What's inside
Part I — the law, in sixteen chapters
Foundations & the four tiers
What the Act is, who it binds — including providers outside the EU whose output lands here — the Article 3 definitions, and how every system sorts into one of four risk tiers.
Classification, worked properly
The questions in order, the Article 6(3) filter, and the profiling override that makes an Annex III system high-risk regardless of the filter. Ends with the mistakes people actually make.
The seven pillars & your role
Articles 8–15 pillar by pillar, then the value chain: provider, deployer, importer, distributor — and how placing a system under your own name makes you the provider.
QMS, conformity & CE marking
Article 17 as a standing system rather than a project, then the route to market in order: assess conformity, declare it, affix CE, register in the EU database.
After launch, and transparency
Post-market monitoring and the incident clock that starts at awareness, then the Article 50 duties that reach far beyond high-risk — chatbots, generated content, deepfakes.
GPAI, literacy, enforcement & rights
Model-provider duties and what changes when you fine-tune, Article 4 literacy, who enforces and what it costs, the rights of people on the receiving end, sandboxes, and the GDPR overlap.
Part II — six working tools
Fill-in material, not further reading
Practical classification examples
Five real systems worked end to end — from the question, to the classification, to the actions each one triggers.
Building your Annex IV technical file
The most substantial high-risk deliverable, split into four sections with one owner each.
FRIA walkthrough & template
Who must run an Article 27 assessment, how to run it, and a fill-in template — plus why the DPIA cannot be copy-pasted into it.
AI system inventory template
The register everything else keys off. One row per system: bought, built, or embedded in something you already licence.
Serious-incident report form
Pre-fill sections 1–3 today so the clock never beats you. Deadlines run from awareness, not from confirmation.
12-month compliance calendar
July 2026 → June 2027, quarter by quarter, to arrive comfortably ahead of the December 2027 high-risk wall.
Why start with the handbook
Plain English, not legalese
Every article is translated into language a busy team can act on — with practical examples rather than recitals.
Re-timed for the Omnibus
Standalone high-risk obligations apply from 2 December 2027 and Annex I product-embedded from 2 August 2028, deferred by Regulation (EU) 2026/1744. Article 50 transparency was not deferred — it has applied since 2 August 2026.
Six tools, not just reading
Part II is fill-in material: an inventory, a FRIA template, an incident form and a 12-month calendar. Four of the six are new in v2.2.
Deployer-first
Most EU organisations are Deployers, not Providers. The handbook prioritises Deployer obligations under Article 26.
Mapped to the regulation
Every claim is anchored to a specific article, recital or Annex — so your file points back to the source.
A path to automation
When you're ready to stop tracking by hand, the Veritome platform picks up exactly where the handbook leaves off.
Frequently asked questions
Who is this handbook for?
Anyone responsible for AI compliance in an EU organisation — compliance, legal, risk, and product leads — whether you deploy third-party AI tools or build your own systems.
Is it really free?
Yes, completely free. We ask for your email so we can send occasional compliance updates and tips — you can unsubscribe at any time.
How long is it?
54 pages. Part I is 16 chapters on the law; Part II is six ready-to-use working tools; the reference section closes with a complete compliance checklist, an FAQ, a glossary and the primary sources.
What changed in version 2.2?
Every chapter was deepened with article walk-throughs, step-by-step how-tos and common-mistakes notes, and four new working tools were added: a FRIA walkthrough and template, an AI system inventory, a serious-incident report form and a 12-month compliance calendar. The dates throughout are re-timed for the Digital Omnibus.
How is this different from the Veritome platform?
The handbook is the reading. The Veritome platform is the doing: it automates classification, generates the exact obligations that apply, and assembles verifiable documentation from your live data.
When does the EU AI Act apply?
In stages. Prohibited practices have been banned since February 2025 and GPAI obligations since August 2025. Article 50 transparency has applied since 2 August 2026. Standalone Annex III high-risk obligations apply from 2 December 2027, and high-risk AI embedded in Annex I products from 2 August 2028 — both deferred by Regulation (EU) 2026/1744, in force since 27 July 2026.
Get your free compliance handbook
Join thousands of compliance professionals preparing for the EU AI Act deadline.

