// ai act guide

The EU AI Act,
in plain terms.

The world's first comprehensive AI regulation has been in force since August 2024, and has applied in general to European teams since August 2, 2026. The high-risk tranche is what is still ahead. Here is what it asks of you and how to be ready without the scramble.

476 days to the Annex III high-risk tranche December 2, 2027

// the law

A risk-based rulebook for AI in Europe.

The AI Act regulates AI by how risky its use is, not by the technology itself. It applies to anyone placing an AI system on the EU market or using one inside the EU, including companies that only integrate third-party models.

If your team puts AI into production for European users, the question you have to ask is which obligations you carry, and whether your stack can meet them.

// timeline

How it rolls out.

The Act phases in over three years. The date that matters for most enterprises is the next one.

  1. Aug 1, 2024
    In force

    The EU AI Act enters into force.

  2. Feb 2, 2025
    Bans apply

    Prohibited AI practices become illegal across the EU.

  3. Aug 2, 2025
    GPAI rules and penalties

    Obligations for general-purpose AI models begin, and the penalties chapter becomes applicable, all of it except the fines for general-purpose model providers, which wait for Aug 2, 2026.

  4. Aug 2, 2026
    General applicationyou are here →

    The regulation applies in general, transparency and governance included, together with the Commission powers over general-purpose models.

  5. Dec 2, 2026
    Marking, and two new bans

    The extra time the Omnibus gave the machine-readable marking of AI-generated content, for systems placed on the market before Aug 2, 2026. The other transparency obligations keep their date. The same regulation adds two prohibited practices from this date: AI systems that generate non-consensual intimate imagery, and those that generate child sexual abuse material.

  6. Aug 2, 2026 Dec 2, 2027
    Use-based high-risk

    Obligations for the Annex III high-risk uses, hiring and credit and education among them. Postponed by Regulation (EU) 2026/1744, in force since July 2026.

  7. Aug 2, 2027 Aug 2, 2028
    Embedded high-risk

    Rules for AI that is a safety component of a product regulated by the Annex I legislation. Postponed by the same regulation.

// risk tiers

Four levels of risk.

Your obligations depend entirely on which tier your use of AI falls into. Most enterprise tooling lands in the middle two.

Unacceptable

Banned

Social scoring, manipulative or exploitative systems. Prohibited outright since February 2025. The Omnibus adds two more from December 2026: generating non-consensual intimate imagery, and generating child sexual abuse material.

High-risk

Strict obligations

Two routes in: your purpose fits a case in Annex III (hiring, credit, education, essential services), or your system is a safety component of a product already regulated by the Annex I legislation (medical devices, machinery, toys). Risk management, data governance, logging, human oversight and documentation.

Limited risk

Transparency

Chatbots and generative systems. Users must be told they are interacting with AI, and AI-generated content must be labelled.

Minimal risk

No obligations

Spam filters, recommendation, most internal tooling. Free to use, with voluntary codes of conduct.

// penalties

The cost of getting it wrong.

Fines are tiered by severity and calculated on global turnover, whichever figure is higher. They are built to register at board level.

€35M / 7% Prohibited AI practices
€15M / 3% Breach of high-risk, transparency or GPAI obligations
€7.5M / 1% Supplying incorrect information to authorities

Figures are the higher of the fixed amount or the percentage of global annual turnover.

// your obligations

What you'll need to show.

For most teams running AI in production, compliance comes down to a handful of things you must be able to demonstrate.

Know where data is processed

Be able to show inference runs in the EU, not on a hyperscaler subject to the US Cloud Act.

No silent training on your data

Your prompts and outputs must not feed a third-party training set without basis.

Records & traceability

Keep an auditable trail of what system processed what, and where it ran.

Transparency to users

Disclose AI interactions and label AI-generated content.

Human oversight

Keep a person in the loop for decisions that carry real-world risk.

Data governance

Control the lawful basis, quality and residency of the data you feed in.

// open models

If the model is open, who carries what.

General-purpose obligations fall on whoever built the model. Worth reading before anyone tells you open weights are the risky option.

The model developer

Technical documentation, a copyright policy and a public summary of training content, under Articles 51 to 56. With GPT that package belongs to OpenAI. With Qwen or GLM it belongs to Alibaba or Z.ai.

