EU AI Act · Timeline updated May 2026
THE DEADLINE
MOVED. MOST
VENDORS HAVEN'T
NOTICED.
The EU's Digital Omnibus pushed the high-risk deadline to Dec 2027 — but transparency obligations still land Dec 2, 2026. A 3-week fixed-scope audit tells you what actually applies to you, on the actual dates.
WHAT ACTUALLY CHANGED
In May 2026, the EU's Digital Omnibus agreement pushed back two of the Act's biggest deadlines: high-risk obligations for use-based systems (Annex III — anything touching employment, credit, education, essential services) now land December 2, 2027, not August 2026. High-risk product-embedded systems (Annex I) move to August 2028.
What didn't move: transparency and watermarking obligations for general-purpose AI still take effect December 2, 2026 — about four months from now. Penalties for the Act's prohibited-practice and high-risk provisions still scale up to €35 million or 7% of global annual turnover, whichever is higher, once obligations apply to you.
Most companies we talk to are still working off the old August 2026 date — either panicking about a deadline that already moved, or relaxing because they heard "it got delayed" and missed that transparency rules didn't. Both are expensive mistakes. The audit tells you which rules actually apply to your product, and when.
WHO THIS IS FOR
- European startups (10–100 people) that have shipped AI features in the last 18 months.
- Companies using OpenAI, Anthropic, or other model APIs in customer-facing products.
- Teams building agents, automation, or scoring/ranking systems.
- Founders heading into a raise or acquisition who need a credible AI code audit for diligence.
- Founders who suspect they need to do something but don’t know where to start.
If you're not sure whether the EU AI Act applies to you, the 60-second exposure check will tell you in plain English.
A different reason to book this
RAISING, OR BEING
ACQUIRED?
AI-code due diligence is now near-standard practice ahead of a raise or acquisition — even if your product has no customer-facing AI features at all. If you built fast with Claude Code, Cursor, or similar tools, investors increasingly want to know the codebase can survive a real audit before they wire the check. This same audit runs as a pre-raise or acquisition-ready variant: same scope, same three weeks, framed for what your investor or acquirer's technical diligence will actually ask.
Fixed scope · 3 weeks
WHAT'S INCLUDED
- Inventory of all AI systems and AI-touching workflows in the product and the org.
- Risk classification under the EU AI Act framework (prohibited / high-risk / limited / minimal).
- Vendor and dependency review (which third-party AI services you rely on, what their compliance posture is).
- MCP server and agent permission security review — a distinct attack surface from general appsec.
- Conformity assessment documentation package for high-risk systems.
- Human-oversight and logging recommendations, with implementation effort estimates.
- Remediation roadmap prioritized by deadline exposure.
- 90-minute walkthrough call with the founder and tech lead at the end of the engagement.
TIMELINE
Kickoff, system inventory, vendor review.
Risk classification, gap analysis, draft documentation.
Final report, walkthrough, roadmap handoff.
Engagements start within 5 business days of contract signing. Booking now gives you comfortable margin before the December 2, 2026 transparency deadline — and a documented head start on the December 2027 high-risk deadline while most competitors are still reacting to the old date.
WHY US
- We are a working engineering team, not a compliance-only firm — recommendations are implementable, not theoretical.
- EU-based (Portugal); GDPR-native; familiar with the European regulatory environment.
- Track record building production AI systems (Logistio, GrowSober, IRL).
- If we find that you don’t need a full audit, we’ll tell you in the free 30-min check and point you to the cheaper option.
FAQ
Yes — the Digital Omnibus (May 2026) moved the high-risk deadline to December 2027. Transparency obligations didn’t move and land December 2026. The point of the audit isn’t to beat a fake deadline, it’s to know which of your systems fall under which date so you’re not scrambling — or over-building compliance work you don’t need yet — later.
Probably not as a high-risk system, but you likely still need a usage policy, a vendor risk assessment, and shadow-AI controls. The exposure check will clarify.
We’ll tell you in the 30-min call. We don’t sell audits to companies that don’t need them — that’s bad for both sides.
Yes. Most audit clients move into a fractional CTO engagement or a targeted build sprint to implement the recommendations. The audit is priced as a standalone product, but it commonly leads into longer engagements.
Take the 60-second exposure check first — it’ll tell you your likely risk tier immediately. If it’s worth a deeper look, we get on a call: you describe your product and AI usage, we tell you (a) whether the EU AI Act applies and under which annex, (b) what the audit would cover for you specifically, and (c) an honest recommendation on whether to engage. No slides, no pitch deck.
KNOW YOUR ACTUAL EXPOSURE.
The exposure check takes 60 seconds. The call, if you need one, takes 30 minutes.