The EU AI Act became enforceable on 2 August 2026. Articles 10–15 apply to most high-risk AI systems from 2 December 2027, giving enterprises a short window of 16 months to implement the required controls.
These requirements cover data governance, technical documentation, record keeping, transparency, human oversight, accuracy, robustness, and cybersecurity. Compliance depends on whether enterprises can show how AI systems access data, make decisions, take action, and remain governed throughout operation.
Which AI systems are affected?
The strongest obligations apply to high-risk AI systems. In practice, that can capture a significant share of enterprise AI, particularly where systems support employment, education, credit, essential services, critical infrastructure, biometrics, law enforcement, migration, or justice.
Enterprises should assess AI systems across the full portfolio, including internal tools and operational workflows, to determine where these criteria may apply and what data, models, agents, and connected services each system relies on.
What does the EU AI Act require?
Articles 10–15 require enterprises to:
- Govern the data used by AI systems
- Maintain current technical documentation
- Record relevant events throughout operation
- Provide clear information on system use, risks, and limitations
- Enable effective human oversight
- Maintain appropriate accuracy, robustness, and cybersecurity
How to prepare for EU AI Act compliance
Govern access to enterprise data
Control which information an AI system can retrieve based on purpose, sensitivity, consent, relationships, delegated authority, and runtime context. Learn more about governing data access.
Establish trusted data and provenance
Maintain evidence of where data came from, how it changed, whether it remains suitable, and which information influenced a decision or action. Learn more about capturing trust indicators and provenance.
Evaluate authorization throughout execution
Reassess authority as AI systems retrieve data, invoke tools, delegate work, and interact with other systems. Learn more about AI governance.
Apply context-aware policy enforcement
Use live signals such as identity, purpose, data sensitivity, consent, risk, and previous workflow activity to govern each action. Learn more about context driven control.
Create decision traceability
Record who initiated the workflow, which systems participated, what data was accessed, which policies were evaluated, and which actions followed. Learn more about decision traceability.
EU AI Act compliance checklist
- Identify systems that may be classified as high risk
- Map their data sources, models, tools, and agents
- Assess current controls against Articles 10–15
Use IndyKite to:
- Establish provenance and trusted data practices
- Implement contextual access and action controls
- Record decisions and workflow activity
- Test whether compliance evidence can be produced on demand
Start preparing now
Implementing these capabilities across enterprise architecture takes time. Systems already in production or approaching deployment should be assessed first, particularly where they access sensitive data, perform high-impact tasks, or operate across multiple tools and services.
Download The Enterprise Guide to EU AI Act Compliance for a detailed breakdown of the requirements and the technical capabilities enterprises need before December 2027.








