The EU AI Act, plainly.
Where the Act actually bites, which obligations routeur.ai helps you meet, and which stay firmly your responsibility.
For most companies the immediate drivers are GDPR processor obligations, customer due diligence, and the Act's direction of travel — not Annex III. Here's what applies to whom.
The timeline, in plain English
The AI Act entered into force; obligations phase in over the following years.
Bans on unacceptable-risk practices (e.g. social scoring, certain biometric uses) began to apply.
Transparency and documentation duties for general-purpose AI models began to apply.
Article 50 duties apply — telling people when they're dealing with an AI system, and labelling AI-generated or manipulated media. Marking of synthetic content in systems already on the market is eased to 2 December 2026.
The bulk of high-risk system obligations (Annex III) — record-keeping, logging and human-oversight duties — deferred from 2 August 2026 by the 2026 Digital Omnibus. Systems built into regulated products (Annex I) follow from 2 August 2028.
Endorsed by the European Parliament and given final approval by the Council in June 2026, and signed in July, the Digital Omnibus defers the bulk of high-risk (Annex III) obligations from 2 August 2026 to 2 December 2027. The February 2025 prohibitions, the August 2025 general-purpose AI duties and the August 2026 transparency obligations are unchanged, and a new prohibition on AI-generated non-consensual intimate imagery and CSAM applies from 2 December 2026. The deferral takes legal effect once the amendment is published in the EU's Official Journal — expected in July 2026.
What maps to what
| Obligation | What routeur.ai provides | What stays your responsibility |
|---|---|---|
| Record-keeping & logging Art 12 | Per-request traces and a tamper-evident, append-only audit trail — provider, model, tokens, latency, cost, routing decision and policy verdict on every call. | Deciding which systems are high-risk, what must be logged for your use case, and how long you retain it. |
| Transparency | Visibility into which model handled each request and which policies fired, surfaced in the dashboard and audit trail. | Telling your own users when they're interacting with AI and providing required notices. |
| Human oversight | Policy enforcement, prompt shields, DLP and hard spend caps that can block or flag requests before they reach a provider. | Defining oversight processes, escalation paths and who reviews flagged activity. |
| Deployer duties incl. log retention Art 26 | Configurable audit-log retention (7 days Starter, 90 days Pro, extended on Enterprise) and per-request traces you can export to your own SIEM. | Classification, a Fundamental Rights Impact Assessment (FRIA) where required, vendor DPAs, and your retention policy. |
The EU AI Act interacts with GDPR and sector rules in ways that depend on your specific use case. Use it to frame a conversation with your own legal and compliance advisers — not as a substitute for one.
Get the readiness checklist
A one-page EU AI Act readiness checklist for AI-using companies: 12 yes/no items across visibility, policy, logging, vendor DPAs, data residency and incident response. Drop your work email and we'll unlock it.
Unlocked. Open the checklist below — use your browser's “Print → Save as PDF” to keep a copy.
Open the checklist →Not sure where your AI exposure is?
Start with a Shadow AI Assessment — we'll help you map where AI is already used across your business, what data flows through it, and which obligations that triggers. The fastest way to turn the Act from an abstract deadline into a concrete plan.
Request a Shadow AI Assessment →