Your Mission: Prevent Compliance Disasters
Every organization handling AI faces the same question: Are we compliant with the EU AI Act? Fines reach up to €35M or 7% of global turnover for prohibited practices. You have 5 Realms to master, 100 Trust Credits at stake, and unlimited potential to become an AI Compliance Expert.
EU AI Act Compliance: Free Interactive Course
Learn AI compliance in Europe by doing: five hands-on challenges on prohibited practices, high-risk AI systems, Article 50 transparency, general-purpose AI and regulatory sandboxes.
Updated for the Digital Omnibus on AI (Regulation (EU) 2026/1744), with every answer linked to the AI Act article it comes from. Free, no sign-up, about 25 minutes.
EU AI Act timeline after the Digital Omnibus (2026)
Last reviewed:
The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved several AI Act deadlines:
- 2 Feb 2025: Article 5 prohibitions apply.
- 2 Aug 2025: General-purpose AI model obligations apply.
- 2 Aug 2026: Article 50 transparency obligations apply: chatbot disclosure, deepfake labels, and machine-readable marking for generative AI placed on the market from this date.
- 2 Dec 2026: Machine-readable marking deadline for generative AI already on the market before 2 Aug 2026, and the new ban on AI that generates non-consensual intimate imagery or child sexual abuse material.
- 2 Aug 2027: Deadline for each Member State to set up a national AI regulatory sandbox.
- 2 Dec 2027: Annex III high-risk obligations (biometrics, critical infrastructure, education, employment, credit scoring, law enforcement), postponed from 2 Aug 2026.
- 2 Aug 2028: High-risk AI in products covered by Annex I EU legislation, such as medical devices and machinery, postponed from 2 Aug 2027.
The Omnibus also extended SME relief to small mid-cap companies (fewer than 750 employees and up to €150M turnover or €129M balance sheet), softened the AI literacy duty in Article 4, added an EU-level sandbox, allowed processing of special categories of personal data to detect and correct bias, and gave the AI Office more oversight of general-purpose AI.
EU AI Act compliance checklist
A starting point for product, engineering, legal and compliance teams in Europe and for non-EU companies whose AI is used in the EU.
- Inventory your AI. List every AI system and general-purpose AI model you build, buy or use, and where its output is used.
- Define your role. For each system, decide whether you are a provider, deployer, importer or distributor. Changing a system's intended purpose can make you its provider (Art. 25).
- Rule out prohibited practices. Check every use against Article 5, including the two bans added from 2 December 2026.
- Classify risk. Check Annex I and Annex III. If you conclude an Annex III system is not high-risk under Article 6(3), document why and register it in the EU database.
- Plan for high-risk requirements. Risk management, data governance, technical documentation, logging, instructions for deployers, human oversight, and accuracy, robustness and cybersecurity (Art. 9 to 15), ready by 2 December 2027 or 2 August 2028.
- Meet Article 50 now. Disclose chatbots and deepfakes, and mark AI-generated content in a machine-readable way.
- Check GPAI duties. If you provide a general-purpose AI model: technical documentation, downstream information, a copyright policy and a public training-data summary (Art. 53).
- Support AI literacy. Take measures so the people who build and use your AI understand it (Art. 4).
The Five Realms of the EU AI Act Compliance Quest
This interactive course guides learners through five practical EU AI Act compliance challenges. Each realm combines a short scenario with a decision exercise so product, engineering, legal, and compliance teams can apply the regulation to real AI systems.
- Realm 1 - Prohibited Practices: Classify AI uses such as social scoring, harmful manipulative techniques, untargeted facial-image scraping, real-time biometric identification for law enforcement, and emotion recognition in the workplace, while distinguishing them from permitted uses.
- Realm 2 - High-Risk Systems: Match healthcare, employment, education, and other high-risk scenarios to risk-management, data-governance, documentation, human-oversight, monitoring, and cybersecurity controls.
- Realm 3 - Transparency: Decide when chatbots, synthetic media, generated images, and other AI outputs need clear disclosure labels so people know when they are interacting with or viewing AI-generated content.
- Realm 4 - General-Purpose AI: Work through GPAI provider responsibilities, including systemic-risk assessment, copyright and training-data transparency, downstream-use safeguards, technical documentation, and cooperation with regulators.
- Realm 5 - Regulatory Sandbox: Build a controlled compliance plan for innovative AI applications, selecting validation, bias audits, human oversight, incident logging, cybersecurity, data protection, and regulatory coordination measures.
Realm 1: Prohibited Practices
Drag & Drop: Identify illegal AI applications under the EU AI Act
📋 Your Task: Sort AI applications into "Prohibited" and "Allowed" categories.
⚠️ Five are banned under Article 5. ✓ Three are not prohibited.
