Solutions
Partners
Company
Resources
Platform
EXPLORE
FEATURES
SUCCESS STORIES
All Capabilities
No-Code Development
Built enterprise apps without writing code
Agentic AI
Governed AI agents for enterprise workflows
Architecture
Micro-agent orchestration. Built for scale
Security
Full control over every AI decision
Integrations
Connect any system, instantly
Start for Free
Create your WEM Account
WEM is an easy-to-use platform, with the WEM Modeler as its online building environment.
FEATURES
No-Code Development
Built enterprise apps without writing code.
Agentic AI
Governed AI agents for enterprise workflows.
Architecture
Micro-agent orchestration. Built for scale.
Security
Full control over every AI decision.
Integrations
Connect any system, instantly.
Documentation
Technical guides and API references.
Training
Master the WEM platform.
INDUSTRY SOLUTIONS
Government
Compliant automation for public sector.
Logistics & Transportation
Automate supply chain and fleet operations.
Manufacturing
ERP extension and process orchestration.
Healthcare
Governed AI for regulated clinical workflows.
Other Industries
Automation built for your sector.
USE CASES
Business Process Automation
Replace manual workflows with governed automation
Legacy System Modernization
Modernize without replacing your core systems
Customer & Supplier Portal
Branded portals your clients actually use
Tools and Apps
Purpose-built apps for any process
Core Systems & Orchestrated AI
Orchestrate your most critical operations
SAP Extensions
Extend SAP without custom development
ROLE-BASED SOLUTIONS
CIO
Strategic IT leadership tools.
Business Leader
Drive growth and efficiency.
IT Leader
Manage development and operations.
JOIN THE NETWORK
Find a Partner
Certified experts to build your apps.
Become a Partner
Join our global network.
Partner Portal
Resources for existing partners.
OUR ORGANIZATION
About Us
Our mission & story.
Contact Us
Get in touch with our team.
CONTENT LIBRARY
Customer Stories
Real-world success stories.
Events
Meet us at global events.
QUICK START
Start for Free
Begin your no-code journey.
Forum
Join the community discussion.
Support
Get help from our experts.
EDUCATION
Academy
Structured learning paths.
Documentation
Technical references.
Automate supply chain and fleet operations
EXPLORE
INDUSTRY SOLUTIONS
SUCCESS STORIES
By Industry
By Use Case
By Role
Compliant automation for public sector
Logistics & Transportation
Manufacturing
ERP extension and process orchestration
Healthcare
Governed AI for regulated clinical workflows
Other Industries
Automation built for your sector
Government
Start for Free
Create your WEM Account
WEM is an easy-to-use platform, with the WEM Modeler as its online building environment.
EXPLORE
USE CASES
SUCCESS STORIES
By Industry
By Use Case
By Role
Legacy System Modernization
Modernize without replacing your core systems
Business Process Automation
Replace manual workflows with governed automation
Core Systems & Orchestrated AI
Orchestrate your most critical operations
Tools and Apps
Purpose-built apps for any process
Customer & Supplier Portal
Branded portals your clients actually use
New Core System
Financial Car Management System for Biggest Leasing Company in Europe
SAP Extensions
Extend SAP without custom development
Start for Free
Create your WEM Account
WEM is an easy-to-use platform, with the WEM Modeler as its online building environment.
EXPLORE
ROLE-BASED SOLUTIONS
SUCCESS STORIES
By Industry
By Use Case
By Role
New Core System
Financial Car Management System for Biggest Leasing Company in Europe
CIO
Strategic IT leadership tools
Business Leader
Drive growth and efficiency
IT Leader
Manage development and operations
Start for Free
Create your WEM Account
WEM is an easy-to-use platform, with the WEM Modeler as its online building environment.
PROGRAMS
JOIN THE NETWORK
Partner Hub
Find a Partner
Certified experts to build your apps
Become a Partner
Join our global network
Start for Free
Create your WEM Account
WEM is an easy-to-use platform, with the WEM Modeler as its online building environment.
ABOUT WEM
OUR ORGANIZATION
Company Info
About Us
Our mission & story
Contact Us
Get in touch with our team
Start for Free
Create your WEM Account
WEM is an easy-to-use platform, with the WEM Modeler as its online building environment.
RESOURCE CENTER
CONTENT LIBRARY
LATEST WEBINAR
Library
Get Started
Learn
Customer Stories
Real-world success stories
File Control System
Business Critical Application from scratch in less than 7 months for WIJEindhoven
Events
Meet us at global events
Start for Free
Create your WEM Account
WEM is an easy-to-use platform, with the WEM Modeler as its online building environment.
RESOURCE CENTER
QUICK START
LATEST WEBINAR
Library
Get Started
Learn
Start for Free
Begin your no-code journey
Start for Free
Create your WEM Account
WEM is an easy-to-use platform, with the WEM Modeler as its online building environment.
RESOURCE CENTER
EDUCATION
LATEST WEBINAR
Library
Get Started
Learn
File Control System
Business Critical Application from scratch in less than 7 months for WIJEindhoven
Start for Free
Create your WEM Account
WEM is an easy-to-use platform, with the WEM Modeler as its online building environment.

