EU AI Act
Stay ahead of the EU AI Act
The EU AI Act’s transparency obligations have been in force since 2 August 2026. High-risk system obligations follow in December 2027. Here’s what applies when, and how Orq helps you meet it.
Trusted by European teams in production

Why this matters now
One deadline has already passed
None of the obligations are paperwork. Each one needs to be built into the system before it applies.
Article 50 transparency obligations, covering chatbot disclosure and synthetic content labeling, have applied since 2 August 2026. For high-risk AI systems, logging, monitoring, and human oversight take effect in December 2027. Audit trails and monitoring cannot be built retroactively, so the work needs to start now, regardless of which deadline applies to you.
Start here
If you’re an EU company using AI, start here
Four steps, in order. Each one is a prerequisite for the one after it.
Build a central AI inventory
List every AI use case in the business, who owns it, what data it touches, and which model serves it. You cannot classify what you have not cataloged.
Classify each use case by risk
The tier a use case falls into determines what you are required to build. Classification is per use case, not per company.
Apply logging, tracing, and guardrails
Automatic logging, human oversight, and PII controls have to be live before the obligation applies, not after.
PII and risk guardrails
Screen requests for sensitive data automatically and route around risk before it reaches a model.
Risk classification
Classification decides which obligations apply
Each tier carries a different set of obligations, and the tier a use case lands in is yours to determine and evidence.
Prohibited (Article 5)
Social scoring, untargeted facial scraping, emotion inference at work or in schools, and manipulative systems. Banned outright and already in force. These need blocking, not classifying.
High-risk (Annex III)
Recruitment and HR, creditworthiness, insurance pricing, education, essential public services, medical devices, and critical infrastructure. The full obligation set applies from December 2027.
Limited risk (Article 50)
Chatbots, AI-generated text, images, audio and video, and biometric categorization. Disclosure and labeling obligations have applied since 2 August 2026.
Minimal risk
Internal copilots, summarization, search, translation, and coding assistants. No further AI Act obligations. Article 4 AI literacy still applies at every tier.
High-risk controls
If a use case is high-risk, these become mandatory
Automatic logging (Article 12)
Tamper-evident logs of every input, output, timestamp, tool call, and decision, including the full agent action chain.
Tracing and monitoring (Articles 9 and 13)
A living risk management system with post-deployment monitoring, and decisions a human can trace and interpret.
Audit trails and retention (Article 26(6))
System logs retained for at least six months in audit-ready form, exportable and searchable.
Guardrails and PII redaction (Articles 14 and 15)
PII detection and redaction, jailbreak and prompt-injection screening, toxicity blocking, red-teaming, and human-in-the-loop on tool use.
How Orq.ai helps
Compliance, built in
Auditability across the full lifecycle
Every prompt, response, tool call, API invoked, and agent decision logged and traceable, from development through production. The complete record an auditor needs, built in from day one.
The Articles
What the EU AI Act requires, article by article
Article 4
AI literacy: providers and deployers must ensure staff have sufficient AI knowledge.
In force
Documentation, audit trails, and governance reporting that evidence literacy measures.
Article 5
Prohibited practices: unacceptable-risk AI systems banned outright.
In force
Guardrails that enforce internal bans on prohibited use patterns at the gateway level.
Article 50
Transparency obligations: chatbots disclose they are AI; synthetic content must be labeled.
In force
Metadata tagging and content detection at the gateway level. Disclosure UX in your product remains your obligation; Orq provides the traces to evidence it.
Article 9
A living risk management system with ongoing post-deployment monitoring.
Dec 2027
Continuous observability across every request, with gateway-level policies for PII detection, redaction, and bias monitoring.
Article 12
Automatic, tamper-evident logging of every input, output, timestamp, tool call, API invoked, and decision taken, including the full agent action chain.
Dec 2027
Full request tracing on by default, covering every agent step: tool calls, API invocations, and decisions. Audit logs on all system and agent changes.
Article 13
Decisions a human can trace and interpret.
Dec 2027
End-to-end traces grouped into threads, with spans your team can inspect.
Article 14
Humans who can understand, intervene, override, and halt the system.
Dec 2027
Policies and guardrails at the AI gateway level, plus human-in-the-loop approval screens for tool use.
Article 15
Accuracy, robustness, and resistance to adversarial attacks.
Dec 2027
PII guardrails, fallback chains, routing rules, and automated red teaming for agents.
Article 26(6)
Deployers must retain system logs for at least 6 months in audit-ready form.
Dec 2027
Full audit logs, tamper-evident and exportable, retained and searchable across all agent and gateway activity.
Article 73
Report serious incidents within 2 to 15 days by severity; 2 days for critical-infrastructure incidents.
Dec 2027
Real-time alerts and full historical traces from the moment an issue occurs.
Article 50 is now in force. High-risk obligations follow in December 2027, but audit trails and monitoring only work if they are already live before the deadline arrives.
Testimonials
Teams that run on our EU AI gateway

We chose Orq.ai to replace our internal setup with a production-ready AI Gateway that meets our governance, scalability, and cost-monitoring requirements.

Benjamin Kleppe,
GenAI Lead at bunq

Connecting to Orq.ai’s platform means we no longer need to revise our own code. The platform provides full control over the functionality of the models, saving considerable time and manual adjustments.

Thomas Goijarts,
Founder, Caro health
FAQs
What teams ask us about the EU AI Act
How long do I need to keep system logs?
Article 26(6) requires deployers to retain system logs for at least six months in audit-ready form. Orq’s audit logs are tamper-evident, exportable, and searchable across agent and gateway activity.
How fast do I need to report a serious incident?
Article 73 requires reporting within 2 to 15 days, depending on severity. That depends on monitoring and alerting already being in place.
Does the EU AI Act apply to companies outside the EU?
The Act applies to providers and deployers of AI systems placed on the EU market or whose outputs are used in the EU, regardless of where the provider is based.
How does Orq help with AI Act compliance?
Full request observability, automatic logging covering the full agent action chain, real-time monitoring, and router-level guardrails are built into the platform by default, ready before you need them.