📦ITEMS (8)
Social scoring that leads to unjustified detrimental treatment of people
Untargeted scraping of facial images to build recognition databases
Subliminal or manipulative techniques that cause significant harm
Real-time remote biometric identification in public spaces for law enforcement (outside narrow exceptions)
Emotion recognition of employees in the workplace
AI-powered content recommendations on social media
Email spam filtering using AI
Real-time translation for accessibility
PROHIBITED5
✓ 0/5 items placed
ALLOWED3 items
✓ 0/3 items placed
EU AI Act Compliance FAQs
Q: What is the EU AI Act?
A: The EU AI Act (Regulation (EU) 2024/1689) is the European Union's law on artificial intelligence. It entered into force on 1 August 2024 and applies in stages: prohibited practices since 2 February 2025, general-purpose AI (GPAI) model rules since 2 August 2025, transparency obligations from 2 August 2026, and high-risk obligations from 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
Q: What is the Digital Omnibus on AI (Regulation (EU) 2026/1744)?
A: Regulation (EU) 2026/1744, the Digital Omnibus on AI, amends the AI Act. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It postponed high-risk deadlines, added two prohibited practices, extended SME relief to small mid-cap companies, softened the AI literacy duty, created an EU-level regulatory sandbox and strengthened the AI Office's oversight of general-purpose AI.
Q: When do high-risk AI obligations apply after the Digital Omnibus?
A: Stand-alone high-risk AI systems listed in Annex III, such as AI for biometrics, critical infrastructure, education, employment, credit scoring and law enforcement, must comply from 2 December 2027. High-risk AI embedded in products covered by Annex I EU legislation, such as medical devices and machinery, must comply from 2 August 2028. Both dates were previously 2 August 2026 and 2 August 2027.
Q: What AI practices are prohibited under the EU AI Act?
A: Article 5 bans harmful subliminal or manipulative techniques, exploiting vulnerabilities, social scoring that leads to detrimental treatment, predicting crime based solely on profiling, untargeted scraping of facial images, emotion recognition in workplaces and schools, biometric categorisation that infers sensitive traits, and real-time remote biometric identification in public spaces for law enforcement outside narrow exceptions. From 2 December 2026 it also bans AI systems that generate non-consensual intimate imagery or child sexual abuse material.
Q: What are the fines under the EU AI Act?
A: Under Article 99, fines reach up to €35 million or 7% of worldwide annual turnover for prohibited practices, €15 million or 3% for most other breaches, and €7.5 million or 1% for supplying incorrect information. For SMEs and small mid-caps the lower of the two amounts applies. GPAI model providers face up to €15 million or 3% under Article 101.
Q: What transparency requirements does the EU AI Act set?
A: From 2 August 2026, Article 50 requires telling people when they interact with an AI system, disclosing deepfakes, and informing people exposed to emotion recognition or biometric categorisation. Providers of generative AI must mark output in a machine-readable way: systems placed on the market from 2 August 2026 must do so from launch, while systems already on the market before then have until 2 December 2026.
Q: Does the EU AI Act apply to companies outside the EU?
A: Yes. The AI Act applies to providers that place AI systems or GPAI models on the EU market, and to providers and deployers outside the EU when the output of their AI system is used in the EU. Non-EU providers of high-risk systems and GPAI models must appoint an authorised representative in the EU.
Q: Is AI literacy still mandatory under the EU AI Act?
A: The Digital Omnibus rewrote Article 4. Instead of having to ensure a sufficient level of AI literacy, providers and deployers must now take measures to support the development of AI literacy among their staff, while the Commission and Member States take a stronger role in promoting it.
Q: How do AI regulatory sandboxes work?
A: Under Articles 57 to 60, companies can develop and test AI under the supervision of a competent authority. Member States must set up national sandboxes by 2 August 2027, and the Digital Omnibus adds an EU-level sandbox with priority access for SMEs and small mid-caps. Sandboxes give guidance and an exit report that can support conformity assessment, but they are not an approval or exemption: the system must still comply before it is placed on the market.
Why Choose Our Interactive Quest?
Comprehensive Coverage
All five areas of the EU AI Act: prohibited practices, high-risk systems, transparency, GPAI and regulatory sandboxes
Interactive Learning
Hands-on exercises with real compliance scenarios. Earn trust credits for correct decisions.
Expert-Designed
Built by a product manager with 7+ years in fintech and AI products; every answer maps to an AI Act article
Real-World Scenarios
Navigate actual compliance challenges: risk assessment, documentation, monitoring, and incident reporting
Designed by Ragavendra Murugadass
A Product Manager & AI Specialist with 7+ years of experience in digital products, fintech and AI. This compliance quest makes learning the EU AI Act straightforward and practical for anyone involved in AI governance.
Product Manager
AI Specialist
Expertise & Focus Areas:
Ready to understand the EU AI Act?
Work through the 5 realms at your own pace and earn Trust Credits for compliant decisions.