Skip to content

AI Act — compliance

Application of most AI Act provisions starts on 2 August 2026. Is your company ready?

From 2 August 2026, most AI Act obligations apply (some bans and duties already apply earlier). They also reach companies that “merely use” off-the-shelf AI tools.

Updated:

2 Aug 2026

most AI Act obligations start to apply (Reg. EU 2024/1689)

EUR 35M

or 7% of turnover — maximum fines (AI Act, Art. 99)

EUR 15M

or 3% of turnover — fines for breaching the remaining obligations (AI Act, Art. 99(4))

2 Dec 2027

deferred deadline for Annex III high-risk systems (Digital Omnibus)

EU AI Act compliance audit

What is an EU AI Act compliance audit?

An EU AI Act compliance audit is a fixed-scope review that establishes how the EU AI Act (Regulation 2024/1689) applies to your company and what to put in place before the obligations apply — most of them from 2 August 2026. For most companies in Poland and the EU it confirms their role as a deployer (and sometimes provider), inventories every AI system in use — including “shadow AI” — and assigns each one a risk category.

Semitora runs it as a working engagement, not a slide deck: typically 2–4 weeks, ending with a documented risk classification and a prioritised plan to close the gaps. It is an implementation-led audit — the result feeds straight into building compliant AI, not a binder for the shelf.

  • AI system inventory — every tool in use, including shadow AI
  • Deployer / provider classification under the AI Act
  • Risk class per system: prohibited / high-risk / limited / minimal
  • Gap-closing plan with owners and priorities
  • AI literacy scope for staff (Article 4)
  • Technical documentation requirements for high-risk systems

Definitions

Key AI Act terms — in one sentence

Deployer (the company using AI)

An organisation that uses an AI system under its authority in a professional context — including off-the-shelf tools like ChatGPT. Most companies using AI are deployers, and have their own AI Act obligations.

Provider

An entity that develops an AI system or model and places it on the market or puts it into service under its own name — including when the build is outsourced. A company can be a provider of some systems and a deployer of others; each role carries different AI Act obligations.

AI literacy (Article 4)

Article 4 requires providers and deployers to take measures to support the development of AI literacy among staff and other people operating AI on their behalf. The measures should reflect their knowledge, experience, the context of use and the people affected. It does not require them to guarantee a specific level of AI literacy.

Human oversight (Article 14)

For high-risk AI systems, Article 14 requires effective human oversight during use: a person who understands how the system works, can question its output and — where appropriate — stop the system before it causes harm.

Shadow AI

AI tools used by employees outside the company's knowledge and control — private ChatGPT accounts, plugins, automations. They increase data-leak risk and can make AI Act or GDPR compliance harder, especially where personal data, regulated decisions or high-risk AI are involved.

Digital Omnibus

Amending Regulation (EU) 2026/1744, published on 24 July 2026, entered into force on 27 July 2026. It defers the full obligations for Annex III high-risk systems to 2 December 2027 and Annex I systems to 2 August 2028. Application of most AI Act provisions still starts on 2 August 2026, and Article 50 has not been postponed.

How we help

Compliance as a process, not a binder.

We don't produce documents for a drawer. We build a working compliance system: inventory, classification, documentation and oversight that survive an inspection and the next regulatory change.

Compliance audit

A review of every AI system and tool in the organisation — including the ones IT doesn't know about.

Mapping & classification

Assigning each system to its AI Act risk category and the obligations that follow.

Technical documentation

Documentation for high-risk systems: data, architecture, oversight, event logging.

“AI literacy” training

Measures supporting employees’ AI literacy (Article 4), tailored to their knowledge, experience and context of use.

Governance & human oversight

AI usage policies, roles and responsibilities, human oversight procedures.

30-day plan

A 30-day AI Act readiness plan

How to go from “we don’t know what we have” to a documented map of your AI systems and a prioritised gap-closing plan in four weeks. This is how we run the audit — and how you can start before most obligations take effect on 2 August 2026.

Week 1

Inventory and shadow AI

We list every AI tool in use — including private ChatGPT accounts and automations IT doesn’t know about. The result is an AI systems register: who, where, on what data and for what purpose.

Week 2

Roles and risk classification

We assign each system your company’s role (deployer / provider) and an AI Act risk category: prohibited, high, limited or minimal. The result is a prioritised risk matrix.

Week 3

AI literacy and human oversight

We tailor measures that support staff AI literacy (Art. 4) and set up human oversight of high-risk systems (Art. 14): someone who understands the system, can challenge its output and stop it. Plus AI usage policies.

Week 4

Documentation requirements and gap backlog

We map the documentation requirements for high-risk systems and close the plan: a prioritised gap-closing backlog, ready to ship as GenAI/RAG implementations on AWS — not a binder on a shelf.

What you get

An audit that ends in an implementation backlog — not slides.

The output of an AI Act audit is a set of working artefacts your board, IT and lawyers actually use — and the starting point for implementation.

AI systems register

A map of every AI system and tool: owner, users, data, purpose and legal basis — including the “shadow AI” we uncover.

Risk matrix

Each system assigned to an AI Act category (prohibited / high-risk / limited-risk / minimal) and to your role: provider or deployer.

Documentation requirements

The documents and mechanisms required for high-risk systems: data, architecture, human oversight, event logging.

Implementation & PoC backlog

A prioritised list of actions that close the gaps — ready to ship as GenAI/RAG implementations on AWS, not to be shelved.

Polish law

The Polish angle: a national act and a new regulator (KRiBSI)

On top of the EU AI Act, Poland is enacting a national act on artificial intelligence systems that provides for its enforcement in Poland. The act was signed by the President on 27 July 2026 and awaits publication in the Journal of Laws and entry into force; as of this update it is not yet binding law.

The act provides for a national supervisory authority: the Commission for the Development and Security of Artificial Intelligence (KRiBSI). Once in force, it — not just Brussels — will enforce the AI Act against Polish companies, which is why your AI inventory, risk classification and oversight are worth having ready before the AI Act obligations take effect (most from 2 August 2026).

  • KRiBSI combines existing regulators: UOKiK, KNF, KRRiT and UKE; the Sejm appoints its chair with consent of the Senate
  • Powers: company inspections, handling complaints, supervising high-risk AI systems and issuing statutory decisions
  • Regulatory sandboxes and individual opinions — a path for companies piloting AI
  • Poland is setting up oversight late (the AI Act expected an authority from 2 August 2025)

FAQ

Common questions about the AI Act

Yes. As a “deployer” you have obligations: ensuring employees' AI literacy (Article 4), overseeing how AI is used and — depending on the use case — further requirements. The key is establishing what AI is really used for in your company, including “shadow AI”.

Open register

See every AI system and use case in one portfolio view.

Record owners, stage, data, integrations, supplier, volume, error impact and the next review date. Roles and risk remain explicitly marked for verification.

Open the AI system register

Free tool

Is your organisation ready for a bounded AI PoC?

Answer 24 questions about process, data, shadow AI, ownership, risk and governance. The result points to the next step without claiming automatic conformity.

Open the AI Readiness Scorecard

Open governance template

Separate accountability for an AI system from decision authority.

Complete a 7-stage × 7-role matrix and decision rights covering the decider, required input, evidence, escalation and response time. Every stage has exactly one Accountable.

Open the AI Governance RACI

Little time remains before most AI Act provisions start to apply.

A compliance audit closes the inventory and classification topic within weeks — and gives you an action plan right away.