NewSnippets: tell the AI about you and your company once.See how New modelClaude Sonnet 5.5 is now available.Read more
EU AI ACT · IN APPLICATION

The EU AI Act is in force. Show your work.

The bans, the AI literacy duty and, since 2 August 2026, the transparency rules all apply. The Annex III high-risk regime follows on 2 December 2027. Nobody will ask what your AI policy says. They'll ask for the register, the oversight record and the logs. StickyPrompts is where that evidence lives.

EU AI ACT · EVIDENCE PACK Northwind · illustrative
Region Data location EU only
Art. 4 AI literacy 1,180 / 1,204 staff
Art. 5 Prohibited use 2 attempts blocked
Art. 26 Human oversight 412 approvals recorded
Art. 26(6) Log retention exportable log
Art. 50 Transparency on by default
Export evidence pack CSV / JSON · scoped per system
The timeline, as amended by the Digital Omnibus (July 2026)
2 Feb 2025
Bans & AI literacy
Prohibited practices (Art. 5) become unlawful. Providers and deployers must take measures to support AI literacy among their staff (Art. 4, as rewritten in 2026).
2 Aug 2025
General-purpose AI
Obligations for providers of general-purpose AI models apply, along with the governance bodies and the penalty regime.
YOU ARE HERE
2 Aug 2026
Transparency
The transparency duties in Art. 50 apply: tell people when they deal with AI, mark synthetic content and disclose deepfakes.
2 Dec 2026
New bans & marking
Two new Art. 5 bans (non-consensual intimate imagery and child sexual abuse material), and marking for generative systems already on the market.
2 Dec 2027
Annex III high-risk
Stand-alone high-risk systems - hiring, credit, education and the rest of Annex III - and the deployer duties in Art. 26 that come with them.
2 Aug 2028
High-risk in products
High-risk AI embedded in products already covered by EU product law (Annex I, Art. 6(1)).
What non-compliance costs

The ceilings are set in the Regulation, not by a regulator's mood.

Article 99 leaves member states room on the details, but the maximums are fixed - and they are calculated on worldwide turnover, not on what you spent on AI.

€35M
or 7% of worldwide annual turnover
Using a prohibited AI practice
Art. 99(3)
€15M
or 3% of worldwide annual turnover
Breaching provider or deployer obligations
Art. 99(4)
€7.5M
or 1% of worldwide annual turnover
Supplying incorrect or misleading information to authorities
Art. 99(5)

Whichever figure is higher applies. For SMEs and start-ups it is whichever is lower, and the Digital Omnibus extends some of that relief to small mid-caps.

STEP ONE

You can't classify what nobody wrote down.

Every obligation in the Regulation starts with knowing which AI systems you actually run, who owns them, and what they touch. In most companies that list doesn't exist - it's spread across personal subscriptions, free tiers and one clever agent on somebody's laptop.

  • One workspace becomes one register - owner, model and purpose on every line
  • Classification and risk tier recorded against each system, ready for review
  • Nothing to chase down at audit time: the register is a by-product of daily work
See how governance works
shadow-ai.txt 8 TOOLS · 0 OWNED
?ChatGPT Pluspersonal card · Sales
?Copilot trialowner unknown
?Midjourneyshared login · Brand
?CV screenerbuilt by an intern
?Gemini (free)no policy accepted
?Notion AIcustomer data · unclear
?Local Llamaon a laptop
?Support macro botno disclosure
You cannot classify, disclose or defend what nobody has written down.
Obligations, meet controls

Four duties that reach nearly every company - and what satisfies them in practice.

Pick an article to see the plain-language requirement next to the control that produces the evidence for it.

Art. 4 · AI literacyApplies since 2 Feb 2025

Providers and deployers must take measures that support AI literacy among their staff and anyone operating AI systems on their behalf, taking into account their knowledge, experience and the context the systems are used in. Since the July 2026 Digital Omnibus this is a duty of effort: no specific level has to be guaranteed, but the measures have to be real.

