RHETRA / Guides / EU AI Act

FULL GUIDE · UPDATED 2026-07-21

EU AI Act compliance, practically

The EU AI Act requires organisations running high-risk AI to operate a risk-management system, data governance, automatic logging, transparency, human oversight and cybersecurity — continuously, with evidence (Art. 9–15). Fines for high-risk non-compliance reach €15M or 3% of global turnover. The practical question is not "which documents do we need?" but "can we produce verifiable evidence of what our AI actually did?" This guide covers the timeline, the obligations, and the evidence-first way to meet them.

ON THIS PAGE
1 · The timeline that matters 2 · What high-risk actually obliges you to do 3 · The real fine tiers 4 · Documents vs evidence — the compliance trap 5 · The author → enforce → prove → export loop

1 · The timeline that matters

If your organisation is a bank, insurer, hospital operator or public authority using AI in decisions about people, the August 2026 date is the one on your desk. Building the logging and oversight infrastructure takes quarters, not weeks — which is why supervisors expect to see it running, not planned.

2 · What high-risk actually obliges you to do

Seven operational duties, all continuous:

3 · The real fine tiers

Art. 99 defines three tiers — often misquoted, so precisely:

4 · Documents vs evidence — the compliance trap

The default corporate response to regulation is documents: policies, registers, PDFs. The AI Act's high-risk duties are largely operational — they concern what the system does at runtime. A policy PDF cannot show that a specific AI call on a specific date was checked, redacted, allowed or blocked. Editable logs cannot prove they weren't cleaned up afterwards.

Evidence has two properties documents lack: it is generated by the enforcing system itself, and it is tamper-evident. That is achievable today: an enforcement gateway in front of every AI call, plus cryptographic signatures over every decision. Post-quantum signatures (e.g. Dilithium5 / ML-DSA, NIST-standardised) keep that evidence durable even against future quantum attacks — relevant, because audit trails must stay verifiable for years.

5 · The loop: author → enforce → prove → export

This is the architecture RHETRA ships: the KRONOS gateway and the Governance Platform implement the loop end to end — on-premise or SaaS. The wider context — why verifiability is the core of sovereignty — is in our pillar guide: What is Sovereign AI?

This guide is general information on the Regulation (EU) 2024/1689, not legal advice.

COMPLIANCE AS RUNNING PROOF

See the loop enforce — live.

45 minutes on a running system: policy in, enforcement inline, signed evidence out.