The AI Act timeline just changed.
Most compliance advice hasn't.
Some duties bind today, the rest run to fixed dates — AnnexWise maps every AI system you build or deploy to the law as it stands, article-referenced and versioned, with documentation drafts for your counsel.
10 minutes per system · no signup required for the assessment · results stay in your browser
until the next application date — 2 December 2026: New prohibition: non-consensual intimate imagery. Article 50 transparency duties are already enforceable.
The timeline, as the law stands
Legal state reviewed 2026-08-05 · rule-set changelog
Article 5 prohibitions
Manipulative techniques, social scoring, untargeted facial-image scraping, emotion recognition at work and school, and the other banned practices — prohibited since 2 February 2025.
GPAI model duties
Articles 53/55 duties for general-purpose AI model providers and the governance structure around the AI Office — applicable since 2 August 2025.
Article 50 transparency + enforcement powers
Article 50 transparency duties (chatbot disclosure, deepfake and synthetic-content labelling), Commission penalty powers over GPAI providers, and national enforcement of everything already applicable — live since 2 August 2026. The Omnibus kept this application date (it amended the Art. 50(2) marking text — see the December 2026 entry).
New prohibition: non-consensual intimate imagery
The Omnibus adds an Article 5 prohibition on AI systems that generate or manipulate non-consensual intimate imagery of identifiable persons (“nudifiers”) and CSAM — reaching systems where such outputs are reasonably foreseeable and reproducible in the absence of reasonable, proportionate and effective safeguards. Applies from 2 December 2026. The same date ends the content-marking grace period for systems already on the market before 2 August 2026 (systems entering the market after that date must mark from day one).
Annex III high-risk obligations
The full high-risk regime for stand-alone Annex III systems — risk management, data governance, Annex IV technical documentation, logging, human oversight, conformity assessment, registration, Article 26 deployer duties — applies from 2 December 2027 (postponed from 2 August 2026 by the Omnibus).
Annex I embedded high-risk systems
High-risk obligations for AI that is a safety component of Annex I regulated products (medical devices, machinery, vehicles…) apply from 2 August 2028 (postponed by the Omnibus).
Postponements set by Regulation (EU) 2026/1744 (in force 27 July 2026) as fixed calendar dates — the proposed standards-availability trigger was dropped. Sites still quoting 2 August 2026 for high-risk are citing the pre-Omnibus text.
Non-compliance is now a board-level number
The AI Act uses GDPR-style penalties — whichever is higher of a fixed amount or a share of global annual turnover. For SMEs and startups the cap flips to whichever is lower (Art. 99(6)) — extended by the 2026 Omnibus to small mid-caps for the obligation tiers, though its reach into the prohibited-practices tier is contested. Commission fines on GPAI model providers sit separately under Art. 101. Still an existential number for most.
Prohibited AI practices — manipulation, social scoring, banned biometrics (Art. 5).
Breach of high-risk, transparency or GPAI obligations — the tier most companies risk.
Supplying incorrect or misleading information to authorities.
From “are we even affected?” to a defensible record
Classify every AI system
A guided 10-minute assessment maps each system to its exact risk tier — prohibited, high-risk, transparency or minimal — with article-level references, using a deterministic rules engine you can defend in an audit.
Get your gap report
A weighted compliance score, every open obligation ranked by severity and fine exposure, and a concrete 30-day remediation plan with effort estimates.
Generate the documentation
Annex IV technical documentation, deployer instructions and policy skeletons — pre-filled from your answers, ready for counsel review instead of a blank page.
Built around what the Act asks you to produce
Deterministic risk engine
Classification follows Articles 5, 6, 50 and Annex III literally — no black-box AI deciding your legal exposure.
Annex IV generator
The document every high-risk provider must have before market. Pre-structured, pre-filled, versioned.
30-day remediation plan
Gaps sorted into a week-by-week plan with effort estimates — built to close before enforcement.
Provider & deployer modes
Different obligations for each role under the Act. AnnexWise tracks both, including Art. 26 deployer duties.
GPAI module
Article 53 duties for general-purpose model providers, including systemic-risk models under Article 55.