People learn inside the tool they actually work in

Approved, owned prompts instead of copy-paste folklore. Your AI use policy is accepted on first login, guidance sits next to the prompt box, and adoption analytics show which teams are still guessing.

evidence.log · live
ONBOARDED1,180 / 1,204 staff · AI use policy accepted
LIBRARY214 approved prompts · each with a named owner
GAPOperations · 62% adoption → training nudge sent
EXPORTcompletion record ready for the file
you can show: who was trained, on what, and when

Article summaries are simplified for orientation and are not legal advice. Sample figures are illustrative.

EU BY DEFAULT

Pick EU once. Everything else follows.

Set your data location and StickyPrompts enforces it for every team, every capability and every model call. Anything that can't be served from inside the region simply isn't reachable - and far more models can be served from the EU than most people assume.

  • Prompts, files, embeddings and logs stay in the region you choose
  • Non-EU models and services blocked outright, not merely discouraged
  • Open-weight and Asian models on our EU endpoints, or inside your own VPC
  • Models whose providers publish no Art. 53 documentation are quarantined automatically
See every model
Data location
model-policy · EU only6 allowed1 held1 blocked
Mistral Largefrom FranceALLOWEDEU · Paris
Claudefrom United StatesALLOWEDEU · Frankfurt
GPTfrom United StatesALLOWEDEU · Stockholm
Llama · open weightsfrom United StatesALLOWEDEU · your VPC
Qwen · open weightsfrom ChinaALLOWEDEU · Frankfurt
DeepSeek · open weightsfrom ChinaALLOWEDEU · Frankfurt
Aurora-X (preview)from undisclosedQUARANTINEDno Art. 53 GPAI documentation
Helios beta endpointfrom United StatesBLOCKEDno endpoint inside the region
origin ≠ location - what the register records is where inference actually runs
The same setting, in the product

Chosen at sign-up.

The data location is part of creating the account, and the EU is already selected. A different location is an Enterprise arrangement, provisioned on request.

Create an account: Google or email, and choose where your data lives - the EU by default 1 EU by default

Enforced in workspace settings.

Storage stays in the region, and two switches narrow inference further: EU-served endpoints only, and zero data retention only.

Data residency: EU storage by default, EU-served inference and zero-retention constraints 1 Storage region 2 Inference constraints
GUARDRAILS & AUDIT

Hand-pick the models. Then the policy holds.

Approve models one at a time, layer your corporate AI policy on top, and let the audit log do the remembering. PII is redacted before any external call and traffic goes to zero-retention endpoints - enforced platform-wide, not team by team.

  • Per-model, per-team allow-lists - you approve one model, not a category
  • Your corporate AI policy enforced in the prompt path, not filed as a PDF
  • Every prompt, model choice, block and approval in an exportable audit log
Read about security
Guardrails & residency 4 active
Privacy log
REDACTED4111 1111 1111 1111 → [payment_data]
REDACTEDHU42 1177 3016… → [payment_data]
REDACTED+36 30 555 0142 → [phone]
BLOCKEDmessage contained an API key
POLICYmodels limited to EU-served endpoints
Every trigger is recorded. Filter it, export it.
Recorded in the product

Redaction, as it happens.

Card numbers, IBANs and phone numbers are caught and replaced as you type, before the prompt reaches any model.

And the record it leaves.

The Privacy Log (AI Act) tab lists every redaction and every policy change, filterable by area and action, and exports for your AI Act file.

The privacy log (AI Act): every redaction and policy change, exportable 1 Each redaction logged 2 Exportable
Know your seat

Most companies are deployers - and a surprising number are providers without realising it.

Your obligations follow the role you play for each system, not your industry. One company can sit in all three seats at once.

