AI Sentri helps you manage AI risk, oversight, and accountability in line with emerging EU AI Act expectations.
The EU AI Act is the world's first comprehensive regulatory framework for artificial intelligence. It takes a risk-based approach, setting clear expectations for how AI systems should be governed, documented, and overseen.
Mapping EU AI Act expectations to practical outcomes.
AI Sentri supports organisations in aligning with EU AI Act principles but does not provide legal advice or guarantee compliance. Organisations should seek appropriate professional guidance.
AI Sentri helps you operationalise AI governance in a way that aligns with evolving regulatory expectations.
Application timeline
The Act applies in stages rather than all at once. Some obligations have been in force since 2025; the largest set was deferred in May 2026.
Prohibitions and AI literacy
Prohibited practices under Article 5 became unlawful, and the Article 4 obligation to ensure staff have sufficient AI literacy took effect. Both are in force now.
General-purpose AI obligations
Transparency, documentation and copyright duties for providers of general-purpose AI models, alongside governance and penalty provisions.
Transparency duties and registration
Article 50 transparency obligations and Article 49 registration requirements apply, together with the general application of the Act. These were not deferred.
High-risk obligations, Annex III systems
Stand-alone high-risk systems — recruitment, credit scoring, education, essential services, law enforcement, border control — deferred from August 2026 by the Digital Omnibus.
High-risk obligations, Annex I products
AI embedded as a safety component in regulated products such as medical devices, machinery and vehicles.
A deferral is not a reprieve. The Digital Omnibus moved dates, it did not remove obligations — and the AI literacy duty and transparency rules kept their original timing. Classification work still has to happen before you can know which deadline applies to you. Penalties reach €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices, with lower bands for other breaches.
Our reading of the position as at 23 September 2026, reflecting the Digital Omnibus on AI agreed 6 May 2026 and confirmed in Council on 13 May 2026. Legislative timelines change — confirm against the official text before relying on any date.
AI Sentri is an aid, not an assurance. It helps you structure your thinking, record what you have done and see where the gaps are. It does not make you compliant, and nothing it produces is legal advice or a regulatory opinion. Scores are indicative. Responsibility for compliance stays with your organisation, and decisions with legal consequences should be taken with a qualified adviser.
Before you start
Prohibited practices and the Article 4 AI literacy duty have applied since 2 February 2025. General-purpose AI obligations followed on 2 August 2025. Article 50 transparency and Article 49 registration apply from 2 August 2026. High-risk obligations for stand-alone Annex III systems were deferred to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028, by the Digital Omnibus agreed in May 2026.
Yes. The Digital Omnibus on AI, politically agreed on 6 May 2026 and confirmed in Council on 13 May 2026, deferred high-risk obligations for Annex III systems from August 2026 to 2 December 2027, and for Annex I embedded products to 2 August 2028. The deferral is temporal only — no obligation was removed, and the transparency and AI literacy duties kept their original timing.
Providers and deployers of AI systems placed on the EU market or whose output is used in the EU, wherever they are established. That reaches many UK organisations through customers, subsidiaries or suppliers. Obligations differ substantially depending on whether you built the system or are deploying someone else's.
Stand-alone systems used in employment and recruitment, education access, creditworthiness and credit scoring, essential public and private services, law enforcement, migration and border control, and administration of justice. Separately, Annex I covers AI acting as a safety component of already-regulated products such as medical devices, machinery and vehicles. Classification turns on the purpose the system is put to, not the technology behind it.
Up to €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices, with lower bands for other breaches. For most organisations the more realistic exposure is being unable to demonstrate a governance process when a customer, auditor or regulator asks — which is a commercial problem long before it becomes a legal one.
In order: inventory every AI system; classify each by purpose against the prohibited, high-risk, limited and minimal categories; confirm whether you are provider or deployer for each; evidence AI literacy under Article 4, which is already in force; then work through the obligations attaching to your highest category — risk management, data governance, technical documentation, human oversight, accuracy and robustness, logging, and registration. Most organisations discover the real blocker is step one.
Inventory, then classify, then close gaps in risk order. You cannot know which deadline applies to you until you know what you run and what each system is used for. AI Sentri is built around that sequence, and the two-minute health check gives an indicative position before you commit to anything.
More in the full FAQ, or ask us directly.