Living verdicts
When the law moves — as the Omnibus just did — every saved assessment flags itself, re-runs your answers under the new rule set, and shows you the exact diff before anything changes. This requires deterministic, versioned rules — which is exactly why ours are public and fingerprinted.
Priced like software, not like a law firm
Classification and gap analysis in ten minutes instead of a consulting engagement measured in months. Start free; pay when you want the documents.
Starter
- ✓Everything in the free assessment
- ✓Annex IV technical documentation export
- ✓Fundamental Rights Impact Assessment (FRIA)
- ✓14-day no-questions refund
We email a secure checkout link within one business day.
Growth
- ✓Everything in Starter
- ✓AI system inventory dashboard
- ✓Policy template pack (oversight, literacy, transparency)
- ✓Legal-change notices to your purchase email + public rule-set changelog
- ✓Priority email support
We email a secure checkout link within one business day.
Partners
- ✓Everything in Growth
- ✓Written liability boundary for your risk committee
- ✓Article-level release notes on every rule change
- ✓Per-client inventory files (export/import)
- ✓Named support from the founders
- ✓No-cost referral track (we pay you 30%) also available
Prices exclude VAT. While we complete our payment-processor setup, purchases are completed against an invoice we send within one business day; where VAT applies it is shown there.
Exactly what each tier unlocks
| Feature | Free | Starter €490 | Growth €1,990/yr |
|---|---|---|---|
| Risk classification + article references | ✓ | ✓ | ✓ |
| Gap report, 30-day plan, gaps CSV | ✓ | ✓ | ✓ |
| Counsel-pack cover letter | ✓ | ✓ | ✓ |
| Living Verdicts re-check on rule-set updates | ✓ | ✓ | ✓ |
| Annex IV technical documentation draft | — | ✓ | ✓ |
| FRIA (Art. 27) export | — | ✓ | ✓ |
| Policy pack (Arts. 4, 14, 50) | — | — | ✓ |
| Legal-change notices to purchase email | — | — | ✓ |
| Systems in inventory | 1 | 1 | 10 |
White-label branding is free for every firm, ungated, with no agreement needed. Inventory capacity follows your plan; keep a separate export file per client — see the partner track.
Built and operated by two attorneys
A legal conclusion you cannot audit is a liability — that conviction comes from practice, and it is why every verdict here is deterministic, versioned and article-referenced.

Moshe Taieb
Attorney, Israel Bar 2008 · Deputy President of the Israel Bar Association · founding partner, Lev-Taieb Law Firm

Rinat Solimany
Attorney, Israel Bar 2009 · LL.M. (Health & Law) · AnnexWise's registered operator
Who we are — and where our role ends, and your counsel's begins →
Questions your CFO will ask
We're not an EU company. Does the AI Act apply to us?
Very likely yes. The Act applies to any provider placing AI systems on the EU market and to any provider or deployer whose system output is used in the EU — regardless of where the company is established (Art. 2). This is the same extraterritorial reach that made GDPR a global standard.
Didn't the Omnibus just delay the AI Act?
It delayed part of it. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026) postponed the high-risk regime — Annex III to 2 December 2027, Annex I embedded systems to 2 August 2028. It did not touch what started on 2 August 2026: Article 50 transparency duties, Commission enforcement over GPAI providers, and national enforcement of everything already applicable. It also added a new Article 5 prohibition (non-consensual intimate imagery) from 2 December 2026. Prohibited practices have been banned since February 2025 and GPAI duties have applied since August 2025.
High-risk moved to December 2027 — why classify now?
Because the delay only helps the companies that use it. You cannot know whether the postponement even applies to you without classifying: transparency duties bite today, the new prohibition lands in December, and a high-risk verdict means conformity work — oversight design, logging, documentation — that realistically takes the full runway. Contracts, procurement questionnaires and investors are asking for the classification now, not in 2027.
Is AnnexWise legal advice?
No. AnnexWise turns weeks of structuring, classification and drafting into hours, and produces documents your counsel reviews instead of writing from scratch. Final conformity decisions belong with qualified counsel.
How fast can we realistically get compliant?
The assessment takes about 10 minutes per system. Most companies with normal SaaS products land in the transparency tier and can close their gaps in days. High-risk providers get a 30-day plan that front-loads critical items.
We use AI vendors — isn't compliance their problem?
Only partly