Prohibited AI is already banned and GPAI duties applied from Aug 2025; high-risk obligations land in 2027/2028 — deferral is not exemption.
The EU AI Act is the world's first law to impose mandatory, risk-tiered regulation on AI systems, applied in phases: prohibited systems (social scoring, manipulative AI) banned outright since February 2025; GPAI transparency, copyright and training-data summary obligations applicable since August 2025; high-risk system duties formally deferred to December 2027 (Annex III) and August 2028 (Annex I products). Any Chinese company offering AI systems to EU users, or using AI systems in the EU — including cross-border e-commerce, SaaS, consumer brands, and internet platforms — falls within its scope, with fines up to 7% of global turnover. Deferral is not exemption — now is the window to build your compliance system.
Classify your AI systems under the EU AI Act's four risk tiers (unacceptable / high / limited / minimal) and identify compliance priorities.
For high-risk systems such as recruitment AI, credit scoring, and biometric identification: risk management systems, technical documentation, and human oversight mechanisms.
If you train or fine-tune LLMs and deploy them in the EU, GPAI obligations apply: training-data transparency, copyright compliance, and model card publication.
For companies without an EU entity: appoint an EU representative as required, establish a compliance contact point, and respond to regulatory inquiries.
Work with our global-compliance consultants to map priority jurisdictions, implementation scope, and project timing.
Book Consultation