Regulatory

The EU AI Act: technical requirements for companies running production AI.

The EU AI Act has been in force since August 2024. The binding requirements take effect in stages. From 2 August 2026, the transparency obligations under Art. 50 apply; the comprehensive high-risk obligations were postponed via the AI Omnibus to December 2027 (Annex III) and August 2028 (Annex I) respectively. Companies operating AI systems in regulated domains face a concrete documentation task: making the technical infrastructure integrity of their systems demonstrable.

This page explains the technical requirements of the EU AI Act, the timeline, and the infrastructure implications for IT leaders, compliance teams and decision-makers.

This page serves technical orientation purposes. For an assessment of regulatory obligations in a specific case, consult qualified legal and compliance advisors.

Layer architecture — golden data foundation with transparent AI processing layers
Basic structure

Risk-based approach in four tiers

The EU AI Act assesses AI systems according to their risk class. The classification determines the scope of the requirements.

Unacceptable risk

AI systems that endanger fundamental rights. Complete ban. Covers social scoring by state actors, manipulative systems and real-time biometric remote identification in public spaces.

High risk (Annex III)

AI systems in regulated domains with potentially significant impact on health, safety or fundamental rights. Extensive documentation, transparency and testing obligations. The use case relevant to most companies.

Limited risk

AI systems with specific transparency obligations. Chatbots and generative systems interacting with natural persons must disclose their AI nature.

Minimal risk

AI systems without special regulatory requirements. Voluntary codes of conduct recommended.

Annex III

Which systems count as high risk

Annex III of the EU AI Act lists the use cases in which AI systems are classified as high risk. Eight areas. Clear boundaries. The classification applies regardless of company size.

No. 1
Biometric identification

Systems for the remote identification of natural persons.

No. 2
Critical infrastructure

AI in the management and operation of critical infrastructure in energy, water, transport and digital infrastructure.

No. 3
Education and vocational training

Systems that decide access to educational institutions or the assessment of exam performance.

No. 4
Employment and personnel management

Systems for candidate selection, promotion decisions and performance monitoring.

No. 5
Essential private services

Credit scoring, creditworthiness assessment, risk classification in insurance.

No. 6
Law enforcement

Systems for crime prediction, witness evaluation and evidence assessment.

No. 7
Migration and border control

Systems for risk assessment of individuals and document verification.

No. 8
Justice and democratic processes

Systems supporting judicial decisions and influencing political processes.

Companies that operate AI systems in one of these areas, or act as suppliers within a corresponding supply chain, fall within the scope of the high-risk requirements.

Art. 50

Transparency obligations — technically anchored, enforced from August 2026

Art. 50 EU AI Act requires that AI use be disclosed and AI-generated content be marked in a machine-readable way. These obligations directly affect the infrastructure layer on which AI systems deliver content and prove its provenance — and they apply from 2 August 2026.

Machine-readable labeling (providers only)

Art. 50(2) requires providers of generative AI systems (whoever develops a system or offers it under their own brand, including white-label) to mark AI-generated content as artificially generated in a machine-readable format. Deployers using third-party AI tools are instead subject to Art. 50(4). For providers, the infrastructure layer forms the basis for this verifiable labeling.

Traceable provenance

The origin and authenticity of the labeling must be verifiable. Machine-readable declarations and cryptographically anchored provenance are components of the transparency documentation.

Disclosure of AI use

AI systems that interact with natural persons or generate content must clearly disclose the AI use. DNS configuration, cryptographic signature infrastructure and access configuration for automated systems are audit-relevant parameters.

Documentation obligation

Fulfilment of the Art. 50 requirements must be documented. Audits and conformity assessments require a structured evidence document.

From 2 August 2026, the transparency obligations under Art. 50 apply; the EU Commission gains enforcement powers over GPAI providers, while national market surveillance in Germany is still being built up via the KI-MIG (draft bill: BNetzA). The fine framework of the EU AI Act (Art. 99) provides for sanctions of up to 15 million euros or 3 percent of global annual turnover for breaches of the high-risk requirements or the Art. 50 transparency obligations, whichever is higher. The higher framework of 35 million euros or 7 percent applies exclusively to breaches of the prohibited practices under Art. 5.

The timeline

The enforcement phases at a glance

Aug. 2024
EU AI Act enters into force

The regulation becomes binding EU law.

Feb. 2025
Ban on unacceptable risks

AI systems of the highest risk class are prohibited from this date.

Aug. 2025
GPAI requirements

Requirements for general-purpose AI models take effect. Obligations for providers of foundation models.

