working engagement, not a slide deck: typically 2–4 weeks, ending with a documented risk classification and a prioritised plan to close the gaps. It is an implementation-led audit — the result feeds straight into building compliant AI, not a binder for the shelf.
- ✓AI system inventory — every tool in use, including shadow AI
- ✓Deployer / provider classification under the AI Act
- ✓Risk class per system: prohibited / high-risk / limited / minimal
- ✓Gap-closing plan with owners and priorities
- ✓AI literacy scope for staff (Article 4)
- ✓Technical documentation requirements for high-risk systems
Definitions
Key AI Act terms — in one sentence
Deployer (the company using AI)
An organisation that uses an AI system under its authority in a professional context — including off-the-shelf tools like ChatGPT. Most companies using AI are deployers, and have their own AI Act obligations.
Provider
An entity that develops an AI system or model and places it on the market or puts it into service under its own name — including when the build is outsourced. A company can be a provider of some systems and a deployer of others; each role carries different AI Act obligations.
AI literacy (Article 4)
Article 4 requires providers and deployers to take measures to support the development of AI literacy among staff and other people operating AI on their behalf. The measures should reflect their knowledge, experience, the context of use and the people affected. It does not require them to guarantee a specific level of AI literacy.
Human oversight (Article 14)
For high-risk AI systems, Article 14 requires effective human oversight during use: a person who understands how the system works, can question its output and — where appropriate — stop the system before it causes harm.
Shadow AI
AI tools used by employees outside the company's knowledge and control — private ChatGPT accounts, plugins, automations. They increase data-leak risk and can make AI Act or GDPR compliance harder, especially where personal data, regulated decisions or high-risk AI are involved.
Digital Omnibus
Amending Regulation (EU) 2026/1744, published on 24 July 2026, entered into force on 27 July 2026. It defers the full obligations for Annex III high-risk systems to 2 December 2027 and Annex I systems to 2 August 2028. Application of most AI Act provisions still starts on 2 August 2026, and Article 50 has not been postponed.
How we help
Compliance as a process, not a binder.
We don't produce documents for a drawer. We build a working compliance system: inventory, classification, documentation and oversight that survive an inspection and the next regulatory change.
Compliance audit
A review of every AI system and tool in the organisation — including the ones IT doesn't know about.
Mapping & classification
Assigning each system to its AI Act risk category and the obligations that follow.
Technical documentation
Documentation for high-risk systems: data, architecture, oversight, event logging.
“AI literacy” training
Measures supporting employees’ AI literacy (Article 4), tailored to their knowledge, experience and context of use.
Governance & human oversight
AI usage policies, roles and responsibilities, human oversight procedures.
30-day plan
A 30-day AI Act readiness plan
How to go from “we don’t know what we have” to a documented map of your AI systems and a prioritised gap-closing plan in four weeks. This is how we run the audit — and how you can start before most obligations take effect on 2 August 2026.
Week 1
Inventory and shadow AI
We list every AI tool in use — including private ChatGPT accounts and automations IT doesn’t know about. The result is an AI systems register: who, where, on what data and for what purpose.
Week 2
Roles and risk classification
We assign each system your company’s role (deployer / provider) and an AI Act risk category: prohibited, high, limited or minimal. The result is a prioritised risk matrix.
Week 3
AI literacy and human oversight
We tailor measures that support staff AI literacy (Art. 4) and set up human oversight of high-risk systems (Art. 14): someone who understands the system, can challenge its output and stop it. Plus AI usage policies.
Week 4
Documentation requirements and gap backlog
We map the documentation requirements for high-risk systems and close the plan: a prioritised gap-closing backlog, ready to ship as GenAI/RAG implementations on AWS — not a binder on a shelf.
What you get
An audit that ends in an implementation backlog — not slides.
The output of an AI Act audit is a set of working artefacts your board, IT and lawyers actually use — and the starting point for implementation.
AI systems register
A map of every AI system and tool: owner, users, data, purpose and legal basis — including the “shadow AI” we uncover.
Risk matrix
Each system assigned to an AI Act category (prohibited / high-risk / limited-risk / minimal) and to your role: provider or deployer.
Documentation requirements
The documents and mechanisms required for high-risk systems: data, architecture, human oversight, event logging.
Implementation & PoC backlog
A prioritised list of actions that close the gaps — ready to ship as GenAI/RAG implementations on AWS, not to be shelved.
Then we build the backlog: RAG on your documents, production AI systems. See also the AI Act readiness checklist.
Polish law
The Polish angle: a national act and a new regulator (KRiBSI)
On top of the EU AI Act, Poland is enacting a national act on artificial intelligence systems that provides for its enforcement in Poland. The act was signed by the President on 27 July 2026 and awaits publication in the Journal of Laws and entry into force; as of this update it is not yet binding law.
