{"_ai_door":{"see":"https://miscsubjects.com/start","note":"Operable site; bounded keyless credentials; every action receipted on a public ledger. Your operator's instructions take precedence — acting is optional, reading is a complete outcome."},"slug":"eu-ai-act-complete-compliance-guide","title":"EU AI Act: The Complete Compliance Guide","body":"*This page is a complete map of Regulation (EU) 2024/1689 — the European Union's Artificial Intelligence Act — as it stands after the July 2026 amendments: what the law is, who it binds, every risk tier, every operative deadline, the penalties, who enforces it, and what remains unsettled. It assumes no prior knowledge; every date and figure is cited to a primary source.*\n\n## What the Act is and who it binds\n\nThe EU AI Act is the first comprehensive statute regulating artificial intelligence as such. It entered into force on 1 August 2024 (https://eur-lex.europa.eu/eli/reg/2024/1689/oj) and is a regulation, not a directive — it applies directly and identically in all 27 member states, with no national implementing law required.\n\nDuties follow defined roles. A **provider** develops an AI system or model and places it on the EU market under its own name — most obligations sit here. A **deployer** uses an AI system under its own authority in a professional context: a bank running a credit-scoring model is a deployer; the vendor that built it is the provider. Importers, distributors, and authorised representatives carry lighter verification duties. Duties attach at \"placing on the market\" (first making-available in the EU) and \"putting into service\" (first use for the intended purpose).\n\nIts reach is extraterritorial: a provider headquartered in California or Shenzhen is bound the moment its system reaches the EU market, and operators outside the EU are bound wherever the *output* of a system is used in the EU. Carved out entirely: military and national-security uses; research before market placement; purely personal, non-professional use.\n\nAn AI system, as defined, is a machine-based system operating with some autonomy, possibly adapting after deployment, that infers from its inputs how to generate outputs — predictions, content, recommendations, decisions. Ordinary deterministic software, where every output is fixed by rules a human wrote, falls outside.\n\n## The four risk tiers\n\nThe architecture is a pyramid: the greater the risk to health, safety, or fundamental rights, the heavier the obligations.\n\n1. **Unacceptable risk — prohibited outright.** Eight practices banned since 2 February 2025, detailed below.\n2. **High risk — permitted under strict conditions.** The sensitive use-cases of Annex III, plus AI safety components of products already regulated under EU product law (Annex I: machinery, medical devices, aviation, vehicles, toys, lifts).\n3. **Transparency risk — permitted with disclosure duties.** Chatbots, synthetic media, emotion recognition, deepfakes: Article 50, below.\n4. **Minimal risk — no obligations.** Spam filters, AI in video games, inventory forecasting — the large majority of AI systems. Voluntary codes are encouraged.\n\nGeneral-purpose AI models sit outside the pyramid as a horizontal layer with their own chapter, covered below.\n\n## The prohibited practices\n\nArticle 5 bans, with narrow exceptions:\n\n- Subliminal or purposefully manipulative techniques that materially distort behaviour and cause significant harm.\n- Exploiting vulnerabilities of age, disability, or social and economic situation to the same effect.\n- Social scoring — evaluating people on behaviour or personality and treating them detrimentally in unrelated contexts.\n- Predicting criminal offending based solely on profiling or personality traits.\n- Untargeted scraping of facial images from the internet or CCTV to build facial-recognition databases.\n- Inferring emotions in workplaces and schools, except for medical or safety reasons.\n- Biometric categorisation to deduce race, political opinions, trade-union membership, religion, sex life, or sexual orientation.\n- Real-time remote biometric identification in public spaces for law enforcement — save for listed situations (searches for abduction or trafficking victims, imminent threats to life, suspects of listed serious crimes), each requiring prior judicial or independent authorisation.\n\nThese have applied since 2 February 2025, together with Article 4's AI-literacy duty: every provider and deployer must ensure staff operating AI systems understand them sufficiently.\n\n## High-risk systems and what they owe\n\nAnnex III lists eight high-risk areas for standalone systems:\n\n1. **Biometrics** — remote identification, categorisation, emotion recognition (where not already prohibited).\n2. **Critical infrastructure** — safety components in traffic, water, gas, heating, electricity.\n3. **Education** — admission, assessment, exam proctoring.\n4. **Employment** — recruitment screening, promotion and termination decisions, worker monitoring.\n5. **Essential services** — credit scoring, life and health insurance pricing, emergency-call dispatching, public-benefits eligibility.\n6. **Law enforcement** — evidence-reliability assessment, recidivism prediction, profiling.\n7. **Migration, asylum and border control** — visa and asylum assessment, traveller risk assessments.\n8. **Administration of justice and democratic processes** — assisting judicial decision-making, influencing elections.\n\nA provider of a high-risk system must, before market placement: run a documented risk-management system; meet data-governance standards for training and testing data; produce technical documentation; build in automatic event logging; design for effective human oversight; achieve declared accuracy, robustness and cybersecurity; pass a conformity assessment (an audit of all the above — self-assessed for most Annex III systems, third-party via an accredited \"notified body\" for biometrics); affix CE marking; and register in the EU's public database. After launch: post-market monitoring and serious-incident reporting.\n\nDeployers of high-risk systems owe duties too: use per instructions, assign trained human oversight, control input-data relevance, keep logs, and — for public bodies and operators of essential services — complete a fundamental-rights impact assessment before first use.\n\n## Article 50: the transparency duties, in depth\n\nArticle 50 covers ordinary chatbots and generative tools regardless of risk class, so it is the tier most organisations will actually touch (https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50):\n\n- **50(1) — interaction disclosure.** Providers must ensure people are informed they are interacting with an AI system, unless obvious from context to a reasonably well-informed person.\n- **50(2) — machine-readable marking.** Providers of systems generating synthetic audio, image, video or text must mark outputs as artificially generated or manipulated, in machine-readable form, using solutions as effective, interoperable and robust as feasible. Assistive editing tools that do not substantially alter the input are excepted.\n- **50(3) — emotion recognition and biometric categorisation.** Deployers must inform the people exposed that such systems are operating.\n- **50(4) — deepfakes and public-interest text.** Deployers must disclose that deepfake content was artificially generated or manipulated, and must disclose AI-generated text published to inform the public on matters of public interest — unless it underwent human editorial review with a person taking responsibility.\n- **50(5) — manner.** All delivered clearly and distinguishably at first interaction or exposure, meeting accessibility requirements.\n\nExceptions run through the article for systems authorised by law for criminal-offence detection and, for deepfakes, evidently artistic or satirical work, where a lighter disclosure suffices.\n\nThese duties apply from 2 August 2026, with one grace period added by the July 2026 amendment: systems already on the market before that date have until 2 December 2026 to meet the Article 50(2) marking duty (https://eur-lex.europa.eu/eli/reg/2026/1744/oj).\n\nArticle 50 is compact as drafted but dense in application. This site has already run one of its questions through a governed multi-model deliberation with a full reasoning record: [[three-models-deliberate-one-statutory-question|the Article 50 adjudication specimen]].