EU AI Act

EU AI Act readiness, built into the platform.

The legally binding date for high-risk obligations is 2 August 2026 — and the Digital Omnibus deferral to December 2027 is not yet law. The real question for AI teams is not "when" but "what must we prove": classification, logging, human oversight, and technical documentation. NeuroCluster generates that evidence as a by-product of running your workflows.

The timeline — and what the Digital Omnibus changes

The AI Act entered into force in August 2024. Prohibitions applied from February 2025, GPAI model obligations from August 2025, and many Annex III high-risk obligations were scheduled for 2 August 2026.

In May 2026 the Council and European Parliament reached a provisional political agreement — the Digital Omnibus — to defer the high-risk dates to 2 December 2027 (stand-alone Annex III systems) and 2 August 2028 (product-embedded). That agreement still requires formal adoption and publication in the Official Journal. Until then, 2 August 2026 remains the binding date, and the Omnibus changes timing, not substance: the classification, logging, oversight, and documentation requirements stay the same.

Practically, this means the organizations that treat the deferral as extra runway to build compliant infrastructure will be ready either way — and the ones that treat it as a reason to pause will repeat the same scramble a year later.

Provider vs deployer: which obligations are yours

Most enterprises are deployers, not providers: you use AI systems under your own authority rather than placing them on the market. Deployer obligations under Article 26 include using systems per the provider's instructions, assigning competent human oversight, ensuring input data is relevant, monitoring operation, and retaining automatically generated logs.

The trap is that fine-tuning a model or substantially modifying a high-risk system can shift you into provider territory — with conformity assessment, technical documentation, and CE-marking obligations. Classification of each use case, before production, is where compliance work actually starts.

How NeuroCluster maps to AI Act requirements

NeuroCluster is not a compliance document generator bolted onto someone else's model API. The controls the Act asks for are properties of the runtime itself:

  • Logging (Art. 12/26): every agent action, model call, retrieval, and tool invocation is recorded deterministically — logs exist because the platform cannot act without producing them.
  • Human oversight (Art. 14/26): policy gates require named human approval before high-risk actions execute; approvals are recorded with identity and timestamp.
  • Technical documentation (Art. 11): deployment snapshots capture model versions, prompts, policies, and data sources per workflow — exportable as an evidence pack.
  • Risk management (Art. 9): use-case-scoped policies, classification-aware retrieval, and tenant isolation bound what a system can reach, so risk analysis maps to enforced controls rather than intentions.
  • Data governance (Art. 10): governed data access with row-level policies and lineage from output back to source.

Evidence packs: what you hand the auditor

When an internal auditor, regulator, or procurement reviewer asks "prove your AI system operates under control", NeuroCluster exports an evidence pack: the deployment snapshot, the policies in force, the approval history, and the complete action log for the period under review.

This is the difference between compliance as a quarterly documentation project and compliance as a property of infrastructure. Teams running on general-purpose cloud AI APIs reconstruct this evidence manually; teams on NeuroCluster export it.

The EU AI Act readiness checklist

A 40-point, print-ready checklist covering classification, deployer obligations, logging, human oversight, technical documentation, and vendor evidence — the working document our assessment starts from.

Frequently asked questions

Does the Digital Omnibus mean we can wait until 2027?

No. The deferral is a provisional political agreement, not law — until it is published in the Official Journal, 2 August 2026 remains the binding date for high-risk obligations. And the deferral changes deadlines, not requirements: classification, logging, human oversight, and documentation work takes months and should not wait.

Are we a provider or a deployer under the AI Act?

If you use AI systems under your own authority you are typically a deployer (Article 26 obligations). If you develop a system, place it on the market, or substantially modify a high-risk system — including some fine-tuning scenarios — you can take on provider obligations. Classify each use case with legal and compliance before production.

Which enterprise AI use cases count as high-risk?

Annex III covers, among others: AI in critical infrastructure operation, employment and worker management (CV screening, performance evaluation), access to essential services (creditworthiness, insurance pricing), education, and law enforcement. If a system influences decisions about people's access to jobs, credit, or services, treat it as a high-risk candidate until classified otherwise.

Does using NeuroCluster make us AI Act compliant?

No platform can make you compliant by itself — compliance depends on your use cases, classification, and processes. What NeuroCluster does is make the technical controls the Act requires (logging, human oversight, documentation, data governance) native properties of the runtime, and export the evidence reviewers ask for.

How do we start?

A 30-minute readiness assessment: we map your intended use cases against the Act's risk categories, identify which obligations apply, and show how the required evidence would be generated on your infrastructure.

Keep evaluating

Start with one operational problem.

You do not need a finished brief. Bring the problem — we will work out the next step together.

Or book a call with the team