Deployer
You use an AI system under your own authority - a copilot, a screening tool, a bot in front of customers. This is where almost every ordinary company sits, and where Art. 4, 26 and 50 land.
Provider
You develop an AI system, put your name on one, or substantially modify a high-risk system someone else built. Rebadging or repurposing a model can quietly move you into this seat.
Building on GPAI
The general-purpose models underneath you carry their own obligations. You still have to know which ones you depend on, under what terms, and where they run.
From policy to proof

Intentions don't survive an audit. Records do.

The difference between a company that's ready and one that isn't rarely comes down to the policy document. It comes down to whether anyone can produce the register, the oversight trail and the logs on the day they're asked for.

  • One register of every AI system, owner and classification
  • Data location set once and enforced on every model call
  • Human approval recorded on every consequential action
  • A privacy log you can filter and export for your AI Act file
EU
storage region by default
2
inference switches: EU-only and zero retention
3
guardrail outcomes logged: warned, redacted, blocked
1
export for your AI Act file
Straight answers

The questions legal and IT ask us first.

Does StickyPrompts make us compliant with the EU AI Act?

No product can, and you should be wary of any that says otherwise. Compliance is an organizational obligation that depends on what you build, deploy and sell. What StickyPrompts does is make the work possible and provable: one register of every AI system in use, policy enforced before a model is ever called, human oversight recorded as it happens, and logs you can hand over. Your counsel still decides how each system is classified.

We don't build AI - we just use it. Does this apply to us?

Almost certainly. Deployers carry obligations of their own, the AI literacy duty in Art. 4 has applied since February 2025 regardless of risk tier (since July 2026 it is a duty to take measures that support literacy, not to guarantee a level), and anything customer-facing runs into the transparency rules in Art. 50, which apply from 2 August 2026. The Regulation also reaches companies established outside the EU where the output of their AI system is used in the Union.

We already have an AI policy. Isn't that enough?

A policy is what you intend. An audit asks what happened. The gap between the two is usually shadow AI - tools bought on personal cards, prompts pasted into free tiers, an agent running on someone's laptop. StickyPrompts closes that gap by making the governed path the easy one, then recording it.

What about the systems we've already classified as high-risk?

Classification stays yours. The Digital Omnibus moved the Annex III high-risk rules to 2 December 2027 (2 August 2028 for AI inside regulated products), which is time to build the record, not a reason to wait. StickyPrompts supplies the instrumentation around it: approval gates with a named human on them, and an exportable log you keep for as long as Art. 26(6) and your own policy require.

Can we keep everything inside the EU?

Yes - data location is a setting, not a support ticket. Choose EU and prompts, uploads, embeddings and logs stay in the region. Every model and service that can't be served from inside it becomes unreachable for everyone, so there's no quiet exception for the one team that wanted a US-only preview endpoint. Zero-data-retention routing and redaction of sensitive data before any model call can be switched on top.

Does staying in the EU mean giving up the best models?

Far less than people expect. European models run in Europe natively, the major US frontier models are reachable through EU regions, and open-weight models - including the strong Asian ones - run on our EU endpoints or inside your own VPC, because open weights can be served anywhere. Where a model has origin in one place and inference in another, only the second one is what your register records.

Can we block models that don't meet the Regulation?

You can pin the estate down as tightly as you like: hand-pick models one at a time rather than approving a whole vendor, scope approvals per team, and layer your corporate policy on top. Models whose providers haven't published the documentation expected of general-purpose AI under Art. 53 are quarantined automatically until someone with authority signs off - so a new model appearing at a provider doesn't quietly appear in your company.

How long until we have a register?

It depends on how scattered your AI use is today. The work is the same everywhere: bring the tools people already use into one workspace, give each system an owner, and from then on the register is kept up by daily use rather than by a quarterly spreadsheet hunt.

Trial
A $5 balance to start. No card needed.
Get it on the record

Every AI your company runs, on one register.

Start free with a $5 trial balance. Bring in the AI your people already use, give every system an owner, and walk into your next audit meeting with the record.