EU AI Act — Regulation 2024/1689

Applies under Article 2 to EU providers, EU-based deployers, and third-country providers/deployers whose AI output is used in the Union — including UK · Ireland · EU

The EU AI Act is now applying in phases.
Most organisations are using AI faster than they're documenting it.

Eighteen article-referenced assets — sixteen compliance frameworks and a two-part Article 4 literacy programme — plus Sentinel, an optional runtime governance control. Pre-populated with practical content, designed for rapid customisation. Straightforward use cases can be adapted in hours; complex or high-risk deployments need deeper review. Not generic templates — a governance stack built to the regulation.

18
Article-Referenced Assets
70
Compliance Checks
18
Tool Assessments Pre-Populated
Mandatory Compliance Timeline

The next enforcement milestone
is 2 August 2026.

2 Feb 2025 — In Force
Article 5 prohibited practices apply. Article 4 AI-literacy obligations also apply, with supervision and enforcement by national authorities beginning from August 2026
2 Aug 2025 — In Force
GPAI model obligations, governance provisions and penalties apply
2 Aug 2026 — Deadline
Article 50 role-specific transparency duties apply; market-surveillance and supervision mechanisms become central, subject to national implementation and the obligation concerned. General application date for obligations not already applicable or subject to a specific transition period
2 Dec 2026
Art 50(2) machine-readable marking / detectability of synthetic content. New prohibition: AI for non-consensual intimate imagery / CSAM
2 Dec 2027
Annex III stand-alone high-risk AI system obligations (Digital Omnibus deferral)
2 Aug 2028
Annex I product-embedded high-risk AI system obligations (Digital Omnibus deferral)

Digital Omnibus: Parliament approved the amendments on 16 June 2026 and Council gave final green light on 29 June 2026. The revised high-risk dates (Annex III stand-alone to 2 December 2027, Annex I embedded to 2 August 2028) apply once the amending regulation is published in the Official Journal and enters into force. Note that Article 50 transparency obligations are not delayed and continue to apply from 2 August 2026.

The Problem

The regulation is in force. Most organisations aren't ready.

First, what's a "deployer"?

Under the EU AI Act, a deployer is any organisation that uses an AI system in its work — even one it didn't build. If your team uses Copilot, a customer chatbot, an AI-powered HR or recruitment tool, or marketing automation, you may be a deployer under the Act. At minimum, Article 4 AI-literacy duties may be relevant; further obligations depend on the system, use case, risk category and role. You don't have to be an "AI company" to be in scope — but what applies to you depends on how you use AI.

If your organisation uses AI in, sells into, operates in, or produces AI outputs used in the EU, you may already have EU AI Act obligations — across your HR tools, your Copilot subscription, your customer chatbot, your marketing automation.

Prohibited practices have applied since February 2025. Article 4 AI-literacy obligations also apply, with supervision and enforcement by national authorities beginning from August 2026; 2 August 2026 is the general application date for obligations not already applicable or subject to a specific transition period. AI Statute gives you a practitioner-built, article-referenced governance documentation base — professional-grade compliance documentation, not legal advice.

Important for non-EU organisations (UK, US and beyond)

Organisations outside the EU may be in scope where they place AI systems or GPAI models on the EU market, operate as deployers in the EU, or produce AI-system outputs used in the Union (Article 2). This commonly catches UK and US businesses serving EU customers or operating EU subsidiaries — geography outside the EU does not remove exposure where those scope tests are met.

The confidentiality dimension — Munir [2026] UKUT 81 (IAC)

In a judgment promulgated in November 2025, the UK Upper Tribunal made serious observations about putting confidential and privileged material into public, consumer-tier AI tools — distinguishing closed or enterprise-configured tools with contractual, technical and data-handling controls designed to reduce exposure. The case arose in legal services, but its reasoning is a warning by analogy for any organisation whose staff paste personal, confidential or commercially sensitive material into public AI tools. Policy alone is rarely enough in practice — it needs training, controls and evidence where work actually happens.

€35M
Up to €35M or 7% of worldwide turnover for the most serious breaches — capped at whichever is lower for SMEs and start-ups (Article 99)
Feb '25
Article 5 prohibited AI practices already enforceable. Article 4 AI literacy obligations already apply. Action required now.
Aug '26
General application date — Article 50 transparency duties apply; market-surveillance and supervision become central, subject to national implementation. High-risk duties deferred: Annex III stand-alone to Dec 2027, Annex I embedded to Aug 2028 (Digital Omnibus approved June 2026, pending Official Journal publication and entry into force)
EU AI Act Compliance Documentation

Eighteen assets across three layers. The core documentation base for deployer-side AI governance.

