The Apryse Summer 2026 Release: OUT NOW

Apryse Deep Dive

A Complete Guide to the EU AI Act

This guide explains what the AI Act covers, who it applies to, the implementation timeline, potential penalties, and how Apryse helps developers build document workflows that support compliance.

Quick Summary

TL;DR

The EU AI Act is no longer a future regulation. As of August 2026, its transparency rules and prohibited-practice bans are already in force, and organizations that develop or deploy AI systems in the EU now face real, active obligations – with high-risk AI rules following on a delayed but confirmed timeline through 2027 and 2028.

  • The EU AI Act is the world's first comprehensive legal framework for artificial intelligence, designed to ensure AI systems used in Europe are safe, transparent, and accountable. Organizations that fail to comply can face serious fines.
  • As regulatory scrutiny increases, organizations must be able to demonstrate human oversight, trace decisions back to their source, and maintain reliable records of AI-assisted processes.
  • Apryse provides the document processing components developers use to build traceable, auditable, and human-reviewed AI workflows.

Risk Categories of the AI Act

The EU AI Act takes a risk-based approach. The greater the potential impact of an AI system on people, safety, or fundamental rights, the stricter the compliance requirements:

Sanity Image

Unacceptable Risk

AI practices considered a clear threat to individuals are prohibited. Examples include social scoring, exploitative AI targeting vulnerable groups, and certain real-time biometric identification systems used in public spaces.

High Risk

AI systems used in areas such as employment, education, critical infrastructure, healthcare, and law enforcement. These systems must meet strict requirements for risk management, data governance, documentation, and human oversight. 

Limited Risk

AI systems with transparency obligations, such as chatbots or AI-generated content that must be disclosed to users.

Minimal Risk

Unregulated applications that pose little to no risk, such as AI-enabled video games or spam filters.

Who Does the AI Act Apply To?

The EU AI Act applies to organizations both inside and outside the EU whenever AI systems are placed on the EU market or their outputs are used within the Union.

Providers

Organizations that develop AI systems and place them on the EU market or put them into service.

Deployers

Organizations that use AI systems under their authority within the EU.

Organizations Outside the EU

Providers and deployers located outside the EU when the output of their AI system is used within the Union.

AI Act Implementation Timeline

The Act is being rolled out in stages through 2028. In May 2026, the EU adopted a "Digital Omnibus" amendment that pushed back several high-risk deadlines – the dates below reflect that update.

  • August 1, 2024 – The EU AI Act entered into force.
  • February 2, 2025 – Prohibited AI practices (Unacceptable Risk) became enforceable.
  • August 2, 2025 – Rules for General-Purpose AI (GPAI) models and governance frameworks took effect.
  • August 2, 2026 – Transparency obligations (Article 50) become enforceable, covering chatbots, emotion-recognition systems, and disclosure of AI-generated content.
  • December 2, 2026 – A new prohibition on deepfakes/CSAM takes effect.
  • December 2, 2027 – High-risk AI obligations for standalone systems under Annex III (employment, education, law enforcement, and similar sensitive-use categories) become enforceable.
  • August 2, 2028 – Full compliance required for high-risk AI embedded in regulated products under Annex I.
Our Capabilities

How Apryse Supports EU AI Act Requirements

Pillar 1: Data Governance & Privacy

Before documents are used for AI training, retrieval, or inference, PII needs to be identified and removed. Apryse Redaction automates that – permanently removing personally identifiable information from documents at scale.

For scanned and image-based documents, OCR and ICR capabilities combine with redaction workflows to catch sensitive information sitting outside machine-readable text layers.

Sanity Image

Pillar 2: Traceability & Record-Keeping

Compliance also means being able to show your work. Apryse Smart Data Extraction turns unstructured documents into structured, layout-aware JSON while preserving document context. This way, extracted data stays traceable to its original source, supporting transparency, auditability, and repeatability in document processing and RAG workflows.

Sanity Image

Pillar 3: Human Oversight

And compliance requires a human checkpoint. With Apryse WebViewer, developers can build review workflows where users inspect, validate, approve, or reject AI-generated outputs before they enter business processes.

Sanity Image

Check where you stand

Get the checklist and find out where you stand under the EU AI Act – your role, your risk category, and the controls you need. It's built for teams building or using AI in document workflows.

Sanity Image
Our Value

Why Apryse?

Secure Deployment

Deploy document processing entirely in the browser, on private infrastructure, or within controlled cloud environments to keep sensitive information inside your organization's security boundaries.

High-Fidelity Document Processing

Industry-leading rendering and data extraction provide a reliable foundation for AI applications that depend on accurate document data.

Built for Enterprise Scale

Trusted by 85 of the Fortune 100 and backed by more than 25 years of document technology expertise, Apryse helps enterprises deploy document processing at production scale.

Build Document Workflows That Are Ready for the EU AI Act

Whether you're preparing for the Annex III high-risk deadline in December 2027 or strengthening governance across existing document workflows today, Apryse gives developers the secure document processing components to build with confidence.

Get Exclusive Access to the

EU AI Act Compliance Checklist for Document Workflows

This checklist walks you through where you stand under the EU AI Act – your role, your risk category, and the controls you need. It's built for teams building or using AI in document workflows.

Frequently Asked Questions

Yes. The Act applies to organizations outside the EU when AI systems are placed on the EU market or when their outputs are used within the European Union.

The EU AI Act uses a tiered penalty framework. Fines are based on the severity of the violation and calculated as the higher of a fixed amount or a percentage of global annual turnover (Article 99).

  • Prohibited AI Practices: Fines of up to €35 million or 7% of global annual turnover apply to banned AI practices such as social scoring, exploitative AI, and certain biometric surveillance uses.
  • High-Risk AI Violations: Fines up to €15 million or 3% of global annual turnover apply to failures in risk management, data governance, human oversight, and other mandatory requirements.
  • Transparency & Reporting Violations: Fines up to €7.5 million or 1% of global annual turnover apply to failing to disclose AI interactions, label deepfakes, provide required records, or supplying misleading information to regulators.

Regulators may also require remediation plans, suspend AI systems, withdraw non-compliant products from the market, prohibit their placement on the EU market, or publicly disclose violations.

Apryse provides secure document processing, PII redaction, OCR, structured data extraction, auditability, and human-in-the-loop review capabilities that help developers build AI document workflows aligned with the governance requirements of the EU AI Act.

The two regulations address different areas. GDPR governs the processing of personal data, while the EU AI Act regulates the development and use of AI systems. Organizations using AI with personal data often need to comply with both.