Agentic compliance for the EU AI Act

The EU AI Act, from AI inventory to the duties of each system.

The EU AI Act, Regulation (EU) 2024/1689, sorts AI systems by risk. Prohibitions and general-purpose AI rules already apply, transparency duties have applied since 2 August 2026, and after the Digital Omnibus the high-risk rules follow from 2 December 2027. Teddy's agents build your AI register, classify each system and map the duties that fit your role.

Every AI systemListed with its risk level
Art. 50Chatbots and AI content must be labelled
Per systemDuties and owners assigned
What the EU AI Act asks for

Six parts of the EU AI Act.
Each one has a home in Teddy.

The EU AI Act is an EU regulation and applies directly. Your duties depend on the risk of each AI system and on your role: provider, deployer, importer or distributor. The Digital Omnibus, in force since 27 July 2026, moved the high-risk dates. Here is what applies and where it lives in Teddy.

Art. 3 and 6AI inventory and role

List every AI system you build or use, and whether you act as provider or deployer for it. Your role decides which duties apply.

In TeddyAI register built from your company model
Art. 5Prohibited practices

Practices such as social scoring and manipulative techniques are banned and have been since 2 February 2025. The Digital Omnibus adds two further prohibitions from 2 December 2026. Fines reach up to €35 million or 7% of worldwide turnover.

In TeddyEvery system checked against Art. 5
Art. 6, Annexes I and IIIHigh-risk classification

AI in areas such as employment, credit scoring, education or critical infrastructure, and AI in regulated products. Duties apply from 2 December 2027 for Annex III and 2 August 2028 for Annex I.

In TeddyRisk class per system, with the reasoning
Art. 9 to 17 and 26High-risk duties

Providers need risk management, data governance, technical documentation, logging, human oversight and a quality management system. Deployers follow the instructions for use, assign trained oversight and keep logs.

In TeddyDuties mapped to controls and owners
Art. 50Transparency

People must know when they interact with an AI system, and AI-generated or manipulated content must be marked. These duties have applied since 2 August 2026. Generative systems already on the market before then have until 2 December 2026 to mark their output.

In TeddyNotices and labels tracked per system
Art. 53 to 55General-purpose AI models

Model providers keep technical documentation, publish a summary of training content and follow EU copyright law. Models with systemic risk carry further duties.

In TeddyVendor documentation tracked for the models you use
2 Feb 2025ProhibitionsArt. 5
2 Aug 2025General-purpose AIArt. 53 to 55
2 Aug 2026TransparencyArt. 50 · marking for older generative systems by 2 Dec 2026
2 Dec 2027High-risk, Annex IIIAnnex I follows on 2 Aug 2028
The problem

AI is everywhere in the company.
Nobody has the list.

Teams buy AI tools, build features on top of models and switch on assistants in existing software. Before you can comply, you need to know which systems you have and what role you play for each.

01Knowing where AI is used

Teddy lists AI in your own products and in the tools you buy, including new features.

02Building or using AI

The duties differ depending on whether you build an AI system or use one. Teddy sets this per system.

03Which deadlines apply when

Teddy shows what applies today and what comes later for each system.

04A spreadsheet, a moving deadline and an AI chat. Still no register.

Legal keeps a list of AI tools in a spreadsheet, HR switched on a screening feature last month, and a product team ships a chatbot. ChatGPT can explain Annex III, but it does not know which systems you run. Teddy builds the AI register from your company model and maps the duties per system and role.

How it works

From a list of AI tools to duties you can show

Teddy's agents find, classify and map every AI system. Legal and the system owners decide, and a compliance engineer is there for difficult classifications.

01 Gap Audit Agent

Find every AI system

Teddy builds the AI register from your company model and connected tools, and asks each team to confirm what they use and who owns it.

AI register · Acme Inc.Draft
AI systems found9
Built in-house3
Bought or switched on6
Teddy: The HR suite update added CV screening. I added it to the register and asked Jasmin to confirm.
02 Gap Audit Agent

Classify risk and role

Each system gets a risk class and your role for it, with the reasoning written down, so Legal can confirm the result.

CV screeningHR suite
Your roleDeployer
Risk classHigh-risk, Annex III
Duties apply from2 Dec 2027
03 Policy Agent

Notices and policies that apply now

The Policy Agent drafts what is due today, such as the AI notice for your chatbot, and prepares what comes next.

