← All posts
Compliance EU AI Act

EU AI Act High-Risk Deadline: August 2, 2026

If your AI system serves EU users and falls under Annex III, you have 9 days to meet conformity obligations. Fines start at €15M or 3% of global turnover.

· 6 min read
Aug 2
high-risk obligations in force
€35M
max fine or 7% global revenue
78%
of organizations unprepared

Most U.S. AI founders are watching the EU AI Act the way they watched GDPR in 2018 — "it doesn't apply to us." It does. The Act is extraterritorial. If your product is used in the EU, even by free-tier users, the high-risk rules apply.

The full enforcement date for high-risk AI systems is August 2, 2026. That's not the date to start thinking about compliance. That's the date the regulator can start asking for your risk management system, data governance documentation, and conformity assessment evidence.

Does This Actually Apply to You?

Annex III covers systems used in:

Translation for SaaS founders: if your AI is used for hiring, lending, insurance, education, health triage, or any biometrics — and you have users in the EU — you're probably in scope.

What "Compliance" Actually Means in 9 Days

You don't have to be perfect by August 2. You have to be defensible. The high-risk requirements break into four practical workstreams:

1. Risk Management System

You need documented identification, estimation, and mitigation of risks to health, safety, and fundamental rights. Not a slide deck — a living document tied to your system design.

2. Data Governance

Training, validation, and testing data must have appropriate governance practices, including bias testing and limitations documentation. If you fine-tune on customer data, this is where most founders get caught.

3. Technical Documentation

Conformity assessment requires records of architecture, capabilities, limitations, performance metrics, and known failure modes. This is essentially a security audit dressed in regulatory language.

4. Human Oversight & Transparency

Natural persons must be able to override the system. Users must be informed they're interacting with AI. High-risk outputs must include clear disclosures.

The GaleOps 9-Day Sprint

I run a small AI security consultancy. We don't write legal opinions, but we can produce the technical evidence compliance teams actually need. Here's the sprint:

After the sprint, most teams need continuous monitoring. Our $2,500/month retainer covers monthly regression testing, guardrail drift checks, and updated technical documentation as your models and integrations change.

9 days. One decision.

Get the 24-hour snapshot first. It's $149. You'll know exactly where you stand before you spend a dollar on the bigger audit.

Get the $149 Snapshot (24h) See All Services

What to Do Right Now

  1. Confirm whether your product touches any Annex III use case.
  2. Document your current risk management and data governance practices — even if rough.
  3. Get a technical audit that produces evidence, not just opinions.
  4. Talk to your legal/compliance team with the audit in hand, not empty.

The companies that get ahead of this won't be the ones with the biggest legal budgets. They'll be the ones with the best technical evidence.

Mathew Gale
AI Security & Automation — GaleOps