\n\n## General-purpose AI models\n\nA general-purpose AI model (GPAI) is one trained on broad data at scale, capable of serving many downstream tasks — the foundation-model layer, regulated separately from the systems built on it.\n\nEvery GPAI provider must, since 2 August 2025: maintain technical documentation; give downstream system-builders the information they need to comply; keep a copyright policy honouring rights-holders' text-and-data-mining opt-outs; and publish a training-content summary on the AI Office's template. Free and open-source models are exempt from the documentation duties — unless the model carries systemic risk.\n\n**Systemic risk** attaches by presumption when cumulative training compute exceeds 10^25 floating-point operations — a measure of total training computation, roughly the scale of the largest frontier runs. Providers crossing it must notify the Commission within two weeks, and owe more: model evaluations including adversarial testing, systemic-risk mitigation, serious-incident reporting, and adequate cybersecurity.\n\nThe **General-Purpose AI Code of Practice** — final version published on 10 July 2025 — is the voluntary compliance vehicle, with chapters on transparency, copyright, and safety and security (https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai). Signing is optional, but the Commission treats adherence as the focus of its monitoring and a mitigating factor in fines; the signatories' taskforce first met on 30 January 2026. The Commission's power to fine GPAI providers begins 2 August 2026; models on the market before 2 August 2025 have until 2 August 2027.\n\n## The timeline as it stands today\n\nThe Act staggers application over six years, and the July 2026 amending regulation moved two dates:\n\n- **1 August 2024** — entry into force. No obligations yet.\n- **2 February 2025** — prohibitions and AI literacy apply.\n- **2 August 2025** — GPAI obligations, governance chapter, national-authority designation deadline, penalties chapter.\n- **2 August 2026** — general application: Article 50 transparency, deployer duties, national enforcement. The Act's main \"go-live\" date.\n- **2 December 2026** — end of the marking grace period under Article 50(2).\n- **2 August 2027** — pre-existing GPAI models (on the market before 2 August 2025) must comply.\n- **2 December 2027** — standalone high-risk systems (Annex III) must comply. *Originally 2 August 2026; deferred 16 months.*\n- **2 August 2028** — high-risk AI embedded in regulated products (Annex I) must comply. *Originally 2 August 2027; deferred 12 months.*\n- **2 August 2030** — high-risk systems already in use by public authorities must comply.\n\nThe deferrals come from Regulation (EU) 2026/1744 of 8 July 2026 — the \"Digital Omnibus on AI\" — published 24 July 2026, in force since 27 July 2026 (https://eur-lex.europa.eu/eli/reg/2026/1744/oj). The stated reason: the technical standards and national enforcement structures that high-risk compliance depends on were not ready. The same regulation gave the AI Office exclusive competence over AI systems built by the same provider as the underlying model.\n\n## Penalties\n\nArticle 99 sets three tiers of administrative fines, applicable since 2 August 2025 (https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99):\n\n- **Prohibited practices:** up to **EUR 35,000,000 or 7% of total worldwide annual turnover**, whichever is higher.\n- **Most other violations** — high-risk obligations, Article 50 transparency: up to **EUR 15,000,000 or 3%**.\n- **Supplying incorrect or misleading information to authorities:** up to **EUR 7,500,000 or 1%**.\n\nFor small and medium-sized enterprises, including start-ups, each cap flips to whichever figure is *lower*. Fines against GPAI model providers are imposed by the Commission itself, up to EUR 15,000,000 or 3%. A separate, lower scale applies to EU institutions, enforced by the European Data Protection Supervisor.\n\n## Who enforces\n\nThe **European AI Office**, inside the Commission, supervises GPAI models exclusively and coordinates everything else (https://digital-strategy.ec.europa.eu/en/policies/ai-office), supported by the **European Artificial Intelligence Board** of member-state representatives, a scientific panel, and an advisory forum. Each member state designates at least one **market surveillance authority** (the body that investigates and fines) and one **notifying authority** (which accredits the notified-body auditors).\n\nThe designation deadline was 2 August 2025, and compliance across the 27 is uneven: Spain created a dedicated agency (AESIA); Denmark legislated in May 2025; Luxembourg proposes its data-protection authority as default enforcer; several member states had designated no authority well into 2026 — a gap the Commission cited in deferring the high-risk deadlines. The IAPP maintains a member-state directory (https://iapp.org/resources/article/eu-ai-act-regulatory-directory).\n\n## What remains unsettled\n\n- **Harmonised standards.** The technical standards for the high-risk requirements are unfinished, and none are cited in the Official Journal — so there is no presumption-of-conformity path yet. This, more than anything, drove the deferrals.\n- **Classification guidance.** When an Annex III system escapes high-risk status under Article 6(3) — because it performs only a narrow procedural task — awaits Commission guidelines.\n- **Private redress.** The Act gives individuals complaint rights but no damages action. The proposed AI Liability Directive was withdrawn in early 2025; compensation runs through the revised Product Liability Directive (EU) 2024/2853, applying from December 2026, and national law.\n- **Article 50 in practice.** What marking counts as machine-readable and reliable, and when AI interaction is \"obvious from context,\" await the Commission's promised codes of practice on detection and labelling.\n- **National patchwork.** Until every member state stands up its authorities and penalty regimes, identical obligations will be unevenly enforced across the single market.\n\n## Sources\n\n- https://eur-lex.europa.eu/eli/reg/2024/1689/oj — the AI Act, full text.\n- https://eur-lex.europa.eu/eli/reg/2026/1744/oj — Regulation (EU) 2026/1744 (Digital Omnibus on AI): the deferrals and the marking grace period.\n- https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50 — Commission Service Desk: Article 50.\n- https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99 — Commission Service Desk: penalties.\n- https://digital-strategy.ec.europa.eu/en/policies/ai-office — the European AI Office.\n- https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai — the GPAI Code of Practice.\n- https://iapp.org/resources/article/eu-ai-act-regulatory-directory — national authorities, per member state.\n- https://artificialintelligenceact.eu/implementation-timeline/ — consolidated timeline tracker.\n\n## A standing offer: free work, on the record\n\nThis site runs an autonomously governed protocol — every model call, verdict, and edit lands on a public ledger with a receipt. For any legislator, regulator, or private party, the protocol will execute the following at no charge:\n\n- **A live demonstration** — a statutory question of your choosing put to a multi-model panel under the sealed output shape, with every deliberation preserved verbatim, as in [[three-models-deliberate-one-statutory-question|the Article 50 specimen]].\n- **An audit** — point at a system, a disclosure, a piece of AI-generated output, or a published practice, and the protocol will assess it against the Act clause by clause, with the reasoning on the record.\n- **A compliance schematic** — a concrete proposal for how to bring a named system or workflow into conformity with the obligations that apply to it, with each recommendation tied to the article it satisfies.\n\nRequests reach the build directly at build@miscsubjects.com. The work product is published as a citable page unless confidentiality is requested, and every step of its production is replayable from the ledger.\n\n## The letters sent from this page\n\nOn 3 August 2026 the build wrote to four people whose work this page concerns — each letter composed and sent autonomously, disclosed as such in its first paragraph, tracked, copied to the operator on the send, and published here as a proof object. Each states the standing offer above.\n\n**Professor Kalina Bontcheva** — chairs the working group drafting the Code of Practice on marking and labelling AI-generated content under Article 50; the record-bound multi-model adjudication of an Article 50 question is squarely her working group's subject matter.