Prohibitions & AI literacy: Practices such as social scoring are banned, and Article 4 requires adequate AI literacy from everyone who provides or deploys AI.
EU AI Act & governance
EU AI Act compliance.In daily work, not in a binder.
The general application date of Regulation (EU) 2024/1689 was 2 August 2026. Prohibitions and the AI literacy duty have applied since 2025; the high-risk deadlines follow in December 2027 and August 2028. Pharen helps your team measure where you stand and keep the register, approvals and evidence where the work happens.
Deadlines & status
The AI Act applies in stages. This is where it stands.
GPAI models: Providers of general-purpose AI models carry their own obligations, and the EU governance structures have been in place since then.
General application: Transparency duties apply: people must be able to tell when they interact with AI or see AI-generated content. Authorities supervise and enforce.
High-risk systems: The Digital Omnibus postponed the deadlines: sensitive use areas by 2 December 2027, AI in regulated products by 2 August 2028.
Approach
How EU AI Act compliance becomes part of daily work.
Take stock: The free EU AI Act check asks ten questions about classification, controls and evidence and shows immediately where your AI use needs attention.
10 questions · about 4 minutesBuild the AI register: Every AI system sits in one central register with owners, roles, data and affected processes instead of scattered lists.
One register, not many listsAnchor the controls: Human approvals, standard reviews and escalation paths run as workflows in Pharen Hub, inside the processes they concern.
Approvals & escalationKeep the evidence: Decisions, documents, logs and recurring checks stay traceable, with history and named owners.
Auditable trailTransparency
Disclosure: Article 50 requires that people can tell when they interact with AI or see AI-generated content.
Approved notices: Wording is reviewed once and then shown consistently everywhere, instead of being rewritten per channel.
Evidence of display: Records show when which notice was shown.
Human oversight
Named owners: A trained person needs the authority and the information to intervene, override or stop the system.
Approvals in the workflow: Critical actions pass through explicit approval steps instead of a quick shout across the room.
A click is not oversight: A nominal review without a real ability to intervene does not remove the risk.
Documentation
Documented classification: For every system there is a record of how and why it was classified, with purpose, role and affected groups.
Records at the use case: Vendor documents, contracts and decisions live with the system, not in inboxes.
Versions & templates: Reviews follow reusable templates, and changes stay visible in the history.
Monitoring & incidents
Defined signals: It is agreed which deviations count and at which intervals checks run.
Clear responsibility: Incidents go to named owners, with a traceable response path.
Checks as tasks: Recurring reviews run as scheduled tasks, not as good intentions.
AI literacy
A duty since February 2025: Article 4 requires adequate AI literacy from providers and deployers of AI systems.
Role-based: Training follows what a role actually does with AI, not a one-size course.
Demonstrable: Learning content, work instructions and completions are assigned to the specific use case.
Tools & sources
Self-assessment
Measure first, then plan the work.
The EU AI Act check is based on Regulation (EU) 2024/1689 and the official European Commission FAQs. It does not replace legal advice, but it gives you an honest first reading: a readiness score, a classification signal and prioritised gaps.
FAQ
Questions & answers
Any organisation that provides or deploys AI systems in the EU, regardless of size. The regulation distinguishes roles such as provider, deployer, importer and distributor; which duties apply depends on the role and the risk class of the system.
Prohibitions and AI literacy have applied since February 2025, GPAI duties since August 2025, transparency and supervision since August 2026. The Digital Omnibus of June 2026 postponed the high-risk deadlines: Annex III by 2 December 2027, Annex I by 2 August 2028.
Since February 2025, Article 4 obliges providers and deployers to ensure adequate AI literacy for the people who operate or oversee AI systems. Role-based content and documented completions make that verifiable; the regulation does not prescribe a specific course.
Article 5 bans, among other things, social scoring, manipulative or exploitative systems and specified biometric practices, each with detailed conditions and exceptions. These prohibitions have applied since February 2025. Whether a concrete case falls under them belongs in qualified legal review.
They apply side by side. The GDPR governs personal data, while the EU AI Act classifies AI systems by risk and attaches duties to that classification. An AI deployment therefore has to answer both: legal basis and data flows as well as classification, controls and evidence.
No. Software alone does not create legal compliance. Pharen structures what compliance needs: a register, approvals, monitoring and auditable evidence. The legal classification of your systems stays with qualified advisers.



