EU AI Act · Seven obligations · August 2, 2026

Full EU AI Act compliance. One platform.

From Article 50 disclosure to Article 14 human oversight to GPAI model provenance: Eniyan covers every obligation the Act creates for operators of consumer-facing and high-risk AI systems.

Article 50 enforcement
In force
since August 2, 2026
August 2, 2026
Fines up to €30M or 6% of global annual turnover (high-risk AI)
The legal obligations

Seven obligations. Every one covered.

The verbatim legislative text, exactly what it requires, and precisely how Eniyan satisfies each obligation.

Limited-risk AI · all operators€15M or 3% global turnover
Article 50(1)
Disclose AI at the point of interaction
Know Your Agent + Verification & Transparency

Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect.

What it requires

Every consumer-facing AI agent must inform users they are interacting with an AI system at or before the first message. The 'obvious' exception is interpreted narrowly; a chat widget is not considered self-evidently AI.

How Eniyan satisfies it

Know Your Agent issues each agent a cryptographic identity credential users can verify in one click. Verification & Transparency publishes a consumer-readable verification page operators link to at first interaction, satisfying the disclosure obligation with a third-party-verified, independently hosted artifact.

Article 50(5)
Clear, timely, accessible delivery
Verification & Transparency

The information shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure and shall conform to the applicable accessibility requirements.

What it requires

Disclosure must be clear, distinguishable, and presented at the moment of first interaction. Not buried in a privacy policy, not surfaced only on request, and not shown after the first message is exchanged.

How Eniyan satisfies it

The Eniyan seal and verification badge embed directly in the chat interface, rendered before the first exchange. The public verification page is accessible without login, designed for consumers rather than compliance teams, and meets WCAG accessibility standards.

High-risk AI · additional obligations€30M or 6% global turnover
Article 11 / 13
Technical documentation
Know Your Agent · AI System Cards

High-risk AI systems shall be designed and developed to ensure their operation is sufficiently transparent to enable deployers to interpret a system's output and use it appropriately. Providers shall draw up technical documentation before placing the high-risk AI system on the market.

What it requires

Providers of high-risk AI must produce and maintain structured technical documentation covering the system's purpose, capabilities, limitations, performance metrics, training data, and risk management measures.

How Eniyan satisfies it

AI System Cards automatically generate Article 11/13-compliant technical documentation PDFs from your agent's registered identity and its review evidence. One click from the dashboard, no consultant required.

Article 14
Human oversight
Know Your Agent · JIT Activation

High-risk AI systems shall be designed and developed, including with appropriate human-machine interface tools, in such a way that they can be effectively overseen by natural persons during the period in which the AI systems are used.

What it requires

High-risk AI systems must be designed so human operators can exercise meaningful oversight, including the ability to override or interrupt the AI at any time and to ensure tasks are only assigned to systems under active human authorization.

How Eniyan satisfies it

JIT activation enforces Article 14 at the cryptographic layer: a human operator must authorize each task window before the agent's credential becomes active. When no task window is open, the credential is technically suspended. Every authorization, expiry, and revocation event is logged immutably.

Article 9 / 17
Risk management system
Know Your Agent · Risk Registry

Providers of high-risk AI systems shall establish, implement, document and maintain a risk management system. The risk management system shall be a continuous iterative process run throughout the entire lifecycle of a high-risk AI system.

What it requires

Providers must establish and continuously maintain a documented risk management system: identifying, estimating, evaluating, and mitigating risks throughout the AI system's lifecycle. Records must be producible for regulatory inspection.

How Eniyan satisfies it

The Risk Registry tracks risk entries across your agent fleet, populated from your agents' review evidence or added manually. Each entry captures the risk, its severity, and how it was resolved. Exportable as a formatted Risk Registry Report PDF citing Article 9/17.

All AI systems · logging & GPAI provenance€15–30M
Article 12 / 26
Record-keeping & operational logs
Verification & Transparency · Audit Log Export

High-risk AI systems shall be designed and developed with capabilities enabling the automatic recording of events relevant to identifying risks to health, safety, or fundamental rights during operation. Deployers shall ensure human oversight and keep logs of operations.

What it requires

Providers must build logging capability into high-risk AI systems. Deployers must retain logs of operation and make them available to national competent authorities on request.

How Eniyan satisfies it

Eniyan captures every consequential agent event in a tamper-evident, exportable audit trail. The Compliance Audit Log Export generates a regulatory-formatted PDF or structured CSV, ready for authority submission.

