Answer guide

"Our buyer says we must be EU AI Act compliant by August 2" — what to actually do

The email is some version of: "Please confirm your company will be fully compliant with the EU AI Act by August 2, or provide your compliance certificate." It reads like a deal-stopper. It is answerable in a page — the frame behind it is wrong, and you can correct it politely while giving the buyer what their legal team actually needs.

The frame is wrong: there is no binary "AI Act compliant"

Regulation (EU) 2024/1689 does not create a single pass/fail state a vendor can certify on a date. Its obligations phase in on different dates and attach differently by risk class and role (provider or deployer). What happens on 2 August 2026 is specific: for a typical B2B SaaS, the substance is the Article 50 transparency duties — which bind you only if your features trigger them. The prohibitions and the Article 4 AI-literacy measures have applied since 2 February 2025; the high-risk regime for Annex III use cases does not apply until 2 December 2027. The precise before/after map is in what actually changes on 2 August 2026.

So the honest reply is neither "yes, fully compliant" (an over-claim you may later be asked to warrant) nor panic. It is: our classification, the obligations that apply to us on that date, our status on each.

The 60-second check: which duties does your product actually trigger?

The free Article 50 checker runs this mapping in six questions, no email required. The paragraph-by-paragraph analysis is in the Article 50 guide.

The reply script

For orientation only — verify every bracket against your own product before sending. If your product touches Annex III territory (biometrics, employment decisions, credit scoring and similar), take legal advice instead of adapting this.

"Thanks for flagging the 2 August date — happy to set out where we stand. There is no single 'AI Act compliant' certification; obligations attach by risk class and role, so here is our position per obligation. Classification: based on its intended use, [product] does not fall within the high-risk use cases of Annex III of Regulation (EU) 2024/1689 and is a limited-risk system — the high-risk regime (from 2 December 2027) does not apply to it. From 2 August 2026: the Article 50 transparency duties, specifically [50(1), because users interact with our AI assistant under our brand]. Status: [users are informed at first interaction that they are interacting with an AI system]. Also in force: the Article 4 AI-literacy measures, since February 2025 — [our staff training and completion records]. In progress: [item], targeted for [approved date]. We can provide documented answers to your full questionnaire, each claim cited to its article."

What to prepare in the next 48 hours

  1. Inventory your AI features: model, provider, version, purpose, where it processes data. This anchors every other answer.
  2. Fix your role per feature. Under your own brand = provider — this decides which Article 50 paragraphs you owe.
  3. Ship or verify the 50(1) disclosure — visible at first interaction. If you rely on the "reasonably well-informed, observant and circumspect" exception, write down why.
  4. Document your 50(2) position if you generate synthetic content: marking in place, or a dated plan inside the transition window.
  5. Pull your Article 4 records: who completed AI training and when — national supervision begins on 2 August 2026.
  6. Draft the four-part answer (classification → obligations → status → gaps with a plan) for the questionnaire that usually follows — the structure is in how to answer "are you EU AI Act compliant?", the wider triage in the first-24-hours playbook.

What not to do

FAQ

Can we just reply "yes, we are EU AI Act compliant"?

No. Obligations phase in on different dates and differ by risk class and role, so "compliant" is only meaningful per obligation — and by contract stage you may be asked to warrant your answers. Use the four-part structure above.

What happens if we are not ready on 2 August 2026?

Breaching Article 50 carries fines of up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher — the lower of the two for SMEs and startups (Article 99(6)). Fines are imposed by Member States, whose enforcement regimes are still being put in place. So: state gaps honestly with a dated plan; do not claim compliance you cannot evidence.

Our AI feature is just OpenAI's or Anthropic's API — isn't compliance their problem?

Not for the duties facing your users. A company that places an AI system on the market under its own name or trademark is treated as its provider — shipping a third-party model under your brand puts the Article 50(1) disclosure duty on you, not on the model vendor.

The buyer wants answers this week?

Send the questionnaire — first 3 answers free within 24h, full delivery in 48h for $490 flat (up to 60 questions), rush in 24h for $790, paid after delivery, late means free. Every answer is a draft for your review with each legal claim cited to its article — judge the public sample first.

Send your questionnaire →