One of five capabilities

Exposure is the entry. Governance is the foundation. Readiness is the objective.

We help organizations establish the governance, documentation, controls, and evidence required to manage AI responsibly and prepare for independent legal, compliance, audit, or certification review.

EU AI Act · Compliance Timeline

The regulatory clock for AI is already running.

Four dates, each a structural shift in legal exposure for AI deployers. The Digital Omnibus provisional agreement (7 May 2026) defers two deadlines, but 2 Aug 2026 remains legally active until Official Journal publication. This is the depth behind it.

  1. GPAI Obligations in Force

    General-purpose AI model providers must maintain technical documentation, comply with copyright law, and publish training-data summaries. Article 53 obligations are now active.

  2. Article 50 Transparency

    Transparency obligations for AI that interacts with people (chatbots, emotion-recognition, synthetic media) become enforceable. Unchanged by the Digital Omnibus, and the imminent threshold for most deployers.

  3. Annex III High-Risk (Stand-alone) · Provisional

    Conformity assessments for stand-alone Annex III high-risk AI (recruitment, credit scoring, biometrics, critical infrastructure) are provisionally deferred from 2 Aug 2026 under the Digital Omnibus (7 May 2026). Not yet enacted. 2 Aug 2026 stays legally active until Official Journal publication, so we treat the earlier date as the planning floor.

  4. Annex I Embedded High-Risk

    AI embedded as a safety component in regulated products (medical devices, machinery, vehicles, civil aviation, critical infrastructure) must meet full conformity requirements. The Omnibus extends this by one year from the earlier 2027 estimate.

Where the exposure sits

What the regulation actually asks of your organization.

AI governance is one of five capabilities RAVENTRYX operates, and the one most clients arrive through. The Article 50 transparency obligation on AI-generated content is live from 2 August 2026; that date did not move. The Digital Omnibus provisional agreement of 7 May 2026 deferred standalone Annex III high-risk conformity to 2 December 2027 and AI embedded in regulated products to 2 August 2028, but the deferral binds only once it is published in the Official Journal. Until that publication lands, the original dates remain the legally active position, and a conformity framework takes twelve or more months to build. The credible reading is headroom, not reprieve.

The exposure that most US organizations miss sits in Article 26. If you buy and configure a third-party high-risk AI system, you are a deployer, and the deployer obligations bind you regardless of the provider’s conformity status: human oversight, six-month log retention, fifteen-day serious incident reporting, worker notification in employment contexts, and a fundamental-rights impact assessment in credit, insurance, and public-sector use. Provider conformity does not transfer these to the provider. A company that runs someone else’s AI in production has obligations it never signed up for and often does not know already apply.

This page is the regulatory depth behind the capability. The engagement model that turns this exposure into a defensible, audit-ready position is set out in our full AI governance engagement model.

Regulatory information only. The frameworks, timelines, and standards referenced here reflect our reading of the EU AI Act (Regulation 2024/1689) and related instruments (including GPAI / Article 53 and the Digital Omnibus deferral) as of the review date below. Regulatory guidance and implementation timelines continue to evolve and may change. Nothing here is legal advice, and reading it does not create an advisory relationship. For guidance specific to your organization, consult qualified legal or compliance counsel. Last reviewed: July 28, 2026.

Sources

What conformity actually requires

The regulatory floor is the start. We design the governance to hold past it.

Annex III high-risk classification

Every model and feature you operate is classified against the EU AI Act high-risk categories (credit scoring, insurance pricing, hiring tools, biometrics) with the rationale documented per system. Classification is step zero: nothing defensible gets built without an inventory that states which systems carry real regulatory weight and which a regulator looks at first. You leave with a populated AI system inventory, not a policy page that asserts good intentions.

Article 50 transparency, operationalized

The transparency obligation on AI-generated and AI-assisted content is live from 2 August 2026 and was not deferred. We turn it into the disclosures, labeling, and record-keeping your product and content workflows actually run, wired into how the team already ships, not acknowledged once in a policy document. The deliverable is the operating control and its evidence trail, structured the way an enterprise reviewer expects to read it.

ISO/IEC 42001 management system (AIMS)

We help establish an AI management system aligned with relevant ISO/IEC 42001 requirements, including documented policies, named responsibilities, risk-management processes, operational controls, monitoring, management review, and improvement actions. The system is structured to support future independent certification if the organization chooses to pursue it. Certification itself is performed solely by an independent accredited certification body.