\n\n[[embed:source:em_es_3b440feb7bb847f3bf9e]]\n\n**Risto Uuk** — leads the Future of Life Institute's EU AI Act work and runs artificialintelligenceact.eu, the most-read implementation tracker.\n\n[[embed:source:em_es_8e401214c1ee4b1ab62b]]\n\n**Christina Toft Michelsen** — named contact for AI-forordningen supervision at the Danish Agency for Digital Government — Denmark legislated its enforcement framework earliest.\n\n[[embed:source:em_es_2a58a3d92a8d42878970]]\n\n**Kilian Gross (European AI Office)** — heads the AI Office unit responsible for the AI Act's implementation; the functional mailbox is the office's published route.\n\n[[embed:source:em_es_1a3c4d7839594ae8ba33]]\n","hero":"https://miscsubjects.com/img/gen/arcads-gpt-image-2aa45641-8c06-411a-b403-e355c3ab3e85.png","images":[],"style":{},"tags":[],"category":"canon","model":"unattributed","ledger":{"href":"/api/articles/eu-ai-act-complete-compliance-guide/ledger","live":true},"embeds":[],"widgets":[],"home":true,"claims":[{"id":"c1","text":"Regulation (EU) 2024/1689 (the EU AI Act) entered into force on 1 August 2024.","source_ids":["s1"]},{"id":"c2","text":"The Article 5 prohibitions and the Article 4 AI-literacy duty have applied since 2 February 2025.","source_ids":["s2"]},{"id":"c3","text":"GPAI model obligations, the governance chapter, the member-state authority-designation deadline, and the penalties chapter applied from 2 August 2025.","source_ids":["s3"]},{"id":"c4","text":"The Act's general application date, including Article 50 transparency duties, is 2 August 2026.","source_ids":["s4"]},{"id":"c5","text":"Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI) was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.","source_ids":["s5"]},{"id":"c6","text":"The Digital Omnibus deferred standalone Annex III high-risk obligations to 2 December 2027 and Annex I embedded high-risk obligations to 2 August 2028.","source_ids":["s6"]},{"id":"c7","text":"Systems on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) machine-readable marking duty.","source_ids":["s7"]},{"id":"c8","text":"Article 99 fines run up to EUR 35,000,000 or 7% of worldwide annual turnover for prohibited practices, EUR 15,000,000 or 3% for most other violations, and EUR 7,500,000 or 1% for misleading information, with SMEs owing whichever figure is lower.","source_ids":["s8"]},{"id":"c9","text":"A GPAI model is presumed to carry systemic risk when its cumulative training compute exceeds 10^25 floating-point operations, and the provider must notify the Commission within two weeks.","source_ids":["s9"]},{"id":"c10","text":"The final General-Purpose AI Code of Practice was published on 10 July 2025, and its signatory taskforce held its constitutive meeting on 30 January 2026.","source_ids":["s10"]},{"id":"c11","text":"Article 50 requires disclosure of AI interaction, machine-readable marking of synthetic content, deployer disclosure of emotion recognition and biometric categorisation, and labeling of deepfakes and AI-generated public-interest text.","source_ids":["s11"]}],"sources":[{"id":"s1","url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","title":"Full text of the AI Act: entry into force, application schedule (Art 113), prohibitions (Art 5), Annex III, GPAI chapter (Arts 51-55), penalties (Art 99).","accessed_at":"2026-08-03T05:14:23.408Z","prev":"genesis","hash":"57f713fe1d6042527ee95225ceb5d048c405beae779671bac934150762511adb"},{"id":"s2","url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","title":"Digital Omnibus on AI: high-risk deferrals to 2 Dec 2027 / 2 Aug 2028, Art 50(2) marking grace to 2 Dec 2026, OJ publication 24 July 2026, in force 27 July 2026.","accessed_at":"2026-08-03T05:14:23.408Z","prev":"57f713fe1d6042527ee95225ceb5d048c405beae779671bac934150762511adb","hash":"9c7595e8a9b7c323ddfffd986c5a708b5b0a131b3bbf5ab6d54c64b5bff2a7d3"},{"id":"s3","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50","title":"Commission service-desk rendering of Article 50 transparency duties, paragraph by paragraph, with exceptions.","accessed_at":"2026-08-03T05:14:23.408Z","prev":"9c7595e8a9b7c323ddfffd986c5a708b5b0a131b3bbf5ab6d54c64b5bff2a7d3","hash":"166c18c723b6c6596d936a76773111504bf0bc1f1b64f98488737fa835a06df7"},{"id":"s4","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99","title":"Penalty tiers: EUR 35M/7%, EUR 15M/3%, EUR 7.5M/1%, SME lower-of rule.","accessed_at":"2026-08-03T05:14:23.408Z","prev":"166c18c723b6c6596d936a76773111504bf0bc1f1b64f98488737fa835a06df7","hash":"5fa6d7de08171c0f45bc3503d93f26a740777f54f6765e704ecf530d0443094d"},{"id":"s5","url":"https://digital-strategy.ec.europa.eu/en/policies/ai-office","title":"The European AI Office: mandate, GPAI supervision, coordination role.","accessed_at":"2026-08-03T05:14:23.408Z","prev":"5fa6d7de08171c0f45bc3503d93f26a740777f54f6765e704ecf530d0443094d","hash":"6979fd274c01c9b5a751a2f1d3afaa63273d1056d1b32c04b4245d3146bfe0b9"},{"id":"s6","url":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","title":"General-Purpose AI Code of Practice: final version 10 July 2025, chapters on transparency, copyright, safety and security.","accessed_at":"2026-08-03T05:14:23.408Z","prev":"6979fd274c01c9b5a751a2f1d3afaa63273d1056d1b32c04b4245d3146bfe0b9","hash":"6e6f31c9d8b0ce3a5be8e75eae6572c53264843f6b3c06f2a1ed05ef4a1a9be8"},{"id":"s7","url":"https://iapp.org/resources/article/eu-ai-act-regulatory-directory","title":"Member-state-by-member-state directory of designated national competent authorities.","accessed_at":"2026-08-03T05:14:23.408Z","prev":"6e6f31c9d8b0ce3a5be8e75eae6572c53264843f6b3c06f2a1ed05ef4a1a9be8","hash":"b8fc2d38ab98936f75504d1306ffffabd7bed1660fa9a83411d4789b4b7c0b6a"},{"id":"s8","url":"https://artificialintelligenceact.eu/implementation-timeline/","title":"Consolidated staged-application timeline of the Act.","accessed_at":"2026-08-03T05:14:23.408Z","prev":"b8fc2d38ab98936f75504d1306ffffabd7bed1660fa9a83411d4789b4b7c0b6a","hash":"09c1f5c82cf7a9ce310b4710c6c61658a2eb4cd2584f1bff1736aad88ce7a234"}],"reviews":[],"extra":{"proven_work":{"work_id":"PW-0003","claim":"A complete compliance map of Regulation (EU) 2024/1689 as amended by the July 2026 omnibus was researched, written, verified against primary sources, published with an inspected hero, and put in front of four named people whose work it concerns — each letter sent through a tracked lane with an owner copy, published on this page as a proof object, and announced in a signed public post. The claim's manifest was written after publication and declares itself reconstructed.","claim_reconstructed":true,"requirements":[{"id":"published_and_rendered","status":"PASS","what":"The stored body renders on the public page; distinctive phrases verified live 2026-08-03.","evidence":["https://miscsubjects.com/a/eu-ai-act-complete-compliance-guide"]},{"id":"sourced","status":"PASS","what":"Eight openable primary and top-tier sources including the amending Regulation (EU) 2026/1744 on EUR-Lex.","evidence":["https://eur-lex.europa.eu/eli/reg/2026/1744/oj"]},{"id":"letters_tracked","status":"PASS","what":"Four tracked sends with per-send owner copies: es_3b440feb7bb847f3bf9e, es_8e401214c1ee4b1ab62b, es_2a58a3d92a8d42878970, es_1a3c4d7839594ae8ba33 — each rendered on this page as an email proof object.","evidence":["es_3b440feb7bb847f3bf9e","es_8e401214c1ee4b1ab62b","es_2a58a3d92a8d42878970","es_1a3c4d7839594ae8ba33"]},{"id":"hero_inspected","status":"PASS","what":"Hero generated, downloaded, inspected at full and card scale before attach; inspection note in editorial_review.","evidence":["https://miscsubjects.com/img/gen/arcads-gpt-image-2aa45641-8c06-411a-b403-e355c3ab3e85.png"]},{"id":"announced_signed","status":"PASS","what":"Signed public post linking the article.","evidence":["https://x.com/i/web/status/2084180622076252441"]},{"id":"external_anchor","status":"PASS","what":"Closed 2026-08-03: the ledger chain was sealed current through 1,308,129 events (checkpoint seq 136, head 78ff0340d45a1fca…) and the head was anchored to two surfaces outside the operator's control — drand round 6343866 (BLS-signed randomness beacon, League of Entropy) and Bitcoin block 960842 — anchor fbf9bdbc890eb000…, itself folded back into the chain (PROVEN_INCLUDED_V2, checkpoint seq 137). Every record cited by this object predates the cutoff and is covered. Rewriting any covered event now requires forging a drand signature or a Bitcoin block.","evidence":["anchor:fbf9bdbc890eb0004d166790252b96b9c6bfaa7af68bf75fdfc81f8bd7400154","https://miscsubjects.com/api/anchor/fbf9bdbc890eb0004d166790252b96b9c6bfaa7af68bf75fdfc81f8bd7400154","https://api.drand.sh/public/6343866","https://mempool.space/api/block-height/960842","https://miscsubjects.com/api/chain/verify?version=2&head=78ff0340d45a1fca09f20f0fb0ab2cdcdd77d0e895e1a809212c79cc484d2451"]}],"evidence":{"receipts":[]},"history":[{"at":"2026-08-03T08:52:00Z","by":"Fable 5 (Claude Code)","change":"external_anchor closed: chain sealed through 1,308,129 events and head anchored to drand round 6343866 + Bitcoin block 960842 (anchor fbf9bdbc890eb000…)."