The EU AI Act is the world's first comprehensive AI law — and it is already in force. For regulated European organisations, readiness is now a board-level obligation, not a future project. OneCompliant™ gets you from "we're not sure where we stand" to a defensible, evidenced position in weeks.
The Act reaches far beyond AI developers. It applies to providers that build or brand AI systems and to deployers that use them — including organisations that simply adopt third-party AI tools. It applies to organisations outside the EU whenever their AI output is used inside it. In practice, that means most mid-market and enterprise organisations operating in Europe today.
You develop, brand, or place an AI system on the EU market — including AI you build on top of a foundation model.
You use an AI system in the course of business. Most obligations that surprise organisations sit here.
The Act applies whenever your AI's output is used within the EU, regardless of where you are based.
The first step to readiness is knowing which of your AI systems fall into which tier — because that determines what you must do. Most organisations have never classified their AI this way, and most underestimate how much of it is high-risk.
Practices such as social scoring and manipulative AI are banned outright. Already in force.
AI in areas like employment, credit, critical infrastructure, and safety. This is where the real work sits.
Chatbots and generated content must be disclosed to the people interacting with them.
Most everyday AI. Low regulatory burden — but you still need to prove it belongs here.
General-purpose AI models — the foundation models many tools are built on — carry their own dedicated obligations on top of this.
The Act came into force in August 2024 and applies in phases. Here's what applies today — and what's ahead after the 2026 Digital Omnibus moved the high-risk deadlines to fixed later dates.
Beyond the dates, compliance is not a one-off deadline. Because AI systems change continuously, it becomes an operating loop — which is exactly where AYJIS lives:
The dates may have moved. The work did not disappear. Organisations still need the inventory, governance, controls, documentation, and evidence required to meet those obligations.
Applicability depends on whether the organisation acts as a provider, deployer, importer, distributor, authorised representative, or product manufacturer, and on the classification and intended purpose of each AI system. OneCompliant supports compliance readiness and operational control implementation — it does not, on its own, guarantee legal compliance.
Not a timeline to admire — a set of obligations, each with a concrete answer.
| EU AI Act requirement | OneCompliant |
|---|---|
| AI inventory (discover shadow AI) | OASAT |
| Risk assessment & classification | OASAT |
| Governance & controls | OASF |
| Runtime controls & human oversight | AYJIS |
| AI security & data protection | AYJIS |
| Audit evidence & logging | AYJIS |
| Executive & board reporting | OneCompliant dashboard |
Non-compliance is not a paperwork risk. The Act's fines are tiered to the severity of the breach and calculated against global turnover.
Up to €35 million or 7% of worldwide annual turnover for breaching the prohibitions on banned AI practices.
Up to €15 million or 3% of worldwide annual turnover for non-compliance with most other obligations, including those for high-risk systems.
Up to €7.5 million or 1% of turnover for supplying incorrect or misleading information to authorities.
Beyond fines, the real cost is commercial: audits you cannot pass, tenders you cannot win, and insurers who cannot price your risk. Readiness protects revenue, not just compliance.
For high-risk AI, the Act expects concrete, operational capabilities. This is the checklist auditors and customers will hold you to.
Large vendors sell you a platform and a multi-year programme. OneCompliant gives you a defined path to readiness that produces evidence at every step — built and deployed by people who have run security in regulated enterprises.
A fixed-price assessment inventories your AI, classifies it against the Act, and delivers a prioritised gap analysis and roadmap — in about two weeks.
A control framework mapped directly to EU AI Act articles — turning obligations into policies, roles, and rules your organisation actually operates.
Runtime enforcement and human oversight where AI is actually used — inspecting, controlling, and logging every governed interaction as it happens.
Audit-ready records and control mappings that prove readiness to regulators, customers, and insurers — the evidence the Act requires.
Start with a fixed-price assessment and get a clear, prioritised readiness roadmap in weeks. You'll work directly with the team that built the platform and deployed it in production.