Due now and nextBy date
Chatbot AI notice · Art. 50Live
AI use policyApproved
Worker information · Art. 26Draft
04 Evidence Agent

Vendor documentation and logs

As a deployer, you rely on the provider's documentation. The Evidence Agent tracks what you have, what is missing and whether logs are kept.

CV screeningEvidence
Instructions for use · HR suite vendorMissing
Logs kept for six monthsCovered
Oversight training records2 of 5
Teddy: I asked the HR suite vendor for the instructions for use. You need them to meet Art. 26.
05 Gap Audit Agent

Map once, comply many

AI governance, security and data protection overlap. Teddy maps the EU AI Act, ISO 42001, ISO 27001 and GDPR onto one control set.

Shared controlsOne control set
Shared with ISO 42001AI policy, roles, impact
Shared with ISO 27001Logging, access, security
Shared with GDPRData governance, DPIA
Teddy: Where both apply, a fundamental rights impact assessment can build on your DPIA.
Never stuck

Is this AI system high-risk? Ask Teddy, with the reasoning written down.

Ask in plain language whether a system is high-risk or which date applies. Teddy answers from your live AI register. For difficult cases, our compliance engineers are at your side.

1

Ask TeddyIs this high-risk? Are we provider or deployer? Teddy knows the AI Act and your systems.

2

Agents do the workRegister, classification, notices and vendor requests, each with its source.

3

Our team backs you upCompliance engineers help with classification questions, vendor requests and authority inquiries.

TeddyAcme Inc. · EU AI Act
Can we wait with the AI Act until 2027?
Not completely. The Digital Omnibus moved the high-risk dates, but other duties already apply.
  • Prohibited practicesSince Feb 2025
  • Transparency · Art. 50Since Aug 2026
  • High-risk · Annex IIIFrom Dec 2027
Shall I list which of your systems need action now?
Show systemsAsk our team
CEYour compliance engineer helps with difficult classifications.
FAQ

Questions about the EU AI Act

Did the Digital Omnibus delay the AI Act?

Partly. It moved the high-risk duties to 2 December 2027 for Annex III systems and to 2 August 2028 for AI in regulated products. The prohibitions, the general-purpose AI rules and the Art. 50 transparency duties were not postponed. It also added two prohibitions and a marking deadline for generative systems already on the market, both from 2 December 2026.

Are we a provider or a deployer?

You are a provider if you develop an AI system, or have it developed, and place it on the market or put it into service under your name. You are a deployer if you use an AI system under your authority. Many companies are both, for different systems.

Is fraud detection high-risk?

Credit scoring of natural persons is high-risk under Annex III, but AI used to detect financial fraud is explicitly excluded. Teddy records the reasoning for every classification.

How does this relate to ISO 42001?

ISO/IEC 42001 is a voluntary management system standard for AI. It does not replace the AI Act, but its controls cover much of the governance the Act expects, so Teddy maps both onto one control set.

Know every AI system and every duty, before the dates arrive.

Start with an AI register and a classification of your systems.

Reviewed by Sven Moritz, former CISO · October 2026

What to expect

How long EU AI Act readiness takes, and how Teddy cuts it to weeks

TypicalMost have not started

More than half of German companies have no concrete measures in place, and most organizations still have no inventory of the AI systems they run.

With TeddyWithin weeks

AI register, classification by risk and role and the duties per system and date, so you know today what December 2027 means for you.

  • The Omnibus is law: Regulation (EU) 2026/1744 entered into force on 27 July 2026, six days before the original high-risk date.
  • AI literacy, reworded: providers and deployers take measures that support AI literacy, without having to guarantee a set level per person.
SMSven MoritzCo-founder of Teddy, former CISOLast reviewed: October 2026
From the audit room

Where AI Act programs go wrong

  1. Transparency is treated as a chatbot banner.

    Art. 50 also covers AI-generated images, audio and text you publish. Marketing and product teams create that content every day, often without anyone tracking it.

  2. Nobody knows which AI systems are in use.

    Classification starts with a list. An inventory, including tools teams bought on their own, is the first step and the basis for the high-risk assessment.

  3. Deployers turn into providers without noticing.

    Your obligations depend on your role per system. If you put your name on an AI system or substantially modify it, you can take on provider duties under Art. 25.