AI Act in 3 sentences
The AI Act regulates AI systems in the EU. High risk AI obligations now apply from December 2027 for most use cases. Transparency obligations apply from August 2026. The CLOUD Act lets US authorities seize your AI data from US providers anywhere in the world.
- AI Act scope: High risk AI includes credit scoring, insurance risk assessment, recruitment AI, and medical device AI
- Transparency obligations: Article 50 requires informing users when they are subject to AI decision making
- The fix: Own your AI infrastructure. Remove US controlled providers from your AI data path
Note: This is a simplified checklist. Refer to the official EU AI Act (Regulation 2024/1689) for full requirements. Consult legal counsel for compliance advice.
AI Act sovereignty checklist
Check each item that applies to your AI deployment. The AI Act and GDPR create sovereignty gaps for organisations using external AI services.
The AI Act says you must tell people when AI makes decisions about them. This starts August 2026. Your chatbot, credit check, or hiring tool must say "AI decided this." If you rent AI from big tech, you cannot control what they do with your data.
Credit scoring, insurance, hiring, and medical AI are high risk. From December 2027 you need a risk assessment for each system. Your external AI provider cannot do this for you. You need your own infrastructure to document and control the data.
AI Act fines for high risk violations go up to EUR 15 million or 3% of your global turnover. For banned AI practices it is EUR 35 million or 7%. Your rented AI provider holds the keys. You carry the fine.
The AI Act applies to any organisation deploying high risk AI systems. If you are a fintech, insurer, HR firm, or medtech company, your AI systems likely fall under Annex III high risk categories. NIS2 Article 21(2)(d) supply chain security catches external AI providers for essential entities. DORA Article 28(8) requires exit strategies for critical ICT including AI platforms. Check your NIS2 exposure or check your DORA exposure.
Worried about NIS2, DORA, AI Act or GDPR?
These regulations ask the same question. Who controls the systems you depend on. Our sovereign platform gives you the answer. You.
No sales pressure. A clear look at your numbers, your dependencies, and your options.