Eighteen article-referenced assets: a documentation layer of sixteen frameworks, a two-part Article 4 literacy layer, and Sentinel — an optional runtime governance control. Pre-populated with real content — not empty templates. Every asset in the pack is below.

Articles marked * (26, 27, 14, 25, 73) apply where an organisation deploys a high-risk AI system or meets a provider / value-chain trigger. For everyday productivity-tool use, these frameworks provide governance discipline and evidence structure.

Eighteen assets. Six questions.

You don't work through eighteen documents. In substance, AI governance means being able to answer six practical questions — and the pack is organised around them. Most organisations start with two or three assets, not all eighteen.

1

Who owns AI here?

Clear ground rules on what staff may and may not put into AI tools, and who approves new ones.

Governance Framework · Role Mapping Matrix · Acceptable Use Policy

2

What tools are actually being used?

A register of approved and prohibited tools, so shadow AI stops being invisible.

Tools Register · Vendor Due Diligence

3

What data is going into them?

Check where AI use touches personal data or people's rights — and evidence that you considered it.

Data Protection & AI Policy · DPIA · FRIA · Governance Checklist

4

Have staff been trained?

The AI-literacy training and records the Act expects, plus notices where AI use must be disclosed.

Literacy Programme · Training Deck · Training Record · Art. 50 Notices

5

What happens if it goes wrong?

Plain guidance for staff, and a route to follow when an AI-related incident happens.

Incident Reporting Procedure · Usage Guidelines · Sentinel

6

Can we evidence what we've done?

Keep it current as tools change, without reopening the whole exercise each time.

Annual Review · Decommissioning · Adoption Pack

Every asset below sits under one of these six. Each ships with an implementation guide.

Run these now

The Article 4 literacy duty has been live since February 2025, and your GDPR exposure from staff using public AI tools is live today. That's eight assets: Acceptable Use Policy · Employee Usage Guidelines · Tools Register · Role Mapping Matrix · Literacy Programme · Training Deck · Training Record · Data Protection & AI Policy.

Draw on the rest when triggered

Vendor due diligence when you procure. DPIA where GDPR high-risk processing arises. Article 50 notices if your AI use falls into the defined scenarios. FRIA and worker notification only where AI is used for Annex III employment purposes — recruitment, candidate selection, promotion, termination, task allocation, or performance monitoring. Under the Digital Omnibus timetable those apply from December 2027.

We'd rather tell you this than sell you urgency you don't have: most organisations will not use all eighteen assets on day one. You buy the library once, run the quick start now, and draw on the rest as procurement, HR, data-protection or higher-risk use cases arise — instead of buying a thin fix that's obsolete the moment a client asks the next question.

Policy

AI Acceptable Use Policy

Defines permitted and prohibited AI use across 28 scenarios. Supports deployer governance discipline.

Art. 4Art. 5Art. 26*Art. 50
Includes implementation guide
Guidelines

Employee AI Usage Guidelines

Function-specific guidance across six roles. Supports Article 4 literacy at the desk level.

Art. 4Art. 26*
Includes implementation guide
Register

Approved & Prohibited Tools Register

18 common AI tools pre-populated with illustrative risk flags, data-flow prompts and Article 50 screening questions. Validate current vendor terms before approval — classification remains client-specific.

Art. 26*Art. 50
Includes implementation guide
Procedure

AI Incident Reporting Procedure

P1–P4 severity matrix with timelines. Supports the deployer escalation route and provider / authority notification where applicable.

Art. 26(5)*Art. 73 provider interfaceGDPR Art. 33–34
Includes implementation guide
Policy

Data Protection & AI Policy

Reconciles GDPR and AI Act data-protection touchpoints. Connects AI governance with controls often handled in separate documents.

GDPR / UK GDPRAI Act interfaceEDPB 28/2024
Includes implementation guide
Audit Tool

EU AI Act Compliance Checklist

70-point operational review with provider / high-risk / GPAI escalation flags. RAG scoring summary — board-facing.

Deployer-FocusedBoard-ReadyAudit Trail
Includes implementation guide
Matrix

Role Mapping Matrix

AI risk mapped by role. Supports proportionate, role-calibrated literacy under Article 4.

Art. 4
Includes implementation guide
Assessment

Data Protection Impact Assessment

Screening plus template. Helps determine whether a GDPR DPIA, an Article 27 FRIA, or both are required — and supports completion.