Annex IV technical file and Article 9 risk file

We produce the conformity documentation an external assessor expects: the Annex IV technical file and the Article 9 risk-management file, structured and version-pinned. Article 9 risk management is a continuous lifecycle obligation, not a one-time engagement, so we build it to be maintained, with the ownership and review cadence that keep it current as the regulatory target moves. When the auditor or the questionnaire arrives, the file is already assembled.

Frameworks referenced in our work

Coordinated control architecture

ISO 42001, ISO 27001, SOC 2, and NIST AI RMF: a coordinated control architecture.

We design a coordinated control architecture that reduces unnecessary duplication across the EU AI Act, ISO/IEC 42001, ISO/IEC 27001, SOC 2, and the NIST AI RMF. Where requirements overlap, controls and evidence can be mapped and reused. Where requirements differ, framework-specific obligations remain separately identified and managed.

EU AI Act
Annex III classification, Annex IV technical file, Article 9 risk management, Article 26 deployer obligations.
ISO/IEC 42001
The certifiable AI management system: policies, owners, and controls that hold under audit.
ISO/IEC 27001
The information-security baseline most enterprise buyers already require, mapped to the same control set.
SOC 2
The Type II attestation enterprise procurement gates on, organized to reduce preparation effort, improve traceability, and support a more efficient independent examination. SOC 2 is an examination performed by an eligible independent auditor, not a certification RAVENTRYX issues.
NIST AI RMF
The govern / map / measure / manage profile US buyers increasingly cite in their questionnaires.

Engage

Structured for certification readiness.

  • AI Readiness Assessment$950one-time
Assess your exposureSecure Stripe checkout

Common questions about EU AI Act and ISO 42001 readiness.

The Digital Omnibus deferred Annex III. Do we still need to act now?

Article 50 transparency obligations remain live from 2 August 2026. The Omnibus deferral is provisional. It binds only once published in the Official Journal, which has not yet occurred. More practically, building a conformity framework takes twelve or more months, so December 2027 is not a long runway from a build perspective. The credible legal position is to use the time, not wait for it.

We already have SOC 2 Type II and ISO 27001. Is that enough?

Not anymore. Enterprise security questionnaires now include AI-specific questions covering ISO 42001 controls, NIST AI RMF alignment, model bias management, training-data lineage, and Annex III risk classification. SOC 2 and ISO 27001 are table stakes, not AI governance. Buyers who surface those gaps in review are looking for the next level of attestation.

We use third-party AI, not our own. Does the EU AI Act apply to us?

Yes. Article 26 deployer obligations apply to any organization using high-risk AI systems: human oversight, six-month log retention, fifteen-day serious incident reporting, worker notification in employment contexts, and a fundamental-rights impact assessment in credit, insurance, and public-sector use. Provider conformity does not transfer these obligations to the provider.

What does EU AI Act compliance consulting actually deliver at the end?

Concrete, audit-ready output: a populated AI system inventory with Annex III classification per system, the Annex IV technical documentation, an Article 9 risk-management file, and FRIA templates for the relevant use cases, structured so that where the EU AI Act, ISO 42001, ISO 27001, SOC 2, and NIST AI RMF overlap the evidence is reused, and where they differ the obligations stay separately identified. You receive an evidence base, not a strategy deck.

Does this apply to US companies that only have some EU customers?

It can. The EU AI Act reaches organizations that place AI systems on the EU market or whose AI output is used in the EU, and Article 26 deployer obligations bind any organization deploying high-risk AI in scope, not only EU-headquartered ones. If EU exposure is becoming a board-level question, the position you can defend is one you have documented in advance.

RAVENTRYX provides advisory, governance design, documentation, implementation support, and operational-readiness services. RAVENTRYX does not provide legal advice and does not issue certifications, conformity decisions, audit opinions, or regulatory approvals. Certification and assurance decisions are made exclusively by appropriately qualified independent bodies. Nothing on this website constitutes a guarantee of certification, regulatory compliance, audit outcome, procurement acceptance, or commercial result. Organizations should obtain advice from qualified legal, compliance, audit, and certification professionals where appropriate.

Pass the floor. Build past it.