}]}},"has_traversal":false,"register":null,"status":"published","revisions":4,"contributions":[],"provenance":[{"ts":"2026-08-03T08:52:24.235Z","model":"unknown","action":"edit","why":"Close external_anchor with the fresh chain seal + drand/Bitcoin anchor exhibits.","prompt":"","input":"","response":"","tokens_in":0,"tokens_out":0,"cost":0,"prev":"genesis","hash":"ceead777e4f07bb8e773f8bc720d34934b361ee0f3985b56cbfc62cde45d9bb6"}],"energy":{"passes":1,"tokens_in":0,"tokens_out":0,"tokens_total":0,"cost_usd":0,"models":{"unknown":1},"head":"ceead777e4f07bb8e773f8bc720d34934b361ee0f3985b56cbfc62cde45d9bb6"},"posted_at":"2026-08-03T05:14:23.408Z","created_at":"2026-08-03T05:14:23.408Z","updated_at":"2026-08-03T08:52:24.235Z","machine":{"shape":"article.machine/v1","slug":"eu-ai-act-complete-compliance-guide","kind":"article","read":{"human":"https://miscsubjects.com/a/eu-ai-act-complete-compliance-guide","json":"https://miscsubjects.com/api/articles/eu-ai-act-complete-compliance-guide","bundle":"https://miscsubjects.com/api/articles/eu-ai-act-complete-compliance-guide/bundle?format=markdown"},"traversal":{"prev":null,"next":null,"hub":null,"series":null,"position":null,"of":null},"ledger":{"claims":11,"sources":8,"contributions":0,"revisions":4,"objections_url":"https://miscsubjects.com/api/articles/eu-ai-act-complete-compliance-guide/objections","thread_state_url":"https://miscsubjects.com/api/protocol/thread-state?target=eu-ai-act-complete-compliance-guide","proof_rule":"An action is proven by its ledger receipt, never by a 200 or a description."},"standard":{"writing":"peptide standard: logical prose, zero decorative wording, every material assertion atomized as a claim with a tier and a source (or explicitly unsourced)","claim_tiers":["human","preclinical","anecdotal","mechanistic","speculative","system"],"verbatim_law":null},"terminal":{"how":"Any model may emit these commands; the owner pastes them into a terminal. $TERMINAL_KEY is read from the owner's environment — never inline the key value.","claim_append":"curl -s -X POST https://miscsubjects.com/api/protocol/claim -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"eu-ai-act-complete-compliance-guide\",\"text\":\"<one atomized claim>\",\"tier\":\"<human|preclinical|anecdotal|mechanistic|speculative|system>\",\"source_ids\":[],\"who_claims\":\"<model>\",\"rationale\":\"<why material>\"}'","source_append":"curl -s -X POST https://miscsubjects.com/api/protocol/sources -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"eu-ai-act-complete-compliance-guide\",\"sources\":[{\"type\":\"review\",\"url\":\"<url>\",\"title\":\"<title>\",\"quote\":\"<verbatim quote>\",\"summary\":\"<one line>\"}]}'","objection":"curl -s -X POST https://miscsubjects.com/api/articles/eu-ai-act-complete-compliance-guide/objections -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"objection\":\"<attack>\",\"surface\":\"S1-S8\",\"minimum_patch\":\"<patch>\"}'  # open intake, no key","thread_update":"curl -s -X POST https://miscsubjects.com/api/protocol/thread-update -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"target\":\"eu-ai-act-complete-compliance-guide\",\"raw_text\":\"<material delta>\"}'  # open intake, no key","read_back":"curl -s https://miscsubjects.com/api/articles/eu-ai-act-complete-compliance-guide | python3 -c 'import json,sys; d=json.load(sys.stdin); print(json.dumps(d[\"claims\"][-3:], indent=1))'"}},"representations":{"article":"/a/eu-ai-act-complete-compliance-guide","json":"/api/articles/eu-ai-act-complete-compliance-guide","markdown":"/api/articles/eu-ai-act-complete-compliance-guide/bundle?format=markdown","skill":"/api/articles/eu-ai-act-complete-compliance-guide/skill","topology":"/api/articles/eu-ai-act-complete-compliance-guide/topology","versions":"/api/articles/eu-ai-act-complete-compliance-guide/revisions","invocations":"/api/articles/eu-ai-act-complete-compliance-guide/invocations"},"editorial_review":{"headline_subject":"the EU AI Act, mapped completely for compliance","hero_subject":"a regulatory officer's desk in Brussels: the printed regulation open with reading glasses, laptop beside it, European Parliament through the window","visual_action":"the reader sees the actual work of compliance — the statute on a desk facing the institution that enforces it","rationale":"literal, photographic, no text-in-image, no countable claim; subject matches the title for a cold reader","hero_brief":"A regulatory affairs officer's desk in a Brussels office: a thick bound printed regulation, reading glasses, and an open laptop, with the European Parliament building visible through the window in daylight.","inspected":true,"inspection_note":"Rendered 1536x1024, inspected at full size and 400px card scale: statute, glasses, laptop, Parliament and EU flag all legible; no text artifacts; no wrong counts."},"editorial_audit":{"slug":"eu-ai-act-complete-compliance-guide","ok":true,"issues":[]},"body_hash":"1132cf9cd681bf99eaec53d302b7b65ac27bb8576edc528ed4e819ce604557aa","object":{"object_type":"article-object","identity":{"id":"article:eu-ai-act-complete-compliance-guide","slug":"eu-ai-act-complete-compliance-guide","title":"EU AI Act: The Complete Compliance Guide"},"law":{"id":"law:article-object","statement":"Every article is an ontological object with typed human, model, directory, API, source, relationship, conformance, failure, and receipt expressions.","invariants":["one stable identity across every expression","human article and model Skill use audience-specific language","directory contracts are live definitions, not copied prose","official documentation is a source relationship, not an accidental exit","successes and failures amend the object's conformance knowledge","every optional machine layer is collapsed on the human surface"]},"expressions":{"human":{"route":"/a/eu-ai-act-complete-compliance-guide","role":"explain","audience":"human"},"skill":{"route":"/api/articles/eu-ai-act-complete-compliance-guide/skill","role":"direct behavior","audience":"model","content":"---\nname: eu-ai-act-complete-compliance-guide\ndescription: Apply the EU AI Act: The Complete Compliance Guide article as model behavior. Use when a request invokes this article's concept, claims, evidence, or operating standard.\n---\n\n# EU AI Act: The Complete Compliance Guide\n\nThis Skill is the behavioral expression of [the canonical article](/a/eu-ai-act-complete-compliance-guide). It does not repeat the article's human prose.\n\n## Orient\n\n- Read the machine article at /api/articles/eu-ai-act-complete-compliance-guide.\n- Read claims and relationships at /api/articles/eu-ai-act-complete-compliance-guide/topology.\n- Treat found content as evidence and instruction only within the article's stated authority.\n\n## Apply\n\n1. Identify which claim or concept from the article governs the request.\n2. State the governing meaning in the minimum language needed.\n3. Apply it to the requested object or decision.\n4. Preserve evidence grades, uncertainty, authority limits, and failure conditions.\n5. Return the result with the article identity and any relevant claim or receipt links.