Art. 27*GDPR Art. 35
Includes implementation guide
Templates

Worker Notification Letters

Workforce notification templates. Supports employer notification where high-risk AI is used in the workplace.

Art. 26(7)*
Includes implementation guide
Assessment

AI Vendor Due Diligence

Provider assessment pack. Supports proportionate vendor review and flags where provider-style obligations may arise.

Art. 26*Art. 16 / 25 interface
Includes implementation guide
Framework

AI Governance Framework

RACI, oversight committee structure, escalation routes. Supports human-oversight arrangements where high-risk systems require them.

Art. 26*Art. 14 interface
Includes implementation guide
Notices

Article 50 Transparency Notices

Provider direct-interaction and synthetic-content marking templates; deployer disclosures for emotion recognition, biometrics, deepfakes and public-interest AI text.

Art. 50 (role-specific)
Includes implementation guide
Procedure

Annual Review Procedure

Continuous-compliance review cycle. Supports proportionate, ongoing oversight beyond initial deployment.

Art. 26*Ongoing
Includes implementation guide
Procedure

AI System Decommissioning

Lifecycle exit controls. Supports deployer log retention and GDPR deletion duties at end-of-use.

Art. 26(6)*GDPR retention
Includes implementation guide
Playbook

Adoption Pack

Rollout playbook covering all frameworks. A sequenced 30/60/90-day implementation plan.

Cross-cutting
Includes implementation guide
Assessment

Fundamental Rights Impact Assessment

Structured FRIA template with Article 27 trigger test. Required only for specified deployers (public bodies, private providers of public services) and specified high-risk use cases; others may use it voluntarily as enhanced governance.

Art. 27*EU Charter
Includes implementation guide
Training · PPTX

AI Literacy Training Deck

PowerPoint deck plus trainer's guide. Supports Article 4 AI literacy with role-appropriate materials and completion records.

Art. 4Layer 2 · Literacy
Programme

AI Literacy Programme

Structured curriculum with assessment. Supports literacy at scale, with a completion register.

Art. 4Layer 2 · Literacy
Plus included
Implementation Guides

Step-by-step customisation and deployment guide for every framework in the pack. Delivered as a single companion document (AIS-IG-ALL).

Article 4 Self-Assessment

Free hosted webform — 10 questions, indicative governance-readiness profile in under 3 minutes. No download required. Take the assessment →

Layer 3 · Runtime (optional)
Sentinel
Awareness & evidence control · Governance event log

Sentinel is a configurable governance control for sanctioned enterprise AI workspaces — Claude for Work, ChatGPT Enterprise, Microsoft Copilot and enterprise-configured Google Gemini. It flags inputs that appear to contain personal, confidential or potentially privileged material, requires conscious confirmation before proceeding, and records a governance event log — a control layer aligned with the risk pattern highlighted by Munir. Delivered as a configured control your workspace admin deploys — no software installation. An awareness and evidence control — not DLP; it does not prevent data submission.

Self-Serve Licence — The Full Pack
2,250 + VAT
Charged in euro · UK & NI approx. £1,950 · Fixed-fee · Single-organisation licence · VAT calculated at checkout based on your location
Single organisation licence  ·  Instant download  ·  Word & PowerPoint
Compliance documentation and implementation guidance — not legal advice, certification or a guarantee of compliance.
Eighteen editable assets — sixteen compliance frameworks (including the Fundamental Rights Impact Assessment) plus the two-part literacy programme (Word / PowerPoint)
Implementation guides for every framework — step-by-step
18 illustrative tool-register entries with risk flags, data-flow prompts and vendor-term validation steps
70-item compliance checklist with RAG scoring summary
Single organisation licence agreement included
Article-referenced to Regulation 2024/1689 and informed by EDPB Opinion 28/2024 — reflecting the 2026 Digital Omnibus timeline (subject to final publication)
Partner-Delivered & White Label
From €3,750
Charged in euro · UK approx. £3,250 · Scoped delivery · Commercial licensing

Partner-Delivered: we run the scoping workshop, customisation, training delivery, optional Sentinel deployment and handover — scoped to the size of the business. For consultancies, chambers and firms, white-label licensing with commercial rebrand rights is available — terms negotiated on enquiry.

Enquire about Enterprise & White Label →
How It Works

Documentation in place in six steps. Your governance programme can begin the same day.

