Insights
EU AI Act Insights
Plain-English EU AI Act explainers and updates, written for the people who have to comply. New entries land here as the rules move.

Harmonised Standards and Presumption of Conformity Under the EU AI Act: A Plain-English Guide to Articles 40 and 41
What "presumption of conformity" actually buys you under Articles 40 and 41, why the CEN-CENELEC standards are delayed, and what high-risk AI providers must do right now.

EU AI Act Article 9: A Plain-English Guide to the Risk Management System for High-Risk AI
Article 9 of the EU AI Act requires a continuous, lifecycle-wide risk management system for every high-risk AI system. Here's exactly what that means and how to build one.

Article 22 EU AI Act: The Plain-English Guide to Authorised Representatives for Non-EU Providers
If you build high-risk AI outside the EU and want to sell into the EU market, Article 22 requires you to appoint an EU authorised representative by written mandate - before you go live. Here's exactly what that means.

Article 11 and Annex IV EU AI Act: Your Plain-English Guide to Technical Documentation for High-Risk AI
Every provider of a high-risk AI system must build a technical file before market launch. This plain-English guide walks through Article 11, all nine Annex IV sections, the Digital Omnibus deadline changes, and practical steps to start now.

Article 26 EU AI Act: A Plain-English Guide to Every Deployer Obligation
Article 26 of the EU AI Act imposes 12 distinct duties on organisations that USE high-risk AI they didn't build. Here's every obligation explained in plain English, with the updated Digital Omnibus deadlines.

Who Actually Enforces the EU AI Act? A Plain-English Guide to the Enforcement Architecture
The EU AI Act splits enforcement between the European AI Office and 27 sets of national authorities. This plain-English guide explains who has power over your organisation - and what to do about it.

EU AI Act vs GDPR: A Plain-English Guide to Dual Compliance
The EU AI Act and GDPR are not rivals - they govern different things and both apply to AI that touches personal data. Here's how to run one programme that satisfies both.

EU AI Act Article 17: A Plain-English Guide to the Quality Management System for High-Risk AI
Article 17 of the EU AI Act requires every provider of a high-risk AI system to build a documented quality management system. Here is what that means in practice - and how to build one.

EU AI Act Articles 72 & 73: A Plain-English Guide to Post-Market Monitoring and Serious Incident Reporting
Everything high-risk AI providers need to know about Article 72 post-market monitoring plans and Article 73 serious incident reporting deadlines - with a practical pre-deadline checklist.

EU AI Act Article 15: A Plain-English Guide to Accuracy, Robustness and Cybersecurity for High-Risk AI
Article 15 of the EU AI Act sets binding technical requirements for accuracy, robustness and cybersecurity across the full lifecycle of high-risk AI systems. Here's what providers and ML engineers need to do.

Article 10 of the EU AI Act: A Plain-English Guide to Data Governance for High-Risk AI
Article 10 of the EU AI Act sets binding data governance rules for high-risk AI training, validation, and testing datasets. Here's exactly what providers must do - and when.

EU AI Act Article 57: Your Plain-English Guide to AI Regulatory Sandboxes
Article 57 of the EU AI Act requires every member state to have an AI regulatory sandbox operational by 2 August 2026. Here's what sandboxes are, why they matter for SMEs and startups, and how to apply.

Article 14 of the EU AI Act: A Plain-English Guide to Human Oversight
Article 14 of the EU AI Act requires effective human oversight of high-risk AI - not rubber-stamping. Here's what providers and deployers must do before 2 August 2026.

EU AI Act Article 27: The Practical Guide to Fundamental Rights Impact Assessments (FRIA) for Deployers
Article 27 of the EU AI Act requires certain deployers to complete a FRIA before going live. Deadline: 2 August 2026. Here's exactly who owes one, what it must contain, and how to start now.

EU AI Act Conformity Assessment and CE Marking: A Plain-English Guide for High-Risk AI Providers
You've confirmed your system is high-risk. Now what? This guide walks through Article 43 conformity assessment routes, the Annex IV technical file, CE marking, EU database registration, and the 9-12 month prep timeline.

Article 50 EU AI Act: Your Complete Guide to AI Transparency Obligations
Article 50 of the EU AI Act imposes four transparency obligations on chatbots, deepfakes, and AI-generated content from 2 August 2026. Here's what marketers, product teams, and newsrooms must do now.

Article 4 EU AI Act: Your Plain-English Guide to the AI Literacy Obligation
Article 4 of the EU AI Act has required AI literacy training since 2 February 2025. Here's what it actually says, who it covers, and how to build a defensible programme before enforcement begins in August 2026.

GPAI Obligations Under the EU AI Act: A Plain-English Guide for Model Providers and Downstream Developers
GPAI obligations under the EU AI Act became applicable on 2 August 2025. This plain-English guide covers baseline duties, systemic-risk rules, the Code of Practice, and the compliance timeline every model provider needs to know.

EU AI Act Fines Explained: A Plain-English Guide to Article 99 Penalties
Article 99 of the EU AI Act sets fines that exceed GDPR - up to €35M or 7% of global turnover. Here's exactly how the three-tier penalty structure works, who enforces it, and how to reduce your exposure.

Article 5 of the EU AI Act: A Plain-English Guide to Every Prohibited AI Practice
Article 5 of the EU AI Act bans eight categories of AI outright - no compliance pathway, no exceptions. Here's what each prohibition means, who it catches, and what's coming next.

The Digital Omnibus on AI: What's Proposed, What's Law, and What You Must Do by 2 August 2026
A provisional deal reached on 7 May 2026 would push the EU AI Act's high-risk deadline to December 2027 - but it is NOT yet law. Here's what's binding right now and how to plan.

EU AI Act Roles Explained: Provider, Deployer, Importer, Distributor - and Who Owes What
The same AI system carries very different legal duties depending on your role. Here's a plain-English breakdown of all four EU AI Act roles and their obligations.

Is Your AI System High-Risk Under the EU AI Act? A Plain-English Classification Guide
Most AI systems are NOT high-risk. Learn the two routes into high-risk classification - Annex I and Annex III - and the Article 6(3) exception that can pull you back out.