> ## Documentation Index
> Fetch the complete documentation index at: https://docs.grantex.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# EU AI Act

> The EU AI Act timeline as amended by Regulation (EU) 2026/1744, provider and deployer obligations, and how Grantex records can help evidence them, with their limits.

## Overview

The **EU AI Act** is Regulation (EU) 2024/1689. It entered into force on
1 August 2024 and applies in stages. It was amended by the AI Omnibus,
**Regulation (EU) 2026/1744**, which entered into force on 27 July 2026 and
moved the high-risk dates. The dates below are those of the amended text, as
of 30 September 2026.

Most of the Act's detailed duties attach to **high-risk AI systems** and fall
on their **providers** (who develop a system and place it on the market or put
it into service under their name) and **deployers** (who use it under their
authority). Grantex is an authorisation layer: it records which agent was
allowed to do what, on whose authority, and what happened. Those records can
help evidence some of these duties. They do not make a system compliant.

<Warning>
  This page maps Grantex features to EU AI Act provisions. It is not legal
  advice, not a conformity assessment and not a certification: only the
  conformity assessment procedures of the Act (and CE marking where they
  require it) establish conformity. Whether a duty applies depends on your
  role and on how your AI system is classified. Consult qualified counsel.
</Warning>

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner:
Sanjeev Kumar. Ownership or IP questions may be sent to
[sanjeev@orchestrum.in](mailto:sanjeev@orchestrum.in) or
[mishra.sanjeev@gmail.com](mailto:mishra.sanjeev@gmail.com).

## Timeline

| Date | What applies |
| - | - |
| **1 August 2024** | The Regulation enters into force |
| **2 February 2025** | Art. 4 AI literacy and the Art. 5 prohibited practices |
| **2 August 2025** | Obligations for general-purpose AI (GPAI) models (Arts. 53-55), governance, and penalties (except Art. 101) |
| **2 August 2026** | General application, including the **Art. 50** transparency obligations; Commission enforcement of GPAI obligations and Art. 101 fines |
| **2 December 2026** | End of the Art. 50(2) marking grace period for generative systems placed on the market before 2 August 2026; the new Art. 5 prohibition of AI systems that generate non-consensual intimate imagery or child sexual abuse material applies |
| **2 August 2027** | GPAI models placed on the market before 2 August 2025 must comply |
| **2 December 2027** | High-risk obligations for **Annex III** (stand-alone) systems (previously 2 August 2026) |
| **2 August 2028** | High-risk obligations for **Annex I** (product-embedded) systems (previously 2 August 2027) |

The separate "Digital Omnibus" on data protection (COM(2025) 837) is still a
proposal; the GDPR is unchanged.

## Roles and classification

* A team that builds an agent on a third-party model is usually the
  **provider** of an AI system, a **deployer** of it, or both. It is not a GPAI
  model provider unless it places a general-purpose model on the market.
* An authorisation layer such as Grantex is not itself a high-risk AI system.
  An agent is high-risk if it falls under Art. 6: a safety component of an
  Annex I product, or a use listed in Annex III (for example credit scoring,
  recruitment or access to essential services).
* Art. 6(3) lets a provider conclude that an Annex III system is not high-risk
  when it does not pose a significant risk, but never when it profiles natural
  persons; the provider documents that assessment and registers the system
  (Art. 6(4)). The Commission's classification guidelines were published as a
  draft on 19 May 2026.

