veille Resource, Regulatory Guide
EU AI Act, European Union

The EU AI Act applies to your organization, even if you've never filed anything in Brussels.

Regulation 2024/1689 has extraterritorial reach. Any organization whose AI systems affect individuals in the EU falls within scope, regardless of where the organization is established. For Canadian enterprises in finance, SaaS, and HR, that is already a live obligation.

In forceAugust 1, 2024
Annex III deadline2 December 2027 (deferred from 2 Aug 2026, Digital Omnibus)
Max penalty€35M or 7% worldwide revenue

Extraterritorial scope

Does it apply to Canadian organizations?

Yes, if your AI system produces outputs used within the European Union, or if your system affects individuals in the EU, the Act applies regardless of where you are established.

In scope for most Canadian enterprises:

  • SaaS platforms with European customers
  • HR systems screening EU-resident candidates
  • Financial institutions with European subsidiaries or counterparties
  • Insurance and credit companies serving European residents
  • AI outputs used by EU-based business partners in regulated processes

Risk classification

Four tiers, obligations differ significantly.

Unacceptable Prohibited AI systems
In force since February 2025. Examples: social scoring by public authorities, real-time biometric identification in public spaces, subliminal manipulation. Most commercial applications are not in this category.
High risk Annex III, specific categories
Mandatory: conformity assessment, technical documentation, human oversight, accuracy standards, transparency to deployers.
  • Employment and recruitment (CV screening, promotion decisions)
  • Access to essential services (credit, insurance)
  • Education (admissions, assessment)
  • Critical infrastructure management
Limited risk Transparency obligations
Systems that interact with humans must disclose that they are AI. Chatbots, virtual assistants, deepfakes, and AI-generated content fall here.
Minimal risk Largely unregulated
Spam filters, AI-powered games, recommendation systems for non-critical content. Voluntary codes of conduct may apply. No mandatory requirements under the Act.

Annex III

High-risk categories relevant to Canadian organizations.

ReferenceCategoryCanadian relevance
§4 Employment & workers management CV screening, shortlisting, promotion decisions affecting EU-resident individuals
§5 Access to essential private services Credit scoring, insurance risk assessment, eligibility for financial products for EU residents
§3 Education & vocational training Admissions, assessment, learning outcome evaluation for EU-based students
§1 Biometric categorisation Biometric identification, emotion recognition in professional contexts

Compliance timeline

Key dates as of July 2026.

Digital Omnibus update

High-risk (Annex III) obligations apply 2 December 2027, deferred from 2 August 2026 by the Digital Omnibus on AI (agreement 7 May 2026, endorsed by the European Parliament 16 June 2026; formal Council adoption pending). Preparatory obligations (documentation, registration) remain active. Article 50 transparency obligations stay on the original schedule (2 August 2026).

Aug. 2024
Act enters into force. Regulation 2024/1689 published. 24-month transition for most provisions.
Feb. 2025
Prohibited practices in force. Bans on social scoring, certain biometric systems, and manipulative AI take effect.
Aug. 2025
GPAI rules in force. General-Purpose AI model obligations apply to frontier model providers.
Now
Preparation window. Complete AI inventory, identify Annex III systems, begin technical documentation. High-risk enforcement deferred to 2 December 2027 by the Digital Omnibus.
2 Dec. 2027
Annex III, high-risk deadline. Full conformity assessments, human oversight, and registration requirements for high-risk systems. Deferred from 2 August 2026 by the Digital Omnibus on AI.

Penalties

Fines calibrated to the severity of the violation.

€35M or 7%
For violations of prohibited practices (Article 5 prohibitions)
€15M or 3%
For non-compliance with high-risk system obligations
€7.5M or 1%
For providing incorrect information to authorities

How Veille helps

EU AI Act coverage in Veille AI.

Veille identifies whether each registered system falls within a high-risk Annex III category, what documentation is required, and what gaps exist. When changes are detected, such as the Annex III deadline revision, all affected systems are re-evaluated within 4 hours.

Coverage note

Veille's EU AI Act coverage focuses on Annex III high-risk obligations and general-purpose AI transparency requirements. Conformity assessment processes (which require a notified body for some systems) are outside Veille's scope, the platform provides the documentation and gap analysis that feeds into that process.

Find out

Is your AI in scope?

A 30-minute conversation is enough to map your systems against EU AI Act risk tiers and identify which obligations apply.

Book a call