Compliance · EU AI Act

The EU AI Act: what applies now, and what comes later

The postponement you read about everywhere applies to the high-risk regime. Three obligations already apply, and they touch almost every organisation that uses AI.

Now
Prohibited practices (art. 5)since February 2025
Now
AI literacy (art. 4)since February 2025
Now
Transparency obligations (art. 50)since 2 August 2026
2 Dec 2026
New prohibitionsend of the grace period for machine-readable marking
2 Dec 2027
High risk, Annex IIIincluding deployers and the fundamental-rights assessment
2 Aug 2028
AI in medical devices

15 questions, 12 pages. No email required.

Or see how Numaga enforces this policy

Who it’s for

Data Protection Officer & legal

Wants to show a regulator, per decision, how policy was applied — not reconstruct it afterwards.

CIO & policy owner

Has AI policy on paper and wants it enforced in practice, not left to whether people read it.

CISO & security

Wants prohibited and high-risk use caught at the gate, not discovered afterwards.

The problem

The EU AI Act is ticking, and policy on paper stops no prompt.

Prohibited applications and high-risk use must be handled demonstrably. Without a log per decision, there is nothing to show a regulator.

Numaga checks every prompt against risk class and data sensitivity before the model call: prohibited use is blocked, high risk carries audit and validation evidence, limited risk gets transparency labels. Policy rules, not LLM judgement: reproducible for inspectors.

Risk-aware routing & data classification

The EU AI Act, operationalised.

Not as a guideline, but as policy, enforced on the control plane.

Risk-class routing
EU AI Act classPlatform behaviour
Prohibitede.g. social scoringBlocked on the control plane.
High riskdecision & process supportAudit · validation evidence.
Limited risktransparency requiredTransparency labels added in-line.
Minimal riskStandard routing with monitoring.
Data-sensitivity routing
SensitivityBehaviour
PublicStandard routing.
InternalIdentity + audit.
ConfidentialEU-compliant provider + redaction.
Strictly confidentialpersonal data, trade secretsStrictest provider class + redaction + long-term retention.

In practice

Proven where data is most sensitive.

Numaga is running a pilot with Ontdek Zorg, a home-care organisation in Gelderland. Healthcare, with special-category personal data under the GDPR, is where responsible AI is hardest. That is exactly where we put the control plane to the test.

  • Home care in Gelderland
  • Special-category data (GDPR Art. 9)
  • Policy and redaction on every prompt
ontdekzorg.nl

See the policy enforced, live.

In a demo environment we show how a prohibited prompt is blocked, and the audit trail it produces.

Request demo access

Download the self-check (pdf)15 questions, 12 pages. No email required.