Skip to main content
EU AI Act · Regulation (EU) 2026/1744 · adopted July 2026

The timeline is set.
The evidence design is still yours.
Build it before deployment.

Regulation (EU) 2026/1744 applies the relevant high-risk obligations from December 2, 2027 for Annex III systems and August 2, 2028 for product-integrated Annex I systems. EMILIA is one open technical mechanism for exact-action admission and portable evidence. It may support selected logging and oversight controls; it is not a complete compliance program and the law does not mandate an EMILIA receipt.

479
Days
22
Hours
46
Minutes
12
Seconds
Talk to a compliance engineerRead the spec
Scope

What "high-risk" covers

Annex III identifies high-risk use areas, subject to the Regulation's definitions, exceptions, and classification rules. A system touching one of these areas is not automatically high-risk; counsel and the deployer must classify the actual intended use.

  • Biometric identification
  • Critical infrastructure
  • Education access and assessment
  • Employment and worker management
  • Essential services — banking, insurance, credit
  • Law enforcement
  • Migration, asylum, border control
  • Administration of justice and democracy
The mapping

Where EMILIA may contribute to Articles 9 through 15

This is a technical-control mapping, not a conformity assessment. Articles 12 and 14 are highlighted because exact-action records and human-approval evidence are EMILIA's closest fit.

Art. 9
Risk management system
The obligation: Continuous risk identification, evaluation, and mitigation across the AI lifecycle.
Potential EMILIA contribution: Gate records the policy and exact action used for a protected decision. That artifact can support, but does not replace, a lifecycle risk-management system.
Art. 10
Data governance and quality
The obligation: Training and operational data must be relevant, representative, and free of errors.
Potential EMILIA contribution: EMILIA does not establish training-data quality or representativeness. It can bind identified operational inputs to one protected action.
Art. 11
Technical documentation
The obligation: Documentation kept current and available to authorities on request.
Potential EMILIA contribution: Public specifications, bounded models, conformance vectors, and 8,755 automated tests can support technical documentation. They are not the deployer's complete regulated documentation.
Art. 12
Automatic logging
Primary EP fit
The obligation: Logs must enable post-incident traceability for the full operational life of the system.
Potential EMILIA contribution: An authorization receipt is one tamper-evident event artifact. It does not replace complete operational logging or prove that every action passed through Gate.
Art. 13
Transparency to users
The obligation: Users must be able to understand and use system outputs.
Potential EMILIA contribution: Receipts expose the action, evidence references, policy version, and decision in a portable form. Usable notices and explanations remain the deployer's responsibility.
Art. 14
Human oversight
Primary EP fit
The obligation: Natural-person oversight to prevent or minimize risks during operation.
Potential EMILIA contribution: A relying party can require signed human-approval evidence for selected protected actions. The organization still decides who is qualified and whether that control meets Article 14.
Art. 15
Accuracy, robustness, cybersecurity
The obligation: System must be resilient to errors, faults, and unauthorized third-party alteration.
Potential EMILIA contribution: Bounded models and executable tests cover named replay, one-time admission, and uncertain-outcome properties. They do not prove overall system accuracy, cybersecurity, or legal conformity.
Article 14 Human-Oversight Kit

Your 30-day path to human oversight.

Article 14 requires effective human oversight. EMILIA can implement one narrow control: requiring action-bound approval evidence at a protected boundary.

01
Week 1 — Inventory
List every irreversible action your system can take. Each becomes a canonical action.
02
Week 2 — Observe
Run a scoped shadow assessment. It does not enforce and does not prove that every path is covered.
03
Week 3 — Enforce + sign-off
Route selected protected actions to qualified reviewers and issue action-bound approval evidence.
04
Week 4 — Evidence
Export the receipt bundle — an auditor verifies it offline, no need to trust EP or you.

Maps to Art 14 (human oversight), Art 12 (record-keeping), Art 9 (risk management). Not a complete compliance program; not legal advice. Full mapping in the Article 14 kit.

Financial services mapping (PDF)Government programs mapping (PDF)Healthcare mapping (PDF)
Penalties

Penalties depend on the violation

Up to €15M
Other-obligation tier under Article 99
Up to 3%
Prior-year worldwide turnover for that tier
Dec 2, 2027
Annex III high-risk application date
Beyond Brussels

Parallel forcing functions

U.S. federal and state instruments create different governance, documentation, inventory, and procurement pressures. They do not all require the same control, and an EMILIA mapping is not compliance by itself.

United States
NIST AI RMF + OMB M-25-21
Federal AI use-case inventories flag high-impact uses; NIST AI RMF alignment shapes procurement. EP publishes its RMF mapping.
California
EO N-5-26 + TL 24-03
Trusted-AI procurement standards and GenAI risk assessments for state entities.
Colorado
Colorado AI Act
Effective June 30, 2026. Impact assessments and consumer notification.
Texas
TRAIGA (HB 149)
Effective Jan 1, 2026. Agency AI governance and disclosure obligations.
Next step

Eighteen months is enough — if you start this week.

We integrate in under a day. Apache 2.0, no vendor lock-in. Reference verifiers deployed publicly; first pilot slots open.

EU AI Act Human Oversight (Article 14): Evidence to Build Now