## Obligations and what Grantex provides

| Article | Who, from when | Requirement (summary) | What Grantex provides | What remains yours |
| - | - | - | - | - |
| **Art. 4** AI literacy | Providers and deployers, 2 Feb 2025 | As amended, take measures to support the development of AI literacy of staff and others operating AI systems on their behalf | Nothing specific | Training and literacy measures |
| **Art. 5** Prohibited practices | All operators, 2 Feb 2025; the new NCII and CSAM prohibition from 2 Dec 2026 | Do not place on the market or use the listed practices | Nothing specific | Not building or using them |
| **Art. 9** Risk management | High-risk providers | A documented, lifecycle risk management system | Controls you can cite as risk measures: scoped, time-limited, revocable grants; delegation that can only narrow authority; budgets and caps; policies | The risk management system itself |
| **Art. 10** Data governance | High-risk providers | Training, validation and test data governance (bias-related special-category processing now in Art. 4a) | Nothing specific | Your data governance |
| **Art. 11 + Annex IV** Technical documentation | High-risk providers | Technical documentation, kept for 10 years (Art. 18) | Exports can be annexed as records | Writing and keeping the documentation |
| **Art. 12** Record-keeping | High-risk systems (provider designs, deployer keeps) | Automatic recording of events over the system's lifetime | The developer's hash-chained audit log of authorisation, delegation, revocation and DPDP events; the [evidence export](/api-reference/dpdp/eu-ai-act-evidence) reports its integrity and time span | Logging inside the AI system itself (inputs, outputs, model events); Grantex records authorisation events only |
| **Art. 13** Transparency to deployers | High-risk providers | Instructions for use | Nothing specific | Writing the instructions |
| **Art. 14** Human oversight | High-risk systems | People able to understand, not over-rely on, interpret, override, intervene in or stop the system | Human consent before a grant; [decision grants](/concepts/decision-grants) for approval of individual actions; payment approvals; revocation with cascade; the operator override (`POST /v1/emergency-stop`, when enabled); the evidence export counts each | Assigning competent people and designing the oversight |
| **Art. 15** Accuracy, robustness, cybersecurity | High-risk providers | Appropriate levels throughout the lifecycle | Token binding, audience and revocation checks contribute to cybersecurity | The system's accuracy and robustness |
| **Art. 17** Quality management | High-risk providers | A documented quality management system | Configuration as code (Terraform provider), versioned policies, and exports as records | The QMS |
| **Art. 19(1)** Logs kept by providers | High-risk providers | Keep automatically generated logs under their control for **at least six months** | Grantex never deletes or rewrites audit entries; retention is your database's | Keeping logs at least that long (a minimum, not a maximum) |
| **Art. 26** Deployers | High-risk deployers | Use per instructions; human oversight; monitor and inform the provider; keep logs **at least six months** (26(6)); inform workers; inform affected persons of Annex III decisions (26(11)) | Per-agent grants and scopes in the evidence export (`art26Deployer`); event streams and webhooks for monitoring | The deployer duties themselves |
| **Art. 27** Fundamental rights impact assessment | Only public bodies, private providers of public services, and deployers of Annex III 5(b) credit scoring and 5(c) life and health insurance | A FRIA before first use | Nothing specific | The FRIA, where it applies |
| **Art. 50** Transparency | Providers and deployers of certain AI systems, 2 Aug 2026 | Tell people they are interacting with an AI system unless obvious (50(1)); mark generated content in a machine-readable way (50(2)); disclose emotion recognition and biometric categorisation (50(3)); disclose deepfakes and AI-generated public-interest text (50(4)); at the latest at first interaction (50(5)) | **Not recorded.** The evidence export states `art50Transparency.recorded: false` | The disclosures and their evidence, from your own systems. The Code of Practice on marking and labelling AI-generated content (10 June 2026) is voluntary |
| **Art. 72** Post-market monitoring | High-risk providers | A post-market monitoring system and plan | Audit and event data as inputs | The system and plan |
| **Art. 73** Serious incidents | High-risk providers (deployers inform them) | Report not later than **15 days** after awareness; **2 days** for a widespread infringement or critical infrastructure; **10 days** in the event of a death; an incomplete initial report is allowed | The DPDP breach register lists personal data breaches; the evidence export includes them under `art73Incidents` | Deciding whether an incident is serious and reporting it; Grantex classifies and reports nothing |

GPAI model obligations are in Arts. 53-55, not Art. 50.

## The EU AI Act evidence export

`POST /v1/dpdp/exports` with `"type": "eu-ai-act-evidence"` returns sections
mapped to Arts. 12, 14, 26, 50 and 73, each naming its data source, with an
`applicability` block of the dates above and a disclaimer that it is evidence
for the operator's own assessment, not a conformity assessment:

```bash theme={null}
curl -X POST https://api.grantex.dev/v1/dpdp/exports \
  -H "Authorization: Bearer $GRANTEX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "type": "eu-ai-act-evidence", "dateFrom": "2026-08-01T00:00:00Z", "dateTo": "2026-08-31T23:59:59Z" }'
```

See [EU AI Act Evidence Pack](/api-reference/dpdp/eu-ai-act-evidence) for
every field. The older `eu-ai-act-conformance` type is kept for compatibility;
despite its name, it is not a conformity assessment.

