AI Act in 3 sentences

The AI Act regulates AI systems in the EU. High risk AI obligations now apply from December 2027 for most use cases. Transparency obligations apply from August 2026. The CLOUD Act lets US authorities seize your AI data from US providers anywhere in the world.

  • AI Act scope: High risk AI includes credit scoring, insurance risk assessment, recruitment AI, and medical device AI
  • Transparency obligations: Article 50 requires informing users when they are subject to AI decision making
  • The fix: Own your AI infrastructure. Remove US controlled providers from your AI data path

Note: This is a simplified checklist. Refer to the official EU AI Act (Regulation 2024/1689) for full requirements. Consult legal counsel for compliance advice.

AI Act sovereignty checklist

Check each item that applies to your AI deployment. The AI Act and GDPR create sovereignty gaps for organisations using external AI services.

AI sovereignty assessment
No gaps identified
0 of 8 gaps found

AI Act sovereignty requirements
Do you inform users when they are subject to AI decision making or interacting with an AI system?AI Act Article 50
Article 50 says you must tell people when AI makes decisions about them. Your AI chatbot or risk tool does not tell them. Your users do not know AI decided their outcome. This breaks the law. Fines start August 2026. This is happening now.
Do you assign human oversight to competent persons for every high risk AI system?AI Act Article 26
Article 26 says you must assign a person to watch every high risk AI system. Your AI runs without a named person. No one is accountable when it fails. Your management body is liable. This starts December 2027 for high risk AI. It starts August 2026 for transparency rules.
Do you retain AI system logs for at least six months under your own control?AI Act Article 26
Article 26 says you must keep AI logs for six months. Your AI provider keeps the logs. You do not control them. You cannot show them in an audit. Your regulator will ask. You will have nothing.
Have you assessed whether your AI system is classified as high risk under Annex III?AI Act Annex III
Annex III says credit scoring, insurance, hiring, and medical AI are high risk. If you work in finance, insurance, HR, or medical devices, your AI is probably high risk. You have not checked. Your regulator will decide for you. From December 2027 you need a risk assessment before you start.
Do you process special category data (health biometric genetic) with AI?GDPR Article 9
Article 9 makes your management body pay the fine for special data. If you use AI on health data for insurance or biometric data for banking, you carry the risk. Regulators have fined companies up to 4% of global turnover. Your board signed the contract. Your board pays the fine.
Can you prove your AI training data and inference logs are not in the possession custody or control of a US provider?CLOUD Act
The CLOUD Act lets the US government take your AI data from AWS, Azure, or Google. Your EU data centre does not protect you. Your US provider will hand over your data without telling you. Your AI models are not private. Your training data and results are exposed to US law.
Do you monitor your AI system for serious incidents and inform the provider without undue delay?AI Act Article 26
Article 26 says you must watch your AI for serious problems and tell the provider. Your AI provider watches the system. You do not. You cannot spot a serious problem. You cannot tell the provider. You are liable when it fails. Your own infrastructure lets you watch. Rented AI hides it from you.
Do you control and validate the input data for your AI systems?AI Act Article 26
Article 26 says you must check the data you feed your AI. Your AI provider controls the data. You do not check it. Your AI may give wrong or biased results. Your management body is liable. Your own infrastructure lets you check the data. Rented AI does not.
Why your board needs to see this
Tell users when AI decides

The AI Act says you must tell people when AI makes decisions about them. This starts August 2026. Your chatbot, credit check, or hiring tool must say "AI decided this." If you rent AI from big tech, you cannot control what they do with your data.

High risk AI needs your own infra

Credit scoring, insurance, hiring, and medical AI are high risk. From December 2027 you need a risk assessment for each system. Your external AI provider cannot do this for you. You need your own infrastructure to document and control the data.

Fine: EUR 15M or 3%

AI Act fines for high risk violations go up to EUR 15 million or 3% of your global turnover. For banned AI practices it is EUR 35 million or 7%. Your rented AI provider holds the keys. You carry the fine.

The AI Act applies to any organisation deploying high risk AI systems. If you are a fintech, insurer, HR firm, or medtech company, your AI systems likely fall under Annex III high risk categories. NIS2 Article 21(2)(d) supply chain security catches external AI providers for essential entities. DORA Article 28(8) requires exit strategies for critical ICT including AI platforms. Check your NIS2 exposure or check your DORA exposure.

Worried about NIS2, DORA, AI Act or GDPR?

These regulations ask the same question. Who controls the systems you depend on. Our sovereign platform gives you the answer. You.

NIS2 Checklist Your DORA Register GDPR Checklist

No sales pressure. A clear look at your numbers, your dependencies, and your options.