The EU AI Act: technical requirements for companies running production AI.
The EU AI Act has been in force since August 2024. The binding requirements take effect in stages. From 2 August 2026, the transparency obligations under Art. 50 apply; the comprehensive high-risk obligations were postponed via the AI Omnibus to December 2027 (Annex III) and August 2028 (Annex I) respectively. Companies operating AI systems in regulated domains face a concrete documentation task: making the technical infrastructure integrity of their systems demonstrable.
This page explains the technical requirements of the EU AI Act, the timeline, and the infrastructure implications for IT leaders, compliance teams and decision-makers.
This page serves technical orientation purposes. For an assessment of regulatory obligations in a specific case, consult qualified legal and compliance advisors.
Risk-based approach in four tiers
The EU AI Act assesses AI systems according to their risk class. The classification determines the scope of the requirements.
Unacceptable risk
AI systems that endanger fundamental rights. Complete ban. Covers social scoring by state actors, manipulative systems and real-time biometric remote identification in public spaces.
High risk (Annex III)
AI systems in regulated domains with potentially significant impact on health, safety or fundamental rights. Extensive documentation, transparency and testing obligations. The use case relevant to most companies.
Limited risk
AI systems with specific transparency obligations. Chatbots and generative systems interacting with natural persons must disclose their AI nature.
Minimal risk
AI systems without special regulatory requirements. Voluntary codes of conduct recommended.
Which systems count as high risk
Annex III of the EU AI Act lists the use cases in which AI systems are classified as high risk. Eight areas. Clear boundaries. The classification applies regardless of company size.
Systems for the remote identification of natural persons.
AI in the management and operation of critical infrastructure in energy, water, transport and digital infrastructure.
Systems that decide access to educational institutions or the assessment of exam performance.
Systems for candidate selection, promotion decisions and performance monitoring.
Credit scoring, creditworthiness assessment, risk classification in insurance.
Systems for crime prediction, witness evaluation and evidence assessment.
Systems for risk assessment of individuals and document verification.
Systems supporting judicial decisions and influencing political processes.
Companies that operate AI systems in one of these areas, or act as suppliers within a corresponding supply chain, fall within the scope of the high-risk requirements.
Transparency obligations — technically anchored, enforced from August 2026
Art. 50 EU AI Act requires that AI use be disclosed and AI-generated content be marked in a machine-readable way. These obligations directly affect the infrastructure layer on which AI systems deliver content and prove its provenance — and they apply from 2 August 2026.
Machine-readable labeling (providers only)
Art. 50(2) requires providers of generative AI systems (whoever develops a system or offers it under their own brand, including white-label) to mark AI-generated content as artificially generated in a machine-readable format. Deployers using third-party AI tools are instead subject to Art. 50(4). For providers, the infrastructure layer forms the basis for this verifiable labeling.
Traceable provenance
The origin and authenticity of the labeling must be verifiable. Machine-readable declarations and cryptographically anchored provenance are components of the transparency documentation.
Disclosure of AI use
AI systems that interact with natural persons or generate content must clearly disclose the AI use. DNS configuration, cryptographic signature infrastructure and access configuration for automated systems are audit-relevant parameters.
Documentation obligation
Fulfilment of the Art. 50 requirements must be documented. Audits and conformity assessments require a structured evidence document.
From 2 August 2026, the transparency obligations under Art. 50 apply; the EU Commission gains enforcement powers over GPAI providers, while national market surveillance in Germany is still being built up via the KI-MIG (draft bill: BNetzA). The fine framework of the EU AI Act (Art. 99) provides for sanctions of up to 15 million euros or 3 percent of global annual turnover for breaches of the high-risk requirements or the Art. 50 transparency obligations, whichever is higher. The higher framework of 35 million euros or 7 percent applies exclusively to breaches of the prohibited practices under Art. 5.
The enforcement phases at a glance
The regulation becomes binding EU law.
AI systems of the highest risk class are prohibited from this date.
Requirements for general-purpose AI models take effect. Obligations for providers of foundation models.
The transparency obligations under Art. 50 apply from 2 August 2026. At the same time, the EU Commission gains enforcement powers over providers of general-purpose AI models (GPAI). National market surveillance in Germany is still being built up via the KI-MIG (draft bill: BNetzA).
Postponed to 2 December 2027 via the AI Omnibus (Council, 29 June 2026): requirements for high-risk AI systems under Annex III take effect.
Postponed to 2 August 2028 via the AI Omnibus: requirements for AI systems in certain product categories (safety components, Annex I) take effect.
