NEWMindMap Digital has acquired Bluetide.co— deepening our data & agentic-AI stack.Read more →
Home · EU AI Act · Whitepaper
Free download · 18 pages · Engineering whitepaper

The EU AI Act for Enterprise.

The world's first comprehensive horizontal AI regulation comes into force for high-risk systems on 2 August 2026. This whitepaper covers what the Act is, what it isn't, who it applies to, the four risk tiers, the Articles 9–15 obligations, the penalties — and the 12-point engineering checklist that produces defensible compliance. Plus the MindMap reference architecture mapped article-by-article.

12 chaptersArticles 9–15 mapped12-point compliance checklist90-day CIO action plan
Get the whitepaper

Free. PDF. In your inbox in 30 seconds.

Tell us where to send it. No follow-up sales sequence — we'll send the PDF, and we'll reach out only if you'd like to talk.

We'll send the PDF and nothing else. No follow-up sales sequence. You can unsubscribe with one click.
The deadline that drives planning
Annex III high-risk systems enforceable from 2 August 2026.
Penalties up to €35M or 7% of global turnover. Most enterprise AI lands in scope.
Book a 30-min review →
What's inside

Twelve chapters. About 15 minutes.

Written by the team that has shipped sovereign AI to 50+ regulated enterprises — banks, insurers, hospitals, government — since 2022. Not legal commentary, engineering practice: the architectural choices that produce defensible compliance.

01

What the EU AI Act is

The world's first comprehensive horizontal AI regulation — risk-tiered, extraterritorial, in force since August 2024.

02

What it is NOT

Five common misconceptions — and what the Act actually says.

03

The four risk tiers

Prohibited · High-risk · Limited risk · Minimal — a practical map of where enterprise workloads land.

04

The enforcement timeline

The dates that drive programme planning — including the 2 Aug 2026 deadline for Annex III high-risk systems.

05

High-risk obligations

Articles 9–15 mapped: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy / robustness / cybersecurity.

06

Provider vs deployer

Who you are determines which obligations apply — and the Article 25 trap that turns deployers into providers.

07

GPAI + foundation models

Article 53 + 55 obligations — and the sovereign open-weights advantage.

08

Penalties + enforcement

€35M · 7% of global turnover · market withdrawal · public disclosure. The financial and reputation exposure.

09

12-point engineering checklist

The architectural choices that produce defensible compliance — mapped to MindMap's reference sovereign stack.

10

MindMap article-by-article

How the reference architecture pre-satisfies Articles 9 through 15 — not as paperwork retrofit, as design choice.

11

How MindMap helps

The four-phase engagement: Assess (4–6 wk) → Architect (2–4 wk) → Implement (6–24 wk per workload) → Operate (ongoing).

12

90-day CIO action plan

The minimum viable programme to put your enterprise on a defensible path to the 2 August 2026 deadline.

Who it's for

Built for the leaders who own the answer to the regulator.

Chief Risk + Chief Compliance Officers

Designing the enterprise AI governance programme that will face the regulator. Need a defensible architecture and a board-ready exposure picture.

Chief Information Officers

Owning the architecture choice between cloud LLM APIs and sovereign deployment for high-risk workloads. Need the engineering trade-offs in front of the legal arguments.

Chief AI Officers + Heads of AI

Standing up the AI portfolio, classifying workloads, deciding which use cases pause until 2 August 2026 and which need acceleration.

General Counsel + Data Protection Officers

Translating Articles 9 through 15 into operational artefacts the technical team will actually implement. The 12-point checklist is built for this conversation.

Why this whitepaper, not another LinkedIn explainer

Engineering practice, not legal commentary.

  • Article-by-article mapping of obligations to MindMap's reference architecture — not abstract compliance hand-waving.
  • 12-point engineering checklist drawn from the architectures we have shipped to 50+ regulated enterprises since 2022.
  • Distinguishes provider vs deployer, base-model vs system, GPAI vs Annex III — the classifications that actually drive obligations.
  • Includes the Article 25 "deployer-becomes-provider" trap, the extraterritoriality scope, and the legacy-systems clock to 2030.
↑ Back to downloadRead the web version →

Read the whitepaper. Then talk to engineers who've mapped this for 50+ regulated enterprises.

Free PDF. No sales sequence. Just the architecture and the obligations, side by side.

↑ Back to the download formRead the web version →
Talk to the product team