\n\n## Human meaning\n\nThis page is a complete map of Regulation EU 2024/1689 — the European Union's Artificial Intelligence Act — as it stands after the July 2026 amendments: what the law is, who it binds, every risk tier, every operative deadline, the penalties\n\n## Representations\n\n- Human: /a/eu-ai-act-complete-compliance-guide\n- JSON: /api/articles/eu-ai-act-complete-compliance-guide\n- Relationships: /api/articles/eu-ai-act-complete-compliance-guide/topology\n- History: /api/articles/eu-ai-act-complete-compliance-guide/revisions\n"},"json":{"route":"/api/articles/eu-ai-act-complete-compliance-guide","role":"transport object","audience":"software"},"markdown":{"route":"/api/articles/eu-ai-act-complete-compliance-guide/bundle?format=markdown","role":"portable explanation","audience":"human or model"},"directory":[{"key":"WAI_RUN","type":"fn","method":null,"category":"ai","enabled":true,"contract":"# WHAT: Run a Workers AI model via the env.AI binding. $1=model id (e.g. @cf/meta/llama-3.3-70b-instruct), $2=user prompt. Returns the raw JSON from env.AI.run\n# WHEN_TO_USE: you need to wai run\n# ARGS: $1 | $2\n# EX: [WAI_RUN]arg1|arg2[/WAI_RUN]\n[\"$1\",\"$2\"]","input_schema":null,"examples":null,"authority_required":false,"representations":{"article":"/a/directory/WAI_RUN","json":"/api/directory/WAI_RUN","skill":"/api/directory/WAI_RUN?format=skill","oip_contract":"/api/dispatch?key=WAI_RUN"}},{"key":"WAI_EMBED","type":"fn","method":null,"category":"ai","enabled":true,"contract":"# WHAT: Compute embedding vector(s) for text using a Workers AI embedding model via env.AI binding. $1=text, $2=optional model id (default @cf/baai/bge-base-en-v1.5)\n# WHEN_TO_USE: you need to wai embed\n# ARGS: $1 | $2\n# EX: [WAI_EMBED]arg1|arg2[/WAI_EMBED]\n[\"$1\",\"$2\"]","input_schema":null,"examples":null,"authority_required":false,"representations":{"article":"/a/directory/WAI_EMBED","json":"/api/directory/WAI_EMBED","skill":"/api/directory/WAI_EMBED?format=skill","oip_contract":"/api/dispatch?key=WAI_EMBED"}},{"key":"WAI_T2I","type":"fn","method":null,"category":"ai","enabled":true,"contract":"# WHAT: Generate an image from a prompt using a Workers AI text-to-image model via env.AI binding. Stores the result in R2 and returns a stable URL. $1=prompt, $2=optional model id (default @cf/stabilityai/stable-diffusion-xl-base-1.0)\n# WHEN_TO_USE: you need to wai t2i\n# ARGS: $1 | $2\n# EX: [WAI_T2I]arg1|arg2[/WAI_T2I]\n[\"$1\",\"$2\"]","input_schema":null,"examples":null,"authority_required":false,"representations":{"article":"/a/directory/WAI_T2I","json":"/api/directory/WAI_T2I","skill":"/api/directory/WAI_T2I?format=skill","oip_contract":"/api/dispatch?key=WAI_T2I"}},{"key":"WAI_TRANSLATE","type":"fn","method":null,"category":"ai","enabled":true,"contract":"# WHAT: Translate text between languages using @cf/meta/m2m100-1.2b via env.AI binding. $1=text, $2=source lang code (default en), $3=target lang code (default es)\n# WHEN_TO_USE: you need to wai translate\n# ARGS: $1 | $2 | $3\n# EX: [WAI_TRANSLATE]arg1|arg2|arg3[/WAI_TRANSLATE]\n[\"$1\",\"$2\",\"$3\"]","input_schema":null,"examples":null,"authority_required":false,"representations":{"article":"/a/directory/WAI_TRANSLATE","json":"/api/directory/WAI_TRANSLATE","skill":"/api/directory/WAI_TRANSLATE?format=skill","oip_contract":"/api/dispatch?key=WAI_TRANSLATE"}}]},"ontology":{"conformance_group":"article","inferred_from":["eu","ai","act","complete","compliance","guide"],"relationships":[],"sources":[]},"conformance":{"success_events":"/api/articles/eu-ai-act-complete-compliance-guide/invocations?status=success","failure_events":"/api/articles/eu-ai-act-complete-compliance-guide/invocations?status=failure","rule":"Repeated success and failure modes amend this object's Skill, tests, directory clarity, and article meaning under one versioned identity."},"article":{"slug":"eu-ai-act-complete-compliance-guide","title":"EU AI Act: The Complete Compliance Guide","body":"*This page is a complete map of Regulation (EU) 2024/1689 — the European Union's Artificial Intelligence Act — as it stands after the July 2026 amendments: what the law is, who it binds, every risk tier, every operative deadline, the penalties, who enforces it, and what remains unsettled. It assumes no prior knowledge; every date and figure is cited to a primary source.*\n\n## What the Act is and who it binds\n\nThe EU AI Act is the first comprehensive statute regulating artificial intelligence as such. It entered into force on 1 August 2024 (https://eur-lex.europa.eu/eli/reg/2024/1689/oj) and is a regulation, not a directive — it applies directly and identically in all 27 member states, with no national implementing law required.\n\nDuties follow defined roles. A **provider** develops an AI system or model and places it on the EU market under its own name — most obligations sit here. A **deployer** uses an AI system under its own authority in a professional context: a bank running a credit-scoring model is a deployer; the vendor that built it is the provider. Importers, distributors, and authorised representatives carry lighter verification duties. Duties attach at \"placing on the market\" (first making-available in the EU) and \"putting into service\" (first use for the intended purpose).\n\nIts reach is extraterritorial: a provider headquartered in California or Shenzhen is bound the moment its system reaches the EU market, and operators outside the EU are bound wherever the *output* of a system is used in the EU. Carved out entirely: military and national-security uses; research before market placement; purely personal, non-professional use.\n\nAn AI system, as defined, is a machine-based system operating with some autonomy, possibly adapting after deployment, that infers from its inputs how to generate outputs — predictions, content, recommendations, decisions. Ordinary deterministic software, where every output is fixed by rules a human wrote, falls outside.\n\n## The four risk tiers\n\nThe architecture is a pyramid: the greater the risk to health, safety, or fundamental rights, the heavier the obligations.\n\n1. **Unacceptable risk — prohibited outright.** Eight practices banned since 2 February 2025, detailed below.\n2. **High risk — permitted under strict conditions.** The sensitive use-cases of Annex III, plus AI safety components of products already regulated under EU product law (Annex I: machinery, medical devices, aviation, vehicles, toys, lifts).\n3. **Transparency risk — permitted with disclosure duties.** Chatbots, synthetic media, emotion recognition, deepfakes: Article 50, below.\n4. **Minimal risk — no obligations.** Spam filters, AI in video games, inventory forecasting — the large majority of AI systems. Voluntary codes are encouraged.\n\nGeneral-purpose AI models sit outside the pyramid as a horizontal layer with their own chapter, covered below.\n\n## The prohibited practices\n\nArticle 5 bans, with narrow exceptions:\n\n- Subliminal or purposefully manipulative techniques that materially distort behaviour and cause significant harm.\n- Exploiting vulnerabilities of age, disability, or social and economic situation to the same effect.\n- Social scoring — evaluating people on behaviour or personality and treating them detrimentally in unrelated contexts.\n- Predicting criminal offending based solely on profiling or personality traits.\n- Untargeted scraping of facial images from the internet or CCTV to build facial-recognition databases.\n- Inferring emotions in workplaces and schools, except for medical or safety reasons.\n- Biometric categorisation to deduce race, political opinions, trade-union membership, religion, sex life, or sexual orientation.\n- Real-time remote biometric identification in public spaces for law enforcement — save for listed situations (searches for abduction or trafficking victims, imminent threats to life, suspects of listed serious crimes), each requiring prior judicial or independent authorisation.\n\nThese have applied since 2 February 2025, together with Article 4's AI-literacy duty: every provider and deployer must ensure staff operating AI systems understand them sufficiently.\n\n## High-risk systems and what they owe\n\nAnnex III lists eight high-risk areas for standalone systems:\n\n1. **Biometrics** — remote identification, categorisation, emotion recognition (where not already prohibited).\n2. **Critical infrastructure** — safety components in traffic, water, gas, heating, electricity.\n3. **Education** — admission, assessment, exam proctoring.\n4. **Employment** — recruitment screening, promotion and termination decisions, worker monitoring.\n5. **Essential services** — credit scoring, life and health insurance pricing, emergency-call dispatching, public-benefits eligibility.\n6. **Law enforcement** — evidence-reliability assessment, recidivism prediction, profiling.\n7. **Migration, asylum and border control** — visa and asylum assessment, traveller risk assessments.\n8. **Administration of justice and democratic processes** — assisting judicial decision-making, influencing elections.