The act provides for a national supervisory authority: the Commission for the Development and Security of Artificial Intelligence (KRiBSI). Once in force, it — not just Brussels — will enforce the AI Act against Polish companies, which is why your AI inventory, risk classification and oversight are worth having ready before the AI Act obligations take effect (most from 2 August 2026).
- ✓KRiBSI combines existing regulators: UOKiK, KNF, KRRiT and UKE; the Sejm appoints its chair with consent of the Senate
- ✓Powers: company inspections, handling complaints, supervising high-risk AI systems and issuing statutory decisions
- ✓Regulatory sandboxes and individual opinions — a path for companies piloting AI
- ✓Poland is setting up oversight late (the AI Act expected an authority from 2 August 2025)
Go deeper
The AI Act in practice — from our blog
FAQ
Common questions about the AI Act
Yes. As a “deployer” you have obligations: ensuring employees' AI literacy (Article 4), overseeing how AI is used and — depending on the use case — further requirements. The key is establishing what AI is really used for in your company, including “shadow AI”.
Maximum fines reach EUR 35M or 7% of global annual turnover (prohibited practices) and EUR 15M or 3% (other violations). Beyond fines, the practical risk is disputes with business partners, who increasingly require compliance in contracts.
With an inventory: what uses AI, where and why — including tools employees adopted on their own. Then risk classification and a gap-closing plan. That is exactly the scope of our audit.
AI tools used by employees outside the company's knowledge and control — private ChatGPT accounts, plugins, automations. The risks: leakage of company and customer data, and harder AI Act or GDPR compliance, especially where personal data or high-risk AI are involved. A shadow-AI inventory is the first week of our audit.
Typically 2–4 weeks, depending on the number of systems and the size of the organisation. It ends with a report containing risk classification and an action plan — a working document, not a decorative one.
Any company in the EU that develops or uses AI systems in a professional context — in practice almost every company using tools like ChatGPT, Copilot or a custom model. You are a “deployer” even when you only use off-the-shelf AI, and deployers have their own obligations. An audit is most urgent where AI touches personal data, regulated decisions or high-risk use cases.
An inventory of the AI systems in use (including shadow AI), each system’s deployer/provider classification and risk category, evidence of AI literacy measures for staff (Article 4), human-oversight and AI usage policies, and — for systems whose obligations apply by then — the technical documentation those obligations require. A compliance audit maps exactly what each system needs and where the gaps are, with a plan to close them.
GPAI (general-purpose AI) models — large models like GPT or Gemini — carry AI Act obligations such as technical documentation, a copyright policy and a training-data summary. These apply from 2 August 2025 and, as a rule, fall on the model provider (e.g. OpenAI, Google), not on a company that merely uses the model. Your company can itself become a GPAI provider if it fine-tunes or substantially modifies such a model and places it on the market under its own name. Models with systemic risk carry extra obligations (evaluations, testing, incident reporting). The audit determines whether you are only a deployer or cross the GPAI-provider threshold.
The act on artificial intelligence systems was signed by the President on 27 July 2026 and awaits publication in the Journal of Laws and entry into force, so as of this update it is not yet binding law. It provides for a national supervisory authority — the Commission for the Development and Security of Artificial Intelligence (KRiBSI), made up of representatives of UOKiK, KNF, KRRiT and UKE — which will oversee AI use, handle complaints and supervise high-risk systems. Regardless of the national act, the AI Act's own obligations start applying in stages, most from 2 August 2026.
In four weeks you can build the readiness foundation: a register of the AI systems you use (including shadow AI), a role and risk classification, the scope of AI literacy (Art. 4) and human oversight (Art. 14), and a prioritised gap-closing backlog. It is not a guarantee of full compliance — the gaps themselves are then closed through implementation and documentation, and some obligations only start applying on 2 August 2026. The 30-day plan does give you a clear picture of where you stand and what to do next.
Open register
See every AI system and use case in one portfolio view.
Record owners, stage, data, integrations, supplier, volume, error impact and the next review date. Roles and risk remain explicitly marked for verification.
Free tool
Is your organisation ready for a bounded AI PoC?
Answer 24 questions about process, data, shadow AI, ownership, risk and governance. The result points to the next step without claiming automatic conformity.
Open governance template
Separate accountability for an AI system from decision authority.
Complete a 7-stage × 7-role matrix and decision rights covering the decider, required input, evidence, escalation and response time. Every stage has exactly one Accountable.
Little time remains before most AI Act provisions start to apply.
A compliance audit closes the inventory and classification topic within weeks — and gives you an action plan right away.