AI Governance Desk

Which EU AI Act rules actually apply to you?

Ten questions. No signup, no email, nothing stored. You get a plain-English list of the obligations that apply to your business and the dates they bite.

Regulatory content verified 29 July 2026, including the Digital Omnibus changes. Runs entirely in your browser — no answers leave your device.

Your results

The documents that make this real

Knowing what applies is step one. The evidence a regulator or an enterprise customer asks for is step two — and that is written work.

The AI Governance Starter Kit is 13 editable documents built for companies of 5–200 people, not for enterprises with a compliance department:

  • AI Acceptable Use Policy, ready to circulate
  • Article 50 disclosure notices — the actual wording for chatbots and media
  • AI system inventory and risk register
  • Prohibited-practices and high-risk screening worksheets
  • 45-minute AI literacy training plan and attendance log
  • Vendor assessment and incident response procedures
  • Customer due-diligence answer bank — pre-written answers to the AI questions in enterprise security questionnaires
$89 one-off · 12 months of updates included

Comparable ISO 42001 toolkits start at $199. Governance platforms start around $10,000 a year.

Get the kit — $89

This is not legal advice. This tool gives a general indication based on your answers, not a legal opinion on your specific circumstances. It cannot see your systems or your contracts. If you are in a regulated sector, use AI in hiring or lending, or have heard from a regulator, speak to a qualified lawyer in your jurisdiction.

The dates, in one table

DateWhat appliesStatus
2 Feb 2025Prohibited practices (Art. 5) and AI literacy (Art. 4)In force now
2 Aug 2025General-purpose AI model obligations; penalties enforceableIn force now
2 Aug 2026Transparency obligations (Art. 50)Imminent
2 Dec 2026Watermarking grace period ends for pre-existing systemsUpcoming
2 Dec 2027High-risk standalone systems (Annex III)Postponed from Aug 2026
2 Aug 2028High-risk AI embedded in regulated products (Annex I)Postponed from Aug 2027

The Digital Omnibus, provisionally agreed on 6 May 2026, postponed the high-risk tiers and softened the AI literacy duty. It takes legal effect only on publication in the Official Journal — until then the original schedule remains operative. Article 50 was not postponed.

Read the full breakdown: what actually applies on 2 August 2026 →

Questions people actually ask

We're not in the EU. Does this apply to us?

Possibly. The Act reaches you if you place an AI system on the EU market or if the output of your AI system is used in the EU. A US company with EU customers using its AI-powered product can be in scope.

We just use ChatGPT and a few tools. Is that regulated?

You are a deployer, which is the lighter category. Your realistic duties are AI literacy for staff, avoiding prohibited uses, and transparency if you run a chatbot or publish AI content. That is a manageable list, and being able to show you have covered it is increasingly what enterprise customers ask for.

What happens if we do nothing?

Penalties run up to EUR 35m or 7% of global turnover for prohibited practices, and up to EUR 15m or 3% for most other breaches, with SMEs facing the lower of the pairing. In practice the more immediate cost for most small companies is commercial: enterprise buyers now send AI questions in procurement, and a blank answer stalls the deal.

Isn't the whole thing delayed?

Partly, and this is widely misreported. The high-risk obligations moved to December 2027. The transparency obligations in Article 50 did not move — they apply from 2 August 2026. Prohibitions and AI literacy have been in force since February 2025.

Do you store my answers?

No. There is no analytics, no cookie, no form submission and no server. The questions run in your browser; close the tab and it is gone.