Whoever serves it, us included

None of the model package. The Commission defines the provider as whoever develops the model and places it on the market under their own name. Its own example: if one actor uploads a model to a repository hosted by another, the developer is still the provider.

You, for the system you build

The system obligations your use brings with it: transparency, human oversight, and the high-risk regime if your use is on that list. Serving an open model unmodified, or calling it through an API, does not move any model obligation onto you.

You, if you fine-tune heavily

You become the provider of the modified model only on a significant change in its generality, capabilities or systemic risk. The Commission’s indicative criterion: more than one third of the original training compute. A LoRA sits orders of magnitude below, and if you did cross it the obligations reach your modification, not the whole model.

Nobody can tell you this one

Whether a given model meets the conditions of the free and open-source exemption, or carries systemic risk, is its developer’s determination to make and to notify. Which is why you will not find us claiming it for the catalogue.

What open weights change for you is what you can prove: you pin the exact version you run, you audit it, and you document your whole stack. None of that is available through a closed API that changes without telling you.

The Commission’s guidelines are not binding on providers, and only the Court of Justice of the EU can give an authoritative interpretation of the AI Act. The Commission does state that the guidelines set out the interpretation on which it will base its enforcement action. Sources: Regulation (EU) 2024/1689, Articles 51 to 56; Commission Guidelines on the scope of the obligations for providers of general-purpose AI models, published 18 July 2025, in the version of Communication C(2025) 7719 final of 19 November 2025. The application dates on this page are Article 113; the high-risk classification routes are Article 6 with Annexes I and III; the postponements are Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026.

// compliant by design

Where Helmcode removes the work.

We can't classify your systems for you, but the hardest, most structural requirements are solved the moment your inference runs on Helmcode.

EU data residency

Inference processed exclusively on EU infrastructure, never a US hyperscaler.

No training on your data

Zero logs: prompts and completions are never stored and never train a model.

Traceability

A single, auditable stack with documented data flows and a sub-processor list.

Sovereignty

EU-owned and operated, outside the reach of the US Cloud Act.

See the full compliance posture

// ai act faq

The AI Act, answered.

The questions European teams ask as the deadline approaches.

Does the AI Act apply to my company if we just use AI?

Very likely. The Act covers providers and deployers of AI systems placed on the EU market or used within the EU, including companies that only integrate third-party models. Obligations scale with the risk level of how you use AI.

What actually changes on August 2, 2026?

The regulation applies in general, transparency duties and governance included, together with the Commission powers over general-purpose models. Prohibited practices, GPAI rules and the penalties chapter already apply from earlier dates. The Omnibus reform moved the obligations for high-risk systems (Annex III to December 2027 and Annex I to August 2028) and also one piece of transparency: the machine-readable marking of AI-generated content gets extra time, until 2 December 2026, for systems placed on the market before 2 August 2026. The other transparency obligations, the literacy duty and the prohibitions keep their dates.

How bad are the penalties, and when can they actually reach us?

Up to €35M or 7% of global annual turnover for prohibited practices, and €15M or 3% for breaching other obligations, whichever is higher. On timing it is worth separating two things. On paper, the penalties chapter of the regulation has been applicable since 2 August 2025, and 2 August 2026 brings the general application of the regulation together with the Commission powers over general-purpose models. In practice, most Member States have still not designated authorities or passed the domestic rules that make it possible to open a case: Italy was among the first to do so, and Spain has it in parliamentary procedure, among the most advanced countries. That gap has two readings and both are true: today it is unlikely you get fined, and today’s breaches will be tomorrow’s case files, because the obligations are already enforceable. And remember that a fine is rarely the first cost: the large client’s contract and the due diligence arrive before any authority does.

How does Helmcode help us comply?

By removing the hardest parts structurally: EU-only processing, zero logs, no training on your data and an auditable stack. You are aligned by architecture rather than by configuration. See Security & Compliance for the full posture.

Is this page legal advice?

No. It is an informational overview to help you scope the work. For your specific obligations and classification, consult qualified legal counsel.

This guide is an informational overview, not legal advice. For your specific obligations and risk classification, consult qualified legal counsel. Sources: Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026.

// get started

START BURNING TOKENS

Skip the AI infra work. Deploy your first private inference endpoint today.

Flat rate. EU data. OpenAI API compatible.