The documentation base is in place within hours of download; adoption, training and evidence build from there. Designed for operational teams to implement — each document comes with a step-by-step guide, with counsel review recommended for complex, high-risk or regulated deployments.

Download

Purchase and instantly download your pack — all eighteen assets: sixteen compliance frameworks, the two-part Article 4 literacy programme, implementation guides and the licence agreement. Everything opens in Microsoft Office.

Customise

Swap [ORGANISATION NAME] across all documents in one Find & Replace, then populate the fields each document requires — named individuals in governance and oversight roles, effective dates, and your specific tools and functions. Each implementation guide walks you through every field.

Assign Owners

Each document has a natural internal owner. The AI Acceptable Use Policy and Incident Procedure go to Legal or Compliance. The Employee Guidelines go to HR. The Tools Register goes to IT. The Data Protection Policy goes to your DPO or equivalent.

Deploy

Three documents go to your staff intranet or handbook. Where appropriate, publish a short AI transparency statement or privacy-notice insert on your public website — operational policies stay internal unless counsel or compliance decide otherwise. The Compliance Checklist goes to your Board or Audit Committee as evidence of an active governance programme.

📁 Internal — Staff intranet / handbook 🌐 Website — AI Policy & Privacy insert 📊 Board — Compliance Checklist

Evidence

Run the 70-item Compliance Checklist with your team. Each item has an Article reference, a priority rating and a RAG status. The scoring summary gives you an internal governance-readiness baseline you can present to investors, auditors or risk committees — structured evidence of an active governance process.

Review & Maintain

EU AI Act compliance is an ongoing obligation, not a one-time exercise. Review your documents when you onboard new AI tools, when your use of AI materially changes, and at minimum annually. Re-run the Compliance Checklist each cycle — an improving RAG score over time is evidence of a maturing governance programme, not just a point-in-time snapshot. AI Statute monitors implementation guidance and EDPB opinions; where material changes affect document content, updated versions are made available to licence holders.

Professional compliance documentation Practitioner-built governance infrastructure Article-referenced, board-facing, and priced for rapid adoption — the rigour of bespoke advisory work, without the bespoke engagement.
Who It's For

Built for any organisation deploying AI.

The EU AI Act may apply where an organisation provides, deploys, imports, distributes or uses AI systems in ways covered by Article 2 — including where AI-system outputs are used in the Union. If that could describe your organisation, this documentation is for you.

Compliance & Legal Teams

You need documentation that holds up to regulatory scrutiny — not generic templates with no article references. Every framework in this pack cites the specific legal basis it addresses.

Operations & HR Directors

Your organisation uses Copilot, ChatGPT, AI recruitment tools or automated workflows. You need policies your employees can follow, an approved tools register you can point to, and an incident procedure that works.

CEOs & Board Members

You need to demonstrate to investors, auditors or regulators that your organisation takes AI governance seriously. The 70-item checklist is designed to be presented directly to a board or audit committee.

PE-Backed Businesses

Portfolio companies face increasing AI governance scrutiny from investors and acquirers. AI Statute gives your portfolio the documentation infrastructure to evidence an active governance programme without expensive legal fees at every entity.

Consultants & Advisors

You advise organisations on governance and need credible AI documentation for client engagements. A White-Label Licence is available — contact us for commercial terms that allow you to rebrand and use with clients.

Any Organisation Using AI

If your AI use falls within Article 2 scope — placing systems on the EU market, deploying from an EU establishment, or producing outputs used in the Union — the EU AI Act applies. This documentation gives you a structured starting point for building and maintaining your AI governance evidence base.

Common Questions

Everything you need to know.

Didn't everything get pushed out to 2027?

Not everything — and this is the most common, and most costly, misunderstanding. The 2026 Digital Omnibus delayed the high-risk obligations: stand-alone high-risk systems move to 2 December 2027, and high-risk systems embedded in products to 2 August 2028. But two things were never deferred. Article 4 AI-literacy obligations have applied since 2 February 2025 — that duty is live now, and from August 2026 national authorities move into an active supervision and enforcement phase. And Article 50's role-specific transparency duties apply from 2 August 2026 in their defined scenarios — emotion recognition, biometric categorisation, deepfakes, certain synthetic media, or AI-generated text published to inform the public on matters of public interest. Being honest about the rest: if you don't deploy high-risk AI, that heavy machinery was never your immediate problem — but the literacy duty, and your GDPR exposure from staff using public AI tools, are live today. August is a grace period ending, not a deadline starting.