Aug. 2026
Art. 50 transparency obligations apply

The transparency obligations under Art. 50 apply from 2 August 2026. At the same time, the EU Commission gains enforcement powers over providers of general-purpose AI models (GPAI). National market surveillance in Germany is still being built up via the KI-MIG (draft bill: BNetzA).

Dec. 2027
High-risk obligations (Annex III)

Postponed to 2 December 2027 via the AI Omnibus (Council, 29 June 2026): requirements for high-risk AI systems under Annex III take effect.

Aug. 2028
Product categories (Annex I)

Postponed to 2 August 2028 via the AI Omnibus: requirements for AI systems in certain product categories (safety components, Annex I) take effect.

The infrastructure implication

What Art. 50 means technically

The requirements of Art. 50 EU AI Act are anchored at the infrastructure layer. The question an auditor asks is: is the technical foundation of the AI system transparent, machine-readably labeled and verifiably documented? This question touches four concrete infrastructure areas.

DNS and cryptographic base integrity

DNSSEC, CAA records, TLS certificate chain and HTTP security headers form the base layer. Gaps at this layer are directly visible in an audit.

Machine-readable data source declaration

AI systems that use external data sources need a verifiable declaration of these sources. Machine-readable AI discovery files and structured data form the technical basis.

Privacy & consent

The consistency between declared crawler configuration and actual infrastructure response is an audit-relevant parameter. Opt-in and opt-out declarations for AI systems must be technically correctly implemented.

AI governance hard gate

AI policy URL, deepfake disclaimer, AI training opt-out status and a named contact point for AI inquiries are machine-readably verifiable and part of the conformity documentation.

CERTavia checks all four areas in a deterministic process and delivers the structured evidence document for compliance documentation.

NIS2 and DORA

Three requirement frameworks, one infrastructure layer

Many companies operate simultaneously under the requirements of the EU AI Act, the NIS2 directive and the DORA regulation. All three frameworks address the same infrastructure layer. One evidence document. Three requirements.

NIS2 sets requirements for the cybersecurity of critical infrastructure and digital services. The technical security requirements overlap at the infrastructure layer with the Art. 50 transparency requirements for AI systems.

DORA defines requirements for the digital operational resilience of financial entities. Infrastructure integrity and documentation obligations for ICT systems touch the same technical layer as Art. 50 EU AI Act.

CERTavia addresses the infrastructure layer where all three requirement frameworks become technically verifiable. In the Enterprise package, CERTavia bundles the Layer-0 evidence as consolidated infrastructure evidence with Art. 50 relevance and mapping to NIS2- and DORA-relevant signals — not DORA reporting in the sense of incident reports or the Register of Information.

From obligation to evidence

Art. 50 EU AI Act requires machine-readable transparency evidence. CERTavia delivers it.

In 90 seconds, cryptographically signed, attachable as an exhibit to the Conformity Assessment Dossier — no call, no form.

Scan your domain now Art. 50 evidence in detail →
Frequently asked questions

Questions about EU AI Act infrastructure evidence

Is this an official certification?

No. CERTavia does not issue an officially recognized certificate. The result is a technical infrastructure evidence document — cryptographically signed, deterministic, machine-readable. Official conformity assessments under Art. 43 build on such technical evidence. More in the glossary →

Who recognizes this evidence?

The SOVP evidence is designed as technical proof for internal compliance teams, external auditors and clients. The Sovereign Validation Protocol has been submitted as an IETF Draft. The evidence is DNS-anchored and cryptographically signed — any party can independently verify authenticity and timing.

How long is a report legally usable?

The SOVP evidence documents the infrastructure state at the time of the scan with a cryptographic timestamp. For EU AI Act audits under Art. 50, compliance is an ongoing obligation — not a one-time proof. We recommend re-scans at least annually and after substantial infrastructure changes. Full Scan Pro with the Sovereign Vault, permanently retrievable via token, is recommended for audit dossiers.

What is the difference from a pentest or ISO 27001?

Pentest: active, manual vulnerability search. SOVP checks the infrastructure configuration passively and deterministically in 90 seconds — reproducible and auditable. ISO 27001: comprehensive management system. CERTavia delivers the machine-readable infrastructure evidence for Art. 50 EU AI Act — the two are not mutually exclusive and can be combined.

Know your infrastructure status

Know your infrastructure status

Quick Scan – free

The free Quick Scan delivers the Layer-0 result of your domain in 90 to 120 seconds. No form, no registration.

Scan your domain now – free

Enterprise & custom requirements

For complex organizational structures or custom documentation requirements, the contact form is available.

Get in touch