Articles 53–55
GPAI model provenance
Know Your Agent · GPAI Model Registry

Providers of general-purpose AI models shall draw up and keep up to date the technical documentation of the model, including its training process, evaluation results, and known limitations. Providers of AI systems built on GPAI models shall ensure they can obtain the information necessary to comply.

What it requires

Operators deploying AI agents built on General-Purpose AI models (GPT-4o, Claude, Gemini, Llama, etc.) must be able to demonstrate which GPAI model powers each system and obtain the downstream compliance documentation required.

How Eniyan satisfies it

The GPAI Model Registry links each deployed agent to its underlying model, capturing the model's provenance and documented limitations from Eniyan's pre-maintained registry of major GPAI models. This flows directly into AI System Card PDFs.

European Commission Code of Practice on AI Transparency: the final implementation guide is expected June 2026, six weeks before enforcement begins. Eniyan's product is designed to satisfy the obligations as written in the Act and the December 2025 draft guidance. Read the draft guidance

Product coverage

Which capability covers which article

ObligationKnow Your AgentVerification & Transparency
Art. 50(1): AI disclosureCoveredCovered
Art. 50(5): Clear, timely deliveryNot coveredCovered
Art. 11/13: Technical documentationAI System CardsCoveredNot covered
Art. 14: Human oversightJIT ActivationCoveredNot covered
Art. 9/17: Risk management systemRisk RegistryCoveredNot covered
Art. 12/26: Operational loggingAudit Log ExportNot coveredCovered
Art. 53–55: GPAI provenanceGPAI RegistryCoveredNot covered
Affected sectors

Who needs to act before August 2nd

The Act applies wherever your AI agents interact with EU consumers, regardless of where your company is headquartered.

Fintech & BankingCritical
Payment assistants, account chatbots, fraud alert agents
FCA oversight and the EU AI Act create dual compliance pressure. Credit and fraud AI triggers high-risk classification; Articles 13, 14, 9/17 apply in full.
E-commerce & RetailCritical
Shopping assistants, returns agents, customer support bots
Consumer-facing AI at scale across EU jurisdictions. Article 50(1) applies to every customer interaction. Recommendation agents may trigger high-risk classification.
SaaS Customer ExperienceHigh
Intercom Fin, Zendesk AI, Freshdesk agents
Platforms exposing AI to EU end-users are in scope. Deployers bear Article 50 responsibility; platforms must provide disclosure infrastructure.
Healthcare & WellnessHigh
Triage agents, appointment bots, symptom checkers
Patient-facing AI is high-risk under both the EU AI Act and sector rules. Articles 13, 14, 9/17, and 12/26 apply in full.
Legal & Professional ServicesMedium
Legal AI assistants, document review agents
Professional services AI affecting fundamental rights triggers high-risk classification. Article 50 disclosure applies to all consumer interactions.
Logistics & OperationsMedium
Delivery tracking agents, supply chain assistants
Consumer-facing interactions trigger Article 50(1). Lower risk tier unless consequential routing or employment decisions are made.
The path

Article 50 compliant in 48 hours. Full stack in 30 days.

No professional services. No compliance consultant. Article 50 disclosure live in under 15 minutes.

01
Register your agents
Declare each agent's purpose, capabilities, and restrictions using the structured Know Your Agent checklist. Upload your system prompt and tool manifest as supporting evidence.
Minutes, not weeks
02
Eniyan reviews & issues credentials
Our trust team cross-checks your declaration against the evidence. Approved agents receive a cryptographic identity credential and a public verification URL.
Reviewed before going live
03
Embed and disclose at first interaction
Embed the seal or verification link in your chat widget header before the first message is exchanged. Satisfies Article 50(1) and 50(5).
30 minutes
04
Maintain through the lifecycle
Enable JIT for human oversight (Art. 14), log risks in the Risk Registry (Art. 9/17), and export Compliance Audit Logs on demand (Art. 12/26).
Ongoing
The cost of non-compliance

What 6% of global revenue looks like.

A $10M ARR startup
€600K
High-risk violation, potentially company-ending
A $100M revenue company
€6M
Equivalent to roughly 12 months of product runway
A $2B+ enterprise
€120M+
Or capped at €30M, whichever is higher

Article 50 (limited-risk) fines: up to €15M or 3%, whichever is higher. Eniyan starts at $0: one free seal, no credit card.

Article 50 is in force. Get compliant now.

Article 50 in 48 hours. Full stack in 30 days. One free seal to start.