ciso.diy
EU AI Act Compliance Clock preview
Compliance EU AI ActAI compliancehigh-risk AIAI transparency

EU AI Act Compliance Clock

Transparency is live; high-risk is December 2027. Classify every AI system you provide or deploy, close the Article 50 duties that already apply, and run the deployer and provider programmes to the date that binds each one — with the US state overlay alongside.

What this actually gives you

  • Article 50 transparency has applied since 2 August 2026 — chatbots must say they are AI and synthetic media must be marked. It is not a deadline to plan for; it is a duty you are either meeting or breaching today.
  • The Digital Omnibus moved Annex III high-risk to 2 December 2027 — and gave the AI Office inspection powers in the same act. More time, and a regulator with teeth to use it.
  • Fines reach €35M or 7% of global turnover; €15M or 3% for high-risk and transparency breaches.
  • Under 750 staff does not mean exempt. The simplified small-mid-cap regime reduces the paperwork, not the substantive duties.

Article 50 transparency has applied since 2 August 2026. Chatbots must say they are AI, synthetic media must be marked, emotion recognition and biometric categorisation must be disclosed. That is not a deadline to plan for — it is a duty you are either meeting today or breaching today, and it is the one most organisations have not noticed arrived.

The Digital Omnibus then moved the Annex III high-risk obligations to 2 December 2027 and gave the AI Office inspection powers in the same act. More time, and a regulator with teeth to use it. Fines reach €35M or 7% of global turnover; €15M or 3% for the high-risk and transparency breaches.

This kit is the practitioner toolset for both halves — what binds you now, and what binds you on a date.

Role first, then risk. Every duty in the Act depends on whether you are a provider or a deployer of a given system, and most organisations are both, on different systems, at the same time. Classify per system, not per company.

What you get

01 Role & Risk Classifier + Inventory (XLSX) — sixteen questions return the role (provider or deployer), the tier (prohibited / Annex I / Annex III / Article 50 / minimal), the date that binds it, the live transparency duties, GPAI status, small-mid-cap regime, legacy grace and fine exposure — then rolls every system up into one inventory.

02 Deadline Calendar & Sequencer (XLSX) — every regime date, EU and US, with an applicability flag, and a sequencer that computes programme milestones backwards from your binding date and marks what is already past due.

03 Art. 50 Transparency Checklist (XLSX) — the ten duties live since 2 August 2026, each with status, evidence and a verdict. Start here, because this is the part that is already late.

04 Deployer Duties Register + Workbook (XLSX + DOCX) — the thirteen Article 26–27 duties per high-risk system, with a FRIA template written in the article's own structure, a human-oversight charter, worker and affected-person notices, the Article 86 explanation, and the incident procedure.

05 High-Risk Conformity Roadmap (XLSX) — the eighteen provider requirements across Articles 9–18, 20, 22, 43–49 and 72–73, each with what an assessor expects to see, status, readiness percentage, conformity route and small-mid-cap flags.

06 US State AI Overlay (XLSX) — Colorado, Texas, Utah, Illinois, NYC, California (ADMT and SB 53) and the federal picture, each mapped to its EU analogue, so one classification answers to both regimes.

07 Board One-Pager (PPTX) — two slides: what is live and dated, then the plan, the exposure and the decisions you need from them.

08 Practitioner Guide (PDF) — what the Omnibus changed, extraterritorial reach, role then risk, the four tiers, Article 50, the deployer and provider programmes, the SMC and SME regimes, the US overlay, sequencing, governance, failure patterns and an FAQ.

aiact.json — the tiers, dates, duty lists and classifier logic, machine-readable, so the same rules can drive your own tooling.

Under 750 staff does not mean exempt. The simplified regime for small mid-caps reduces the paperwork, not the substantive duties — the classifier flags which of the two you are in and what actually changes.

Dated honestly. The Omnibus text is agreed but not yet published in the Official Journal, so every date it moved is marked "verify final" in the files themselves rather than presented as settled. Version 1.1 lands on publication with the dates and article numbering confirmed, and re-download always serves the current edition.

Pairs with the Shadow AI Inventory to enumerate the estate before you classify it, the 2026 AI Risk Register for where AI risk lives once scored, the CCPA Audit & Risk Assessment Kit for California ADMT in depth, the Vendor Risk Operations Kit for the Article 50 confirmations you need from suppliers, and the Security Metrics & KPI Library for the AI metrics that report it.

A practitioner's toolset, not legal advice. The FRIA template and the conformity statements are drafting aids for counsel and, where applicable, a notified body — completing them is not itself compliance with Regulation (EU) 2024/1689.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-03
Pages 8