## Examples

Register an agent with narrow scopes and ask a person for a grant (the grant
bounds what the agent may do, and the person's approval is recorded):

```typescript theme={null}
import { Grantex } from '@grantex/sdk';

const grantex = new Grantex({ apiKey: process.env.GRANTEX_API_KEY });

const agent = await grantex.agents.register({
  name: 'shopper-01',
  description: 'Places orders the user approves on merchant.example',
  scopes: ['catalog:read', 'orders:create'],
});

const request = await grantex.authorize({
  agentId: agent.id,
  userId: 'user_abc123',
  scopes: ['catalog:read', 'orders:create'],
  expiresIn: '24h',
});
// Send the person to request.consentUrl to approve or deny.
```

Stop an agent's authority, including every grant delegated from it
(Art. 14 intervention), and collect audit-chain evidence for a period:

```typescript theme={null}
await grantex.grants.revoke('grnt_01HXYZ...');

const pack = await grantex.compliance.evidencePack({
  since: '2026-08-01T00:00:00Z',
  until: '2026-08-31T23:59:59Z',
});
console.log(pack.chainIntegrity.valid);
```

## Penalties (Art. 99)

* Prohibited practices (Art. 5): up to EUR 35 million or 7% of worldwide
  annual turnover, whichever is higher.
* Most operator obligations, including those of providers (Art. 16),
  deployers (Art. 26) and Art. 50: up to EUR 15 million or 3%.
* Supplying incorrect or misleading information to authorities: up to
  EUR 7.5 million or 1%.
* For SMEs, including start-ups, and small mid-caps, each cap is the **lower**
  of the two amounts.
* GPAI model providers (Art. 101): up to EUR 15 million or 3%, enforceable by
  the Commission from 2 August 2026.

## Cross-framework mapping

These are technical mappings, not a statement that any framework is met.

| Grantex feature | EU AI Act | DPDP Act 2023 | OWASP ASI |
| - | - | - | - |
| Scoped, time-limited grants | Art. 9 (a risk control) | s.4 (purposes recorded; scopes bound authority) | ASI-01 (goal hijacking) |
| Per-agent DID | Art. 12 (attribution in logs) | — | ASI-03 (identity abuse) |
| Delegation that can only narrow | Art. 9 (a risk control) | — | ASI-05 (privilege escalation) |
| Revocation with cascade | Art. 14 (intervene or stop) | s.6(6) (cease processing after withdrawal) | ASI-10 (rogue agents) |
| Human consent and decision grants | Art. 14 (human oversight) | s.6 (consent) | — |
| Hash-chained audit log | Art. 12 and Arts. 19(1), 26(6) (logs) | r.6(1)(e), r.8(3) (one-year logs) | — |
| Breach register | Art. 73 (input to the incident decision) | s.8(6), r.7 (breach intimation) | — |

## Sources

* [European Commission: AI Act regulatory framework](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai)
* [European Commission: the AI Omnibus enters into force](https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force)
* [AI Act Service Desk: article texts](https://ai-act-service-desk.ec.europa.eu/en/ai-act) (some article pages may still show the text before Regulation (EU) 2026/1744)

## Related Resources

* [DPDP Act 2023](/compliance/dpdp-act-2023) — India's data protection mapping
* [DPDP Compliance Module](/features/dpdp-compliance) — features and examples
* [EU AI Act Evidence Pack](/api-reference/dpdp/eu-ai-act-evidence) — export reference
* [Compliance Evidence Pack API](/api-reference/compliance/generate-compliance-evidence-pack) — audit-chain evidence
* [Compliance Matrix](/guides/compliance-matrix) — cross-framework mapping
* [OWASP Agentic Top 10 Blog](/blog/owasp-agentic-top-10-compliance) — threat taxonomy mapping


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.