The EU AI Act: A Practical Guide for Operations Teams

A Note Before You Read On
This article is informational, not legal advice. It describes the EU AI Act's requirements as of August 25, 2026, and how WEM No-Code's platform features relate to them. Regulatory deadlines have moved once already this year and could move again; verify current status before treating any date here as final, and work with your compliance function or legal counsel on what applies to your organization specifically.
eu-ai-act-compliance-guide-featured-image
Every enterprise in Europe has heard of the EU AI Act. Most have read a summary. Far fewer have done the thing the summary leads to: an honest inventory of which AI systems are already subject to requirements that took effect in February 2025, and which face a compliance deadline that, as of four days ago, is no longer where most summaries say it is.

This guide is not a legal briefing. It is a practitioner's read on what the regulation means for people running operations in financial services, healthcare, government, and manufacturing, the sectors where the stakes are highest.

The short version: if your organization uses AI to make or influence decisions about individuals, credit, claims, onboarding, eligibility, compliance screening, some of those systems are already regulated, and more will be from December 2, 2027.

The question is not really whether the deadline is close. It is whether those systems were built for what's coming, since 16 months is not long to retrofit governance onto AI that was never designed with an audit trail in mind.
TL;DR
  • The Annex III high-risk AI compliance deadline moved from August 2, 2026 to December 2, 2027, under the AI Omnibus, which entered into force July 27, 2026. Prohibited practices (since February 2025) and GPAI model obligations (since August 2025) are unchanged.
  • A study of 106 enterprise AI systems by the appliedAI Institute found 18% were clearly high-risk, 42% low-risk, and 40% unclear, meaning most organizations have not finished the classification step the rest of compliance depends on.
  • Fines are tiered: up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for high-risk non-compliance, and up to €7.5 million or 1% for supplying incorrect information to regulators.

What the EU AI Act Actually Is

The EU AI Act, Regulation (EU) 2024/1689, is the world's first comprehensive legal framework for artificial intelligence. It entered into force on August 1, 2024, and applies in phases: some provisions are already enforceable, one major deadline just moved, and a few extend as far as 2030.

The regulation follows a risk-based approach. The obligations an organization faces depend on what its AI systems do and who they affect, not on what the organization calls them internally. A system a product team calls a smart recommendation engine may be a high-risk AI system under the Act's classification.

Whether an organization builds AI or only deploys it, the Act can apply either way, and it applies extraterritorially, similar to GDPR: any organization whose AI systems produce outputs affecting EU residents is in scope, regardless of where the organization is headquartered.

The Enforcement Timeline: What Changed on July 27, 2026

As of August 25, 2026, the European Commission's own AI Act page lists the following application timeline:
The distinction that matters most for this audience: the enforcement machinery, the AI Office and national authorities, stands up on August 2, 2026, as originally planned.

What has moved is the substantive compliance deadline for the high-risk use cases in Annex III, credit scoring, claims processing, employment decisions, and benefits eligibility, which is now December 2, 2027, not August 2, 2026. That is genuine extra runway. It is not a reason to wait until 2027 to start.

The Risk Tiers, and Where Enterprise AI Falls

The Act classifies AI systems into four tiers. Compliance obligations depend on which tier a system falls into.

Unacceptable Risk: Banned Outright

AI systems that manipulate behavior through subliminal techniques, exploit vulnerabilities, enable mass social scoring, or perform real-time biometric surveillance in public spaces have been prohibited since February 2025.

A ninth prohibited practice, AI-generated non-consensual sexual content, takes effect December 2026. Any system that could fall here needs to be switched off, not scheduled for a future review.

High Risk: The Tier That Matters for Most Enterprises

This is where most enterprise operations teams need to focus. Annex III covers, among other categories, credit scoring and loan eligibility, insurance underwriting, AML and fraud classification, clinical decision support and diagnostic assistance, CV screening and candidate ranking, and benefits eligibility and tax assessment.