What Art. 50 means technically
The requirements of Art. 50 EU AI Act are anchored at the infrastructure layer. The question an auditor asks is: is the technical foundation of the AI system transparent, machine-readably labeled and verifiably documented? This question touches four concrete infrastructure areas.
DNS and cryptographic base integrity
DNSSEC, CAA records, TLS certificate chain and HTTP security headers form the base layer. Gaps at this layer are directly visible in an audit.
Machine-readable data source declaration
AI systems that use external data sources need a verifiable declaration of these sources. Machine-readable AI discovery files and structured data form the technical basis.
Privacy & consent
The consistency between declared crawler configuration and actual infrastructure response is an audit-relevant parameter. Opt-in and opt-out declarations for AI systems must be technically correctly implemented.
AI governance hard gate
AI policy URL, deepfake disclaimer, AI training opt-out status and a named contact point for AI inquiries are machine-readably verifiable and part of the conformity documentation.
CERTavia checks all four areas in a deterministic process and delivers the structured evidence document for compliance documentation.
Three requirement frameworks, one infrastructure layer
Many companies operate simultaneously under the requirements of the EU AI Act, the NIS2 directive and the DORA regulation. All three frameworks address the same infrastructure layer. One evidence document. Three requirements.
NIS2 sets requirements for the cybersecurity of critical infrastructure and digital services. The technical security requirements overlap at the infrastructure layer with the Art. 50 transparency requirements for AI systems.
DORA defines requirements for the digital operational resilience of financial entities. Infrastructure integrity and documentation obligations for ICT systems touch the same technical layer as Art. 50 EU AI Act.
CERTavia addresses the infrastructure layer where all three requirement frameworks become technically verifiable. In the Enterprise package, CERTavia bundles the Layer-0 evidence as consolidated infrastructure evidence with Art. 50 relevance and mapping to NIS2- and DORA-relevant signals — not DORA reporting in the sense of incident reports or the Register of Information.
Further reading
The high-risk categories and technical requirements explained in detail.
NIS2 and DORA overlaps →Where the EU AI Act, NIS2 and DORA meet at the same infrastructure layer.
EU AI Act quick test: assess Annex III risk in two minutes →Questions and answers to assess your own risk class.
How CERTavia works →The deterministic testing process and validation procedure explained.
Art. 50 EU AI Act requires machine-readable transparency evidence. CERTavia delivers it.
In 90 seconds, cryptographically signed, attachable as an exhibit to the Conformity Assessment Dossier — no call, no form.
Scan your domain now Art. 50 evidence in detail →Questions about EU AI Act infrastructure evidence
Is this an official certification?
No. CERTavia does not issue an officially recognized certificate. The result is a technical infrastructure evidence document — cryptographically signed, deterministic, machine-readable. Official conformity assessments under Art. 43 build on such technical evidence. More in the glossary →
Who recognizes this evidence?
The SOVP evidence is designed as technical proof for internal compliance teams, external auditors and clients. The Sovereign Validation Protocol has been submitted as an IETF Draft. The evidence is DNS-anchored and cryptographically signed — any party can independently verify authenticity and timing.
How long is a report legally usable?
The SOVP evidence documents the infrastructure state at the time of the scan with a cryptographic timestamp. For EU AI Act audits under Art. 50, compliance is an ongoing obligation — not a one-time proof. We recommend re-scans at least annually and after substantial infrastructure changes. Full Scan Pro with the Sovereign Vault, permanently retrievable via token, is recommended for audit dossiers.
What is the difference from a pentest or ISO 27001?
Pentest: active, manual vulnerability search. SOVP checks the infrastructure configuration passively and deterministically in 90 seconds — reproducible and auditable. ISO 27001: comprehensive management system. CERTavia delivers the machine-readable infrastructure evidence for Art. 50 EU AI Act — the two are not mutually exclusive and can be combined.
Know your infrastructure status
Quick Scan – free
The free Quick Scan delivers the Layer-0 result of your domain in 90 to 120 seconds. No form, no registration.
Scan your domain now – freeEnterprise & custom requirements
For complex organizational structures or custom documentation requirements, the contact form is available.
Get in touchThis page serves technical orientation purposes and does not constitute legal advice. The description of the EU AI Act reflects the state of knowledge at the time of publication. Regulatory requirements continue to evolve. The assessment of specific obligations in individual cases is the responsibility of qualified legal and compliance advisors. CERTavia delivers technical infrastructure validation based on the Sovereign Validation Protocol (SOVP, Patent Pending No. 64/005,737).