Compliance · Europe
The EU AI Act, after the Digital Omnibus.
Most internal knowledge assistants are not high-risk, but the classification must be documented. Some automations are high-risk, and their deadline moved to 2 December 2027.
- In force
- 1 August 2024
- Prohibitions
- Since 2 February 2025
- Annex III high-risk
- From 2 December 2027
- Product-embedded high-risk
- From 2 August 2028
In short
The EU AI Act regulates AI by risk. Prohibited practices have applied since February 2025 and general-purpose AI rules since August 2025. After the Digital Omnibus, in force since July 2026, obligations for Annex III high-risk systems apply from 2 December 2027. Typical internal knowledge assistants are not high-risk, but uses such as CV screening or credit scoring of individuals are.
What it asks
Requirements, and how we meet them.
| Requirement | How DeepVox addresses it |
|---|---|
| Classify each AI system | We document the risk classification for every agent we build. |
| High-risk uses (Annex III) | Employment decisions, creditworthiness of individuals and others are scoped, documented and priced as high-risk. |
| Transparency for generated content | Labelling and disclosure designed in; Article 50(2) duties for synthetic content apply from 2 December 2026. |
| Human oversight | Approval gates and named approvers are our default. |
| Logging and traceability | Every input, source, output and action is logged in your environment. |
Timeline
Key dates.
Prohibitions apply
Banned practices out of the market.
General-purpose AI
Obligations for GPAI model providers.
Synthetic-content transparency
Article 50(2) for generative systems.
Annex III high-risk
Employment, credit, essential services and more.
Annex I high-risk
AI embedded in regulated products.
FAQ
Questions, answered.
Is our internal knowledge assistant high-risk?
Usually not. It becomes high-risk if it is used for a listed purpose, such as decisions about employees or individuals’ creditworthiness. We document the classification either way.
Did the Digital Omnibus remove obligations?
It moved dates rather than removing the high-risk regime: Annex III obligations now apply from 2 December 2027 and product-embedded ones from 2 August 2028.
Related
GDPR
Self-hosted AI keeps personal data, including health and biometric data, inside your environment, which removes most of the transfer and processor questions cloud AI raises..
Learn more →DORA
Since 17 January 2025, EU financial entities must manage ICT third-party risk, keep a register of ICT arrangements and plan exits.
Learn more →Other markets
Europe, the United States and India.
Learn more →General information, not legal advice. Have your counsel confirm how each rule applies to you. Sources: EU AI Act Digital Omnibus summary (Orrick, July 2026). Updated October 2026.
Start with two weeks of evidence, not a sales call.
A fixed-price discovery sprint, credited against whatever comes next. Or write to sales@deepvox.ai.