EU AI Act compliance evidence, scored

    The EU AI Act is the first comprehensive AI law with teeth. If you place an AI system on the EU market, or your output reaches people in the EU, you carry obligations you have to be able to evidence. Not describe. Evidence.

    Describing your AI system is not the same as evidencing it

    Most organizations preparing for the AI Act produce documentation: a system inventory, a risk classification memo, a policy stating that human oversight exists. Each is necessary. None of it demonstrates that the control operated on the day a decision was made.

    The obligations are written in the language of demonstration. Risk management across the lifecycle. Data governance you can substantiate. Logging that supports traceability. Human oversight that is effective, not merely assigned. Every one of those is a claim a regulator can ask you to prove.

    What a timeline change does not change

    The high-risk deadlines moved in July 2026. The evidence burden did not, and neither did the harmonised standards that conformity will eventually be assessed against.

    A deferral is time to build the record, and the record is the part that cannot be produced retroactively. An AI system that ran for eighteen months without traceable logging cannot be back-filled into compliance. The organizations that use the extension to start measuring will have a defensible history when the date arrives. The ones that wait will have a policy binder and a gap.

    What you get from a METRIS™ score

    You get your AI systems mapped against the obligations that actually attach to them, given how you classify and where you operate, so you are not preparing for requirements you do not carry.

    You get a defensible score for each system, decomposable to the evidence behind it. When a regulator, a customer, or your own board asks how you know, you open the score and show them the record rather than restating the policy.

    You get the gaps ranked by exposure, so the work you fund first is the work that closes the most risk. And because the score is continuous, you can show that a control held over time, which is the claim documentation can never make on its own.

    Key dates

    2 February 2025
    Prohibited practices and AI literacy obligations applied.
    2 August 2025
    General-purpose AI model obligations applied.
    2 August 2026
    Most Article 50 transparency obligations apply, including informing people they are interacting with an AI system.
    2 December 2026
    Marking of AI-generated content for systems placed on the market before 2 August 2026.
    2 August 2027
    Regulatory sandbox deadline for member states.
    2 December 2027
    Standalone high-risk obligations (Annex III), deferred from 2 August 2026.
    2 August 2028
    High-risk obligations for AI embedded in regulated products (Annex I), deferred from 2 August 2027.

    Amended by the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026. Confirm against the current consolidated text before relying on any date for a filing.

    Last reviewed 27 July 2026.

    Know what you can evidence, before someone asks

    Start with one AI system. You get a scored result you can show a regulator, and a ranked list of what to fix first.

    Other frameworks

    The same evidence maps to more than one framework. Proving a control once should not mean proving it three times.

    Cookies

    We use cookies to make sanjeevaniai.com work and to understand how visitors engage with our content. Read our Privacy Policy.