Galeops

The EU AI Act's high-risk deadline is August 2, 2026 — 9 days from this article's publication. If your AI system serves EU users and falls under Annex III, you have days to meet conformity obligations. Fines start at €15M or 3% of global turnover.

Most U.S. AI founders are watching the EU AI Act the way they watched GDPR in 2018 — "it doesn't apply to us." It does. The Act is extraterritorial. If your product is used in the EU, even by free-tier users, the high-risk rules apply.

Does This Actually Apply to You?

Annex III covers systems used in biometrics, critical infrastructure, employment, education, access to essential services, law enforcement, migration, and administration of justice.

What "Compliance" Actually Means in 9 Days

You don't have to be perfect by August 2. You have to be defensible. The high-risk requirements break into four practical workstreams: risk management system, data governance, technical documentation, and human oversight and transparency.

The 9-Day Sprint

  • Day 1: Risk snapshot — map your system against OWASP LLM Top 10 + high-risk failure modes
  • Days 2-4: Full technical documentation package — architecture review, data flow, risk register, bias/prompt-injection/red-team findings
  • Days 5-7: Guardrail implementation — input/output filtering, human-in-the-loop gates, audit logging, override controls
  • Days 8-9: Structured adversarial testing with a written report your legal/compliance team can hand to regulators or customers

What to Do Right Now

  1. Confirm whether your product touches any Annex III use case
  2. Document your current risk management and data governance practices
  3. Get a technical audit that produces evidence, not just opinions
  4. Talk to your legal/compliance team with the audit in hand

The companies that get ahead of this won't be the ones with the biggest legal budgets. They'll be the ones with the best technical evidence.