The EU AI Act is in force. Show your work.
The bans, the AI literacy duty and, since 2 August 2026, the transparency rules all apply. The Annex III high-risk regime follows on 2 December 2027. Nobody will ask what your AI policy says. They'll ask for the register, the oversight record and the logs. StickyPrompts is where that evidence lives.
The ceilings are set in the Regulation, not by a regulator's mood.
Article 99 leaves member states room on the details, but the maximums are fixed - and they are calculated on worldwide turnover, not on what you spent on AI.
Whichever figure is higher applies. For SMEs and start-ups it is whichever is lower, and the Digital Omnibus extends some of that relief to small mid-caps.
You can't classify what nobody wrote down.
Every obligation in the Regulation starts with knowing which AI systems you actually run, who owns them, and what they touch. In most companies that list doesn't exist - it's spread across personal subscriptions, free tiers and one clever agent on somebody's laptop.
- One workspace becomes one register - owner, model and purpose on every line
- Classification and risk tier recorded against each system, ready for review
- Nothing to chase down at audit time: the register is a by-product of daily work
Four duties that reach nearly every company - and what satisfies them in practice.
Pick an article to see the plain-language requirement next to the control that produces the evidence for it.
Providers and deployers must take measures that support AI literacy among their staff and anyone operating AI systems on their behalf, taking into account their knowledge, experience and the context the systems are used in. Since the July 2026 Digital Omnibus this is a duty of effort: no specific level has to be guaranteed, but the measures have to be real.
Approved, owned prompts instead of copy-paste folklore. Your AI use policy is accepted on first login, guidance sits next to the prompt box, and adoption analytics show which teams are still guessing.
Article summaries are simplified for orientation and are not legal advice. Sample figures are illustrative.
Pick EU once. Everything else follows.
Set your data location and StickyPrompts enforces it for every team, every capability and every model call. Anything that can't be served from inside the region simply isn't reachable - and far more models can be served from the EU than most people assume.
- Prompts, files, embeddings and logs stay in the region you choose
- Non-EU models and services blocked outright, not merely discouraged
- Open-weight and Asian models on our EU endpoints, or inside your own VPC
- Models whose providers publish no Art. 53 documentation are quarantined automatically
Chosen at sign-up.
The data location is part of creating the account, and the EU is already selected. A different location is an Enterprise arrangement, provisioned on request.
Enforced in workspace settings.
Storage stays in the region, and two switches narrow inference further: EU-served endpoints only, and zero data retention only.
Hand-pick the models. Then the policy holds.
Approve models one at a time, layer your corporate AI policy on top, and let the audit log do the remembering. PII is redacted before any external call and traffic goes to zero-retention endpoints - enforced platform-wide, not team by team.
- Per-model, per-team allow-lists - you approve one model, not a category
- Your corporate AI policy enforced in the prompt path, not filed as a PDF
- Every prompt, model choice, block and approval in an exportable audit log
Redaction, as it happens.
Card numbers, IBANs and phone numbers are caught and replaced as you type, before the prompt reaches any model.
And the record it leaves.
The Privacy Log (AI Act) tab lists every redaction and every policy change, filterable by area and action, and exports for your AI Act file.
Most companies are deployers - and a surprising number are providers without realising it.
Your obligations follow the role you play for each system, not your industry. One company can sit in all three seats at once.
Intentions don't survive an audit. Records do.
The difference between a company that's ready and one that isn't rarely comes down to the policy document. It comes down to whether anyone can produce the register, the oversight trail and the logs on the day they're asked for.
- One register of every AI system, owner and classification
- Data location set once and enforced on every model call
- Human approval recorded on every consequential action
- A privacy log you can filter and export for your AI Act file
The questions legal and IT ask us first.
Does StickyPrompts make us compliant with the EU AI Act?
No product can, and you should be wary of any that says otherwise. Compliance is an organizational obligation that depends on what you build, deploy and sell. What StickyPrompts does is make the work possible and provable: one register of every AI system in use, policy enforced before a model is ever called, human oversight recorded as it happens, and logs you can hand over. Your counsel still decides how each system is classified.
We don't build AI - we just use it. Does this apply to us?
Almost certainly. Deployers carry obligations of their own, the AI literacy duty in Art. 4 has applied since February 2025 regardless of risk tier (since July 2026 it is a duty to take measures that support literacy, not to guarantee a level), and anything customer-facing runs into the transparency rules in Art. 50, which apply from 2 August 2026. The Regulation also reaches companies established outside the EU where the output of their AI system is used in the Union.
We already have an AI policy. Isn't that enough?
A policy is what you intend. An audit asks what happened. The gap between the two is usually shadow AI - tools bought on personal cards, prompts pasted into free tiers, an agent running on someone's laptop. StickyPrompts closes that gap by making the governed path the easy one, then recording it.
What about the systems we've already classified as high-risk?
Classification stays yours. The Digital Omnibus moved the Annex III high-risk rules to 2 December 2027 (2 August 2028 for AI inside regulated products), which is time to build the record, not a reason to wait. StickyPrompts supplies the instrumentation around it: approval gates with a named human on them, and an exportable log you keep for as long as Art. 26(6) and your own policy require.
Can we keep everything inside the EU?
Yes - data location is a setting, not a support ticket. Choose EU and prompts, uploads, embeddings and logs stay in the region. Every model and service that can't be served from inside it becomes unreachable for everyone, so there's no quiet exception for the one team that wanted a US-only preview endpoint. Zero-data-retention routing and redaction of sensitive data before any model call can be switched on top.
Does staying in the EU mean giving up the best models?
Far less than people expect. European models run in Europe natively, the major US frontier models are reachable through EU regions, and open-weight models - including the strong Asian ones - run on our EU endpoints or inside your own VPC, because open weights can be served anywhere. Where a model has origin in one place and inference in another, only the second one is what your register records.
Can we block models that don't meet the Regulation?
You can pin the estate down as tightly as you like: hand-pick models one at a time rather than approving a whole vendor, scope approvals per team, and layer your corporate policy on top. Models whose providers haven't published the documentation expected of general-purpose AI under Art. 53 are quarantined automatically until someone with authority signs off - so a new model appearing at a provider doesn't quietly appear in your company.
How long until we have a register?
It depends on how scattered your AI use is today. The work is the same everywhere: bring the tools people already use into one workspace, give each system an owner, and from then on the register is kept up by daily use rather than by a quarterly spreadsheet hunt.
This page is a plain-language orientation to Regulation (EU) 2024/1689 and is not legal advice. Scope and timelines may be amended by the EU legislator - confirm current requirements with your own counsel. Figures shown in product mock-ups are illustrative. Dates reflect Regulation (EU) 2026/1744 (the Digital Omnibus on AI). Last reviewed 28 September 2026.
Every AI your company runs, on one register.
Start free with a $5 trial balance. Bring in the AI your people already use, give every system an owner, and walk into your next audit meeting with the record.