AI Sentri
    EU AI Act

    EU AI Act compliance, from inventory to evidence.

    AI Sentri helps you manage AI risk, oversight, and accountability in line with emerging EU AI Act expectations.

    What is the EU AI Act?

    The EU AI Act is the world's first comprehensive regulatory framework for artificial intelligence. It takes a risk-based approach, setting clear expectations for how AI systems should be governed, documented, and overseen.

    A risk-based framework that classifies AI systems by their potential impact
    A strong focus on high-risk systems that affect people's rights and safety
    Clear expectations for governance, transparency, and accountability

    Why It Matters

    Applies to organisations operating in or selling into the EU
    Introduces clear expectations for high-risk AI
    Increases scrutiny on governance and documentation
    Non-compliance carries significant risk

    How AI Sentri Aligns

    Mapping EU AI Act expectations to practical outcomes.

    ExpectationAI System Identification
    What It RequiresKnow what AI systems exist and where they are used
    How AI Sentri DeliversFull AI Systems Inventory capturing purpose, use case, stakeholders, and dependencies
    What This Means for YouComplete visibility of your AI estate — no blind spots
    ExpectationRisk Classification (High-Risk Systems)
    What It RequiresIdentify and manage high-risk AI
    How AI Sentri DeliversBuilt-in risk scoring with structured inputs and clear high-risk flagging
    What This Means for YouInstantly understand which systems need the most attention
    ExpectationGovernance & Accountability
    What It RequiresClear ownership and oversight
    How AI Sentri DeliversNamed owners, governance committees, and escalation paths
    What This Means for YouNo ambiguity — clear responsibility across every system
    ExpectationDocumentation & Transparency
    What It RequiresMaintain detailed system documentation
    How AI Sentri DeliversCapture of intended use, misuse, limitations, explainability, and dependencies
    What This Means for YouBe able to clearly explain how your AI works and where it shouldn't be used
    ExpectationHuman Oversight
    What It RequiresEnsure humans can intervene in key decisions
    How AI Sentri DeliversDefined oversight points within each system
    What This Means for YouConfidence that critical decisions aren't left fully to AI
    ExpectationRisk Management & Mitigation
    What It RequiresIdentify, track, and reduce risks
    How AI Sentri DeliversIntegrated risk register with mitigation tracking
    What This Means for YouMove from identifying risks to actively managing them
    ExpectationMonitoring & Logging
    What It RequiresTrack system performance and issues over time
    How AI Sentri DeliversOngoing monitoring, reviews, and issue logging
    What This Means for YouContinuous visibility into how systems behave in the real world
    ExpectationControl & Standards Enforcement
    What It RequiresEnsure consistent safeguards across systems
    How AI Sentri DeliversStandard-driven governance with clear "met / not met" status
    What This Means for YouEnforce consistent governance across all AI, not just best effort
    ExpectationAuditability & Evidence
    What It RequiresBe able to demonstrate compliance
    How AI Sentri DeliversStructured, auditable records across all systems
    What This Means for YouBe ready to evidence your approach without scrambling for documentation

    Key Capabilities

    Deep, structured AI system inventory
    Built-in risk classification and high-risk identification
    Clear ownership, governance, and escalation
    Explainability and transparency captured at system level
    Continuous monitoring and review
    Standardised governance across all systems

    Important Note

    AI Sentri supports organisations in aligning with EU AI Act principles but does not provide legal advice or guarantee compliance. Organisations should seek appropriate professional guidance.

    AI Sentri helps you operationalise AI governance in a way that aligns with evolving regulatory expectations.

    Application timeline

    EU AI Act deadlines, and what changed

    The Act applies in stages rather than all at once. Some obligations have been in force since 2025; the largest set was deferred in May 2026.

    1. 2 February 2025
      In force

      Prohibitions and AI literacy

      Prohibited practices under Article 5 became unlawful, and the Article 4 obligation to ensure staff have sufficient AI literacy took effect. Both are in force now.

    2. 2 August 2025
      In force

      General-purpose AI obligations

      Transparency, documentation and copyright duties for providers of general-purpose AI models, alongside governance and penalty provisions.