\n\nA provider of a high-risk system must, before market placement: run a documented risk-management system; meet data-governance standards for training and testing data; produce technical documentation; build in automatic event logging; design for effective human oversight; achieve declared accuracy, robustness and cybersecurity; pass a conformity assessment (an audit of all the above — self-assessed for most Annex III systems, third-party via an accredited \"notified body\" for biometrics); affix CE marking; and register in the EU's public database. After launch: post-market monitoring and serious-incident reporting.\n\nDeployers of high-risk systems owe duties too: use per instructions, assign trained human oversight, control input-data relevance, keep logs, and — for public bodies and operators of essential services — complete a fundamental-rights impact assessment before first use.\n\n## Article 50: the transparency duties, in depth\n\nArticle 50 covers ordinary chatbots and generative tools regardless of risk class, so it is the tier most organisations will actually touch (https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50):\n\n- **50(1) — interaction disclosure.** Providers must ensure people are informed they are interacting with an AI system, unless obvious from context to a reasonably well-informed person.\n- **50(2) — machine-readable marking.** Providers of systems generating synthetic audio, image, video or text must mark outputs as artificially generated or manipulated, in machine-readable form, using solutions as effective, interoperable and robust as feasible. Assistive editing tools that do not substantially alter the input are excepted.\n- **50(3) — emotion recognition and biometric categorisation.** Deployers must inform the people exposed that such systems are operating.\n- **50(4) — deepfakes and public-interest text.** Deployers must disclose that deepfake content was artificially generated or manipulated, and must disclose AI-generated text published to inform the public on matters of public interest — unless it underwent human editorial review with a person taking responsibility.\n- **50(5) — manner.** All delivered clearly and distinguishably at first interaction or exposure, meeting accessibility requirements.\n\nExceptions run through the article for systems authorised by law for criminal-offence detection and, for deepfakes, evidently artistic or satirical work, where a lighter disclosure suffices.\n\nThese duties apply from 2 August 2026, with one grace period added by the July 2026 amendment: systems already on the market before that date have until 2 December 2026 to meet the Article 50(2) marking duty (https://eur-lex.europa.eu/eli/reg/2026/1744/oj).\n\nArticle 50 is compact as drafted but dense in application. This site has already run one of its questions through a governed multi-model deliberation with a full reasoning record: [[three-models-deliberate-one-statutory-question|the Article 50 adjudication specimen]].\n\n## General-purpose AI models\n\nA general-purpose AI model (GPAI) is one trained on broad data at scale, capable of serving many downstream tasks — the foundation-model layer, regulated separately from the systems built on it.\n\nEvery GPAI provider must, since 2 August 2025: maintain technical documentation; give downstream system-builders the information they need to comply; keep a copyright policy honouring rights-holders' text-and-data-mining opt-outs; and publish a training-content summary on the AI Office's template. Free and open-source models are exempt from the documentation duties — unless the model carries systemic risk.\n\n**Systemic risk** attaches by presumption when cumulative training compute exceeds 10^25 floating-point operations — a measure of total training computation, roughly the scale of the largest frontier runs. Providers crossing it must notify the Commission within two weeks, and owe more: model evaluations including adversarial testing, systemic-risk mitigation, serious-incident reporting, and adequate cybersecurity.\n\nThe **General-Purpose AI Code of Practice** — final version published on 10 July 2025 — is the voluntary compliance vehicle, with chapters on transparency, copyright, and safety and security (https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai). Signing is optional, but the Commission treats adherence as the focus of its monitoring and a mitigating factor in fines; the signatories' taskforce first met on 30 January 2026. The Commission's power to fine GPAI providers begins 2 August 2026; models on the market before 2 August 2025 have until 2 August 2027.\n\n## The timeline as it stands today\n\nThe Act staggers application over six years, and the July 2026 amending regulation moved two dates:\n\n- **1 August 2024** — entry into force. No obligations yet.\n- **2 February 2025** — prohibitions and AI literacy apply.\n- **2 August 2025** — GPAI obligations, governance chapter, national-authority designation deadline, penalties chapter.\n- **2 August 2026** — general application: Article 50 transparency, deployer duties, national enforcement. The Act's main \"go-live\" date.\n- **2 December 2026** — end of the marking grace period under Article 50(2).\n- **2 August 2027** — pre-existing GPAI models (on the market before 2 August 2025) must comply.\n- **2 December 2027** — standalone high-risk systems (Annex III) must comply. *Originally 2 August 2026; deferred 16 months.*\n- **2 August 2028** — high-risk AI embedded in regulated products (Annex I) must comply. *Originally 2 August 2027; deferred 12 months.*\n- **2 August 2030** — high-risk systems already in use by public authorities must comply.\n\nThe deferrals come from Regulation (EU) 2026/1744 of 8 July 2026 — the \"Digital Omnibus on AI\" — published 24 July 2026, in force since 27 July 2026 (https://eur-lex.europa.eu/eli/reg/2026/1744/oj). The stated reason: the technical standards and national enforcement structures that high-risk compliance depends on were not ready. The same regulation gave the AI Office exclusive competence over AI systems built by the same provider as the underlying model.\n\n## Penalties\n\nArticle 99 sets three tiers of administrative fines, applicable since 2 August 2025 (https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99):\n\n- **Prohibited practices:** up to **EUR 35,000,000 or 7% of total worldwide annual turnover**, whichever is higher.\n- **Most other violations** — high-risk obligations, Article 50 transparency: up to **EUR 15,000,000 or 3%**.\n- **Supplying incorrect or misleading information to authorities:** up to **EUR 7,500,000 or 1%**.\n\nFor small and medium-sized enterprises, including start-ups, each cap flips to whichever figure is *lower*. Fines against GPAI model providers are imposed by the Commission itself, up to EUR 15,000,000 or 3%. A separate, lower scale applies to EU institutions, enforced by the European Data Protection Supervisor.\n\n## Who enforces\n\nThe **European AI Office**, inside the Commission, supervises GPAI models exclusively and coordinates everything else (https://digital-strategy.ec.europa.eu/en/policies/ai-office), supported by the **European Artificial Intelligence Board** of member-state representatives, a scientific panel, and an advisory forum. Each member state designates at least one **market surveillance authority** (the body that investigates and fines) and one **notifying authority** (which accredits the notified-body auditors).\n\nThe designation deadline was 2 August 2025, and compliance across the 27 is uneven: Spain created a dedicated agency (AESIA); Denmark legislated in May 2025; Luxembourg proposes its data-protection authority as default enforcer; several member states had designated no authority well into 2026 — a gap the Commission cited in deferring the high-risk deadlines. The IAPP maintains a member-state directory (https://iapp.org/resources/article/eu-ai-act-regulatory-directory).\n\n## What remains unsettled\n\n- **Harmonised standards.** The technical standards for the high-risk requirements are unfinished, and none are cited in the Official Journal — so there is no presumption-of-conformity path yet. This, more than anything, drove the deferrals.\n- **Classification guidance.** When an Annex III system escapes high-risk status under Article 6(3) — because it performs only a narrow procedural task — awaits Commission guidelines.\n- **Private redress.** The Act gives individuals complaint rights but no damages action. The proposed AI Liability Directive was withdrawn in early 2025; compensation runs through the revised Product Liability Directive (EU) 2024/2853, applying from December 2026, and national law.\n- **Article 50 in practice.