If an organization operates in financial services, healthcare, employment, or government and uses AI to influence individual outcomes in these areas, it is very likely here. December 2, 2027 is the date that matters.

Limited and Minimal Risk

Limited-risk systems, chatbots and AI-generated content, carry transparency obligations: people need to know they are interacting with AI.

Those rules apply from August 2026, unchanged. Minimal-risk systems, spam filters, non-consequential recommendation engines, carry no AI Act-specific obligations, though general data protection and product liability rules still apply.

What High-Risk Compliance Actually Requires

Most summaries treat this as a checklist. It reads more accurately as a set of architectural properties an AI system needs to have, not procedures added around it afterward: a documented, continuous risk management process; training data with documented provenance and bias assessment; technical documentation maintained through the system's lifetime; human oversight designed as specific intervention points, not just an available option; testing against edge cases and drift; a decision-level audit trail, not just system logs; and, for certain categories, a conformity assessment and EU database registration before deployment.

The pattern across all of it is the same: AI that operates within defined parameters, logs every decision, supports human oversight at specific points, and produces documentation that can be inspected on demand.

Those properties are difficult to retrofit onto a system that was not built with them in mind, which is the actual reason December 2027 matters, even though it is no longer four months away.

The Gap Most Operations Teams Are Sitting With

Most enterprise AI systems deployed in the last three to five years were not built with the AI Act in mind, because the regulation did not exist when they were designed. A study of 106 enterprise AI systems by the appliedAI Institute found 18% clearly high-risk, 42% clearly low-risk, and 40% unclear, concentrated in critical infrastructure, employment, law enforcement, and product safety.

That 40% is not a legal problem yet. It becomes one when an organization has to explain, on request, why it classified a system the way it did.

The organization that automated claims triage with a machine learning model in 2022, the insurer that deployed an underwriting assistant in 2023, the bank that built an automated KYC scoring system, may all be operating high-risk AI systems with no conformity assessment, no decision-level audit trail, and no human oversight design beyond a human can review the output if something looks wrong.

That is not human oversight under the Act. Oversight means defined escalation criteria, documented intervention authority, and evidence that intervention is actually happening, not an option that exists only in theory.

What to Do With the Extra Runway

The deadline moving to December 2027 changes the pace, not the destination. Three things matter most right now:

  • Inventory AI systems and classify them honestly against Annex III. Function determines whether the Act applies, not what a system is internally called.
  • Assess audit trail capability for each candidate high-risk system: can a complete decision log for any specific decision be produced on demand? If not, that is the most urgent gap, since compliance cannot be demonstrated for something that was never documented.
  • Map human oversight design on paper, not in theory: where oversight occurs, what the escalation criteria are, what the reviewer is authorized to do, and how that authority is evidenced. Undocumented oversight does not count.

The Operational Layer Behind an Audit-Ready AI System

WEM No-Code's AI Agent architecture is built around the principle WEM describes as the agent reasons, but the platform decides: an agent can classify a document, propose a score, or draft a response, but the workflow's own rules and checkpoints govern what actually happens next, and every function call, state transition, and response is logged by the platform itself, not reconstructed after the fact.

That structural logging is the kind of evidence base the requirements above are asking for, though the specific report format a regulator wants is still something the organization assembles and defines itself, not something the platform hands over automatically.

Human escalation is part of the workflow design in WEM No-Code, configured by whoever builds the workflow, rather than a fallback bolted on afterward. Whether that specific configuration satisfies a given high-risk requirement is a determination the deploying organization has to make and document itself; WEM No-Code provides the mechanism, not the compliance determination.

For more on how this same audit trail principle applies under a different regulation, see WEM No-Code's DORA compliance guide.
Frequently Asked Questions

Extra Runway, Not an Excuse

The EU AI Act's most consequential enterprise deadline just moved from August 2026 to December 2027. That is real relief, and it is also not an excuse to wait.

The organizations that spend the next several months classifying their AI systems honestly and building audit trails as a property of how those systems work, not a report assembled before an examination, are the ones that will find December 2027 arrives on schedule rather than as a crisis.

For the platform mechanics behind that kind of structural audit trail, WEM No-Code's Agentic AI page covers how governance and logging work. To see that audit trail against your own AI-driven workflows, book a demo.

This article is informational, not legal advice; work with your compliance function or legal counsel on what applies to your organization specifically.
Redefining Enterprise AI
& No-Code
Book a demo and watch no-code workflow building and orchestrated AI agents work together on a real business problem.