    3. 2 August 2026
      In force

      Transparency duties and registration

      Article 50 transparency obligations and Article 49 registration requirements apply, together with the general application of the Act. These were not deferred.

    4. 2 December 2027
      Deferred

      High-risk obligations, Annex III systems

      Stand-alone high-risk systems — recruitment, credit scoring, education, essential services, law enforcement, border control — deferred from August 2026 by the Digital Omnibus.

    5. 2 August 2028
      Deferred

      High-risk obligations, Annex I products

      AI embedded as a safety component in regulated products such as medical devices, machinery and vehicles.

    A deferral is not a reprieve. The Digital Omnibus moved dates, it did not remove obligations — and the AI literacy duty and transparency rules kept their original timing. Classification work still has to happen before you can know which deadline applies to you. Penalties reach €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices, with lower bands for other breaches.

    Our reading of the position as at 23 September 2026, reflecting the Digital Omnibus on AI agreed 6 May 2026 and confirmed in Council on 13 May 2026. Legislative timelines change — confirm against the official text before relying on any date.

    AI Sentri is an aid, not an assurance. It helps you structure your thinking, record what you have done and see where the gaps are. It does not make you compliant, and nothing it produces is legal advice or a regulatory opinion. Scores are indicative. Responsibility for compliance stays with your organisation, and decisions with legal consequences should be taken with a qualified adviser.

    Before you start

    Questions about the EU AI Act

    What are the EU AI Act deadlines?

    Prohibited practices and the Article 4 AI literacy duty have applied since 2 February 2025. General-purpose AI obligations followed on 2 August 2025. Article 50 transparency and Article 49 registration apply from 2 August 2026. High-risk obligations for stand-alone Annex III systems were deferred to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028, by the Digital Omnibus agreed in May 2026.

    Were the EU AI Act high-risk deadlines delayed?

    Yes. The Digital Omnibus on AI, politically agreed on 6 May 2026 and confirmed in Council on 13 May 2026, deferred high-risk obligations for Annex III systems from August 2026 to 2 December 2027, and for Annex I embedded products to 2 August 2028. The deferral is temporal only — no obligation was removed, and the transparency and AI literacy duties kept their original timing.

    Who does the EU AI Act apply to?

    Providers and deployers of AI systems placed on the EU market or whose output is used in the EU, wherever they are established. That reaches many UK organisations through customers, subsidiaries or suppliers. Obligations differ substantially depending on whether you built the system or are deploying someone else's.

    What counts as a high-risk AI system under Annex III?

    Stand-alone systems used in employment and recruitment, education access, creditworthiness and credit scoring, essential public and private services, law enforcement, migration and border control, and administration of justice. Separately, Annex I covers AI acting as a safety component of already-regulated products such as medical devices, machinery and vehicles. Classification turns on the purpose the system is put to, not the technology behind it.

    What are the penalties for non-compliance?

    Up to €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices, with lower bands for other breaches. For most organisations the more realistic exposure is being unable to demonstrate a governance process when a customer, auditor or regulator asks — which is a commercial problem long before it becomes a legal one.

    What should an EU AI Act compliance checklist cover?

    In order: inventory every AI system; classify each by purpose against the prohibited, high-risk, limited and minimal categories; confirm whether you are provider or deployer for each; evidence AI literacy under Article 4, which is already in force; then work through the obligations attaching to your highest category — risk management, data governance, technical documentation, human oversight, accuracy and robustness, logging, and registration. Most organisations discover the real blocker is step one.

    Where should we start?

    Inventory, then classify, then close gaps in risk order. You cannot know which deadline applies to you until you know what you run and what each system is used for. AI Sentri is built around that sequence, and the two-minute health check gives an indicative position before you commit to anything.

    More in the full FAQ, or ask us directly.

    Your Privacy Matters

    We use cookies to provide essential functionality, analyse usage, and improve your experience. Under GDPR, you have the right to choose which cookies you allow. Strictly necessary cookies cannot be disabled. Privacy Policy