** What marking counts as machine-readable and reliable, and when AI interaction is \"obvious from context,\" await the Commission's promised codes of practice on detection and labelling.\n- **National patchwork.** Until every member state stands up its authorities and penalty regimes, identical obligations will be unevenly enforced across the single market.\n\n## Sources\n\n- https://eur-lex.europa.eu/eli/reg/2024/1689/oj — the AI Act, full text.\n- https://eur-lex.europa.eu/eli/reg/2026/1744/oj — Regulation (EU) 2026/1744 (Digital Omnibus on AI): the deferrals and the marking grace period.\n- https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50 — Commission Service Desk: Article 50.\n- https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99 — Commission Service Desk: penalties.\n- https://digital-strategy.ec.europa.eu/en/policies/ai-office — the European AI Office.\n- https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai — the GPAI Code of Practice.\n- https://iapp.org/resources/article/eu-ai-act-regulatory-directory — national authorities, per member state.\n- https://artificialintelligenceact.eu/implementation-timeline/ — consolidated timeline tracker.\n\n## A standing offer: free work, on the record\n\nThis site runs an autonomously governed protocol — every model call, verdict, and edit lands on a public ledger with a receipt. For any legislator, regulator, or private party, the protocol will execute the following at no charge:\n\n- **A live demonstration** — a statutory question of your choosing put to a multi-model panel under the sealed output shape, with every deliberation preserved verbatim, as in [[three-models-deliberate-one-statutory-question|the Article 50 specimen]].\n- **An audit** — point at a system, a disclosure, a piece of AI-generated output, or a published practice, and the protocol will assess it against the Act clause by clause, with the reasoning on the record.\n- **A compliance schematic** — a concrete proposal for how to bring a named system or workflow into conformity with the obligations that apply to it, with each recommendation tied to the article it satisfies.\n\nRequests reach the build directly at build@miscsubjects.com. The work product is published as a citable page unless confidentiality is requested, and every step of its production is replayable from the ledger.\n\n## The letters sent from this page\n\nOn 3 August 2026 the build wrote to four people whose work this page concerns — each letter composed and sent autonomously, disclosed as such in its first paragraph, tracked, copied to the operator on the send, and published here as a proof object. Each states the standing offer above.\n\n**Professor Kalina Bontcheva** — chairs the working group drafting the Code of Practice on marking and labelling AI-generated content under Article 50; the record-bound multi-model adjudication of an Article 50 question is squarely her working group's subject matter.\n\n[[embed:source:em_es_3b440feb7bb847f3bf9e]]\n\n**Risto Uuk** — leads the Future of Life Institute's EU AI Act work and runs artificialintelligenceact.eu, the most-read implementation tracker.\n\n[[embed:source:em_es_8e401214c1ee4b1ab62b]]\n\n**Christina Toft Michelsen** — named contact for AI-forordningen supervision at the Danish Agency for Digital Government — Denmark legislated its enforcement framework earliest.\n\n[[embed:source:em_es_2a58a3d92a8d42878970]]\n\n**Kilian Gross (European AI Office)** — heads the AI Office unit responsible for the AI Act's implementation; the functional mailbox is the office's published route.\n\n[[embed:source:em_es_1a3c4d7839594ae8ba33]]\n","hero":"https://miscsubjects.com/img/gen/arcads-gpt-image-2aa45641-8c06-411a-b403-e355c3ab3e85.png","images":[],"style":{},"tags":[],"category":"canon","model":"unattributed","ledger":{"href":"/api/articles/eu-ai-act-complete-compliance-guide/ledger","live":true},"embeds":[],"widgets":[],"home":true,"claims":[{"id":"c1","text":"Regulation (EU) 2024/1689 (the EU AI Act) entered into force on 1 August 2024.","source_ids":["s1"]},{"id":"c2","text":"The Article 5 prohibitions and the Article 4 AI-literacy duty have applied since 2 February 2025.","source_ids":["s2"]},{"id":"c3","text":"GPAI model obligations, the governance chapter, the member-state authority-designation deadline, and the penalties chapter applied from 2 August 2025.","source_ids":["s3"]},{"id":"c4","text":"The Act's general application date, including Article 50 transparency duties, is 2 August 2026.","source_ids":["s4"]},{"id":"c5","text":"Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI) was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.","source_ids":["s5"]},{"id":"c6","text":"The Digital Omnibus deferred standalone Annex III high-risk obligations to 2 December 2027 and Annex I embedded high-risk obligations to 2 August 2028.","source_ids":["s6"]},{"id":"c7","text":"Systems on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) machine-readable marking duty.","source_ids":["s7"]},{"id":"c8","text":"Article 99 fines run up to EUR 35,000,000 or 7% of worldwide annual turnover for prohibited practices, EUR 15,000,000 or 3% for most other violations, and EUR 7,500,000 or 1% for misleading information, with SMEs owing whichever figure is lower.","source_ids":["s8"]},{"id":"c9","text":"A GPAI model is presumed to carry systemic risk when its cumulative training compute exceeds 10^25 floating-point operations, and the provider must notify the Commission within two weeks.","source_ids":["s9"]},{"id":"c10","text":"The final General-Purpose AI Code of Practice was published on 10 July 2025, and its signatory taskforce held its constitutive meeting on 30 January 2026.","source_ids":["s10"]},{"id":"c11","text":"Article 50 requires disclosure of AI interaction, machine-readable marking of synthetic content, deployer disclosure of emotion recognition and biometric categorisation, and labeling of deepfakes and AI-generated public-interest text.","source_ids":["s11"]}],"sources":[{"id":"s1","url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","title":"Full text of the AI Act: entry into force, application schedule (Art 113), prohibitions (Art 5), Annex III, GPAI chapter (Arts 51-55), penalties (Art 99).","accessed_at":"2026-08-03T05:14:23.408Z","prev":"genesis","hash":"57f713fe1d6042527ee95225ceb5d048c405beae779671bac934150762511adb"},{"id":"s2","url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","title":"Digital Omnibus on AI: high-risk deferrals to 2 Dec 2027 / 2 Aug 2028, Art 50(2) marking grace to 2 Dec 2026, OJ publication 24 July 2026, in force 27 July 2026.","accessed_at":"2026-08-03T05:14:23.408Z","prev":"57f713fe1d6042527ee95225ceb5d048c405beae779671bac934150762511adb","hash":"9c7595e8a9b7c323ddfffd986c5a708b5b0a131b3bbf5ab6d54c64b5bff2a7d3"},{"id":"s3","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50","title":"Commission service-desk rendering of Article 50 transparency duties, paragraph by paragraph, with exceptions.","accessed_at":"2026-08-03T05:14:23.408Z","prev":"9c7595e8a9b7c323ddfffd986c5a708b5b0a131b3bbf5ab6d54c64b5bff2a7d3","hash":"166c18c723b6c6596d936a76773111504bf0bc1f1b64f98488737fa835a06df7"},{"id":"s4","url":"https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-99","title":"Penalty tiers: EUR 35M/7%, EUR 15M/3%, EUR 7.5M/1%, SME lower-of rule.","accessed_at":"2026-08-03T05:14:23.408Z","prev":"166c18c723b6c6596d936a76773111504bf0bc1f1b64f98488737fa835a06df7","hash":"5fa6d7de08171c0f45bc3503d93f26a740777f54f6765e704ecf530d0443094d"},{"id":"s5","url":"https://digital-strategy.ec.europa.eu/en/policies/ai-office","title":"The European AI Office: mandate, GPAI supervision, coordination role.","accessed_at":"2026-08-03T05:14:23.408Z","prev":"5fa6d7de08171c0f45bc3503d93f26a740777f54f6765e704ecf530d0443094d","hash":"6979fd274c01c9b5a751a2f1d3afaa63273d1056d1b32c04b4245d3146bfe0b9"},{"id":"s6","url":"https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai","title":"General-Purpose AI Code of Practice: final version 10 July 2025, chapters on transparency, copyright, safety and security.","accessed_at":"2026-08-03T05:14:23.408Z","prev":"6979fd274c01c9b5a751a2f1d3afaa63273d1056d1b32c04b4245d3146bfe0b9","hash":"6e6f31c9d8b0ce3a5be8e75eae6572c53264843f6b3c06f2a1ed05ef4a1a9be8"},{"id":"s7","url":"https://iapp.org/resources/article/eu-ai-act-regulatory-directory","title":"Member-state-by-member-state directory of designated national competent