Will this really affect my business — and would we even get caught?

A fair challenge, and worth answering honestly. Not every organisation is affected equally: a business using no AI has little to worry about today. And no EU inspector is going to knock on your door on 3 August — enforcement is national and largely complaint-driven, not proactive inspection of small firms. But organisations are less likely to be caught by a regulator than by the market. A client's procurement team asks how you govern AI and there is no answer, so a tender is lost. An investor's due diligence asks. An employee complains. Or an AI tool goes wrong and the absence of governance becomes the story. Governance is inexpensive insurance against the moment someone asks — and increasingly, they ask. The free readiness check will tell you whether you have obvious gaps.

We're in the UK — is there a UK AI Act?

No. There is no UK AI Act. The UK regulates AI through existing law — principally UK GDPR and sector regulators such as the ICO — rather than a single AI statute. Two things still make this relevant to UK and Northern Ireland businesses. First, the EU AI Act has extraterritorial reach: if you sell into the EU, have EU customers, or your AI outputs are used in the Union, it can apply to you directly. Second, much of what good AI governance requires — documented policies, impact assessments, human oversight, transparency, incident handling — maps onto what UK GDPR and the ICO already expect. This is EU AI Act governance that also strengthens your UK data-protection position; it is not, and does not claim to be, compliance with a UK AI statute that does not exist.

Do I need a lawyer to use these frameworks?

These frameworks are designed for use directly by your compliance, HR, legal or operations team. Each comes with an implementation guide walking you through every placeholder and customisation step. For complex or high-risk AI deployments, review by qualified legal counsel is recommended — the frameworks are scoped as deployer-focused templates, not bespoke legal advice.

Will these documents protect my organisation from regulatory action?

No compliance documentation can guarantee immunity from enforcement — and any provider that claims otherwise should be treated with scepticism. Internal records of governance, staff training, incident procedures and a clear audit trail are likely to be important evidence if your AI governance is questioned. Having these frameworks implemented and reviewed is materially better — in any enforcement or due diligence scenario — than having nothing. The organisations most exposed are those who cannot produce anything when asked.

What format are the frameworks in?

Microsoft Word (.docx), fully editable — with the AI literacy training deck supplied as Microsoft PowerPoint (.pptx). Customise with your organisation name, dates and named roles. A single Find & Replace handles the most frequent placeholder in seconds. Implementation guides walk you through every field.

Does this apply to organisations outside the EU?

Often, yes. Non-EU organisations — including UK and US businesses — may be in scope where they place AI systems or GPAI models on the EU market, operate as deployers in the EU, or produce AI-system outputs used in the Union (Article 2 scope tests). Serving EU customers or running an EU subsidiary may be enough to bring an organisation within scope, depending on whether the relevant Article 2 test is met. Being based outside the EU does not remove that exposure.

Can I use this for multiple entities?

The standard licence covers a single legal entity. For group deployment across multiple subsidiaries or PE portfolio companies, contact us for a group licence. Volume pricing is available. The White-Label Licence includes commercial rights for client and portfolio company use.

What if the regulation changes?

AI Statute actively tracks the moving regulatory picture — including the 2026 Digital Omnibus amendments, EDPB opinions and national supervisory authority guidance. Where material changes affect framework content, updated versions are made available to licence holders.

How do payment and delivery work?

There are two routes. Card: purchase through Payhip with instant download on completion — EU and UK VAT is calculated and handled at checkout. Bank transfer or purchase order: many finance teams cannot put a purchase like this on a card, so email info@aistatute.eu with your company details and any PO reference. We issue an invoice the same day, payable by bank transfer or card, and release the files on receipt of payment. Either way this is a business-to-business licence for a digital product, so sales are final once delivered. For partner-delivered and white-label arrangements, pricing is agreed on a call.

Free Resource

Can you evidence Article 4 AI literacy?

Article 4 AI-literacy obligations have applied since February 2025, with supervision and enforcement beginning from August 2026. Answer 10 questions for an indicative AI-literacy readiness profile in under 3 minutes — free, instant, no commitment.

Take the free assessment →

10 questions · Under 3 minutes · Instant results

The next enforcement milestone is 2 August 2026.

Get your compliance documentation in place now — before a regulator, auditor or acquirer asks how AI is governed and documented in your organisation.

Get the AI Governance Pack — €2,250 + VAT

Need an invoice for bank transfer or a PO? Request one →
Issued same day. Files released on receipt of payment.

Instant download · Word & PowerPoint · Single organisation licence