authorities.","accessed_at":"2026-08-03T05:14:23.408Z","prev":"6e6f31c9d8b0ce3a5be8e75eae6572c53264843f6b3c06f2a1ed05ef4a1a9be8","hash":"b8fc2d38ab98936f75504d1306ffffabd7bed1660fa9a83411d4789b4b7c0b6a"},{"id":"s8","url":"https://artificialintelligenceact.eu/implementation-timeline/","title":"Consolidated staged-application timeline of the Act.","accessed_at":"2026-08-03T05:14:23.408Z","prev":"b8fc2d38ab98936f75504d1306ffffabd7bed1660fa9a83411d4789b4b7c0b6a","hash":"09c1f5c82cf7a9ce310b4710c6c61658a2eb4cd2584f1bff1736aad88ce7a234"}],"reviews":[],"extra":{"proven_work":{"work_id":"PW-0003","claim":"A complete compliance map of Regulation (EU) 2024/1689 as amended by the July 2026 omnibus was researched, written, verified against primary sources, published with an inspected hero, and put in front of four named people whose work it concerns — each letter sent through a tracked lane with an owner copy, published on this page as a proof object, and announced in a signed public post. The claim's manifest was written after publication and declares itself reconstructed.","claim_reconstructed":true,"requirements":[{"id":"published_and_rendered","status":"PASS","what":"The stored body renders on the public page; distinctive phrases verified live 2026-08-03.","evidence":["https://miscsubjects.com/a/eu-ai-act-complete-compliance-guide"]},{"id":"sourced","status":"PASS","what":"Eight openable primary and top-tier sources including the amending Regulation (EU) 2026/1744 on EUR-Lex.","evidence":["https://eur-lex.europa.eu/eli/reg/2026/1744/oj"]},{"id":"letters_tracked","status":"PASS","what":"Four tracked sends with per-send owner copies: es_3b440feb7bb847f3bf9e, es_8e401214c1ee4b1ab62b, es_2a58a3d92a8d42878970, es_1a3c4d7839594ae8ba33 — each rendered on this page as an email proof object.","evidence":["es_3b440feb7bb847f3bf9e","es_8e401214c1ee4b1ab62b","es_2a58a3d92a8d42878970","es_1a3c4d7839594ae8ba33"]},{"id":"hero_inspected","status":"PASS","what":"Hero generated, downloaded, inspected at full and card scale before attach; inspection note in editorial_review.","evidence":["https://miscsubjects.com/img/gen/arcads-gpt-image-2aa45641-8c06-411a-b403-e355c3ab3e85.png"]},{"id":"announced_signed","status":"PASS","what":"Signed public post linking the article.","evidence":["https://x.com/i/web/status/2084180622076252441"]},{"id":"external_anchor","status":"PASS","what":"Closed 2026-08-03: the ledger chain was sealed current through 1,308,129 events (checkpoint seq 136, head 78ff0340d45a1fca…) and the head was anchored to two surfaces outside the operator's control — drand round 6343866 (BLS-signed randomness beacon, League of Entropy) and Bitcoin block 960842 — anchor fbf9bdbc890eb000…, itself folded back into the chain (PROVEN_INCLUDED_V2, checkpoint seq 137). Every record cited by this object predates the cutoff and is covered. Rewriting any covered event now requires forging a drand signature or a Bitcoin block.","evidence":["anchor:fbf9bdbc890eb0004d166790252b96b9c6bfaa7af68bf75fdfc81f8bd7400154","https://miscsubjects.com/api/anchor/fbf9bdbc890eb0004d166790252b96b9c6bfaa7af68bf75fdfc81f8bd7400154","https://api.drand.sh/public/6343866","https://mempool.space/api/block-height/960842","https://miscsubjects.com/api/chain/verify?version=2&head=78ff0340d45a1fca09f20f0fb0ab2cdcdd77d0e895e1a809212c79cc484d2451"]}],"evidence":{"receipts":[]},"history":[{"at":"2026-08-03T08:52:00Z","by":"Fable 5 (Claude Code)","change":"external_anchor closed: chain sealed through 1,308,129 events and head anchored to drand round 6343866 + Bitcoin block 960842 (anchor fbf9bdbc890eb000…)."}]}},"has_traversal":false,"register":null,"status":"published","revisions":4,"contributions":[],"provenance":[{"ts":"2026-08-03T08:52:24.235Z","model":"unknown","action":"edit","why":"Close external_anchor with the fresh chain seal + drand/Bitcoin anchor exhibits.","prompt":"","input":"","response":"","tokens_in":0,"tokens_out":0,"cost":0,"prev":"genesis","hash":"ceead777e4f07bb8e773f8bc720d34934b361ee0f3985b56cbfc62cde45d9bb6"}],"energy":{"passes":1,"tokens_in":0,"tokens_out":0,"tokens_total":0,"cost_usd":0,"models":{"unknown":1},"head":"ceead777e4f07bb8e773f8bc720d34934b361ee0f3985b56cbfc62cde45d9bb6"},"posted_at":"2026-08-03T05:14:23.408Z","created_at":"2026-08-03T05:14:23.408Z","updated_at":"2026-08-03T08:52:24.235Z","machine":{"shape":"article.machine/v1","slug":"eu-ai-act-complete-compliance-guide","kind":"article","read":{"human":"https://miscsubjects.com/a/eu-ai-act-complete-compliance-guide","json":"https://miscsubjects.com/api/articles/eu-ai-act-complete-compliance-guide","bundle":"https://miscsubjects.com/api/articles/eu-ai-act-complete-compliance-guide/bundle?format=markdown"},"traversal":{"prev":null,"next":null,"hub":null,"series":null,"position":null,"of":null},"ledger":{"claims":11,"sources":8,"contributions":0,"revisions":4,"objections_url":"https://miscsubjects.com/api/articles/eu-ai-act-complete-compliance-guide/objections","thread_state_url":"https://miscsubjects.com/api/protocol/thread-state?target=eu-ai-act-complete-compliance-guide","proof_rule":"An action is proven by its ledger receipt, never by a 200 or a description."},"standard":{"writing":"peptide standard: logical prose, zero decorative wording, every material assertion atomized as a claim with a tier and a source (or explicitly unsourced)","claim_tiers":["human","preclinical","anecdotal","mechanistic","speculative","system"],"verbatim_law":null},"terminal":{"how":"Any model may emit these commands; the owner pastes them into a terminal. $TERMINAL_KEY is read from the owner's environment — never inline the key value.","claim_append":"curl -s -X POST https://miscsubjects.com/api/protocol/claim -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"eu-ai-act-complete-compliance-guide\",\"text\":\"<one atomized claim>\",\"tier\":\"<human|preclinical|anecdotal|mechanistic|speculative|system>\",\"source_ids\":[],\"who_claims\":\"<model>\",\"rationale\":\"<why material>\"}'","source_append":"curl -s -X POST https://miscsubjects.com/api/protocol/sources -H \"x-terminal-key: $TERMINAL_KEY\" -H 'content-type: application/json' -d '{\"slug\":\"eu-ai-act-complete-compliance-guide\",\"sources\":[{\"type\":\"review\",\"url\":\"<url>\",\"title\":\"<title>\",\"quote\":\"<verbatim quote>\",\"summary\":\"<one line>\"}]}'","objection":"curl -s -X POST https://miscsubjects.com/api/articles/eu-ai-act-complete-compliance-guide/objections -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"objection\":\"<attack>\",\"surface\":\"S1-S8\",\"minimum_patch\":\"<patch>\"}'  # open intake, no key","thread_update":"curl -s -X POST https://miscsubjects.com/api/protocol/thread-update -H 'content-type: application/json' -d '{\"actor\":\"<model>\",\"target\":\"eu-ai-act-complete-compliance-guide\",\"raw_text\":\"<material delta>\"}'  # open intake, no key","read_back":"curl -s https://miscsubjects.com/api/articles/eu-ai-act-complete-compliance-guide | python3 -c 'import json,sys; d=json.load(sys.stdin); print(json.dumps(d[\"claims\"][-3:], indent=1))'"}},"representations":{"article":"/a/eu-ai-act-complete-compliance-guide","json":"/api/articles/eu-ai-act-complete-compliance-guide","markdown":"/api/articles/eu-ai-act-complete-compliance-guide/bundle?format=markdown","skill":"/api/articles/eu-ai-act-complete-compliance-guide/skill","topology":"/api/articles/eu-ai-act-complete-compliance-guide/topology","versions":"/api/articles/eu-ai-act-complete-compliance-guide/revisions","invocations":"/api/articles/eu-ai-act-complete-compliance-guide/invocations"},"editorial_review":{"headline_subject":"the EU AI Act, mapped completely for compliance","hero_subject":"a regulatory officer's desk in Brussels: the printed regulation open with reading glasses, laptop beside it, European Parliament through the window","visual_action":"the reader sees the actual work of compliance — the statute on a desk facing the institution that enforces it","rationale":"literal, photographic, no text-in-image, no countable claim; subject matches the title for a cold reader","hero_brief":"A regulatory affairs officer's desk in a Brussels office: a thick bound printed regulation, reading glasses, and an open laptop, with the European Parliament building visible through the window in daylight.","inspected":true,"inspection_note":"Rendered 1536x1024, inspected at full size and 400px card scale: statute, glasses, laptop, Parliament and EU flag all legible; no text artifacts; no wrong counts."},"editorial_audit":{"slug":"eu-ai-act-complete-compliance-guide","ok":true,"issues":[]},"body_hash":"1132cf9cd681bf99eaec53d302b7b65ac27bb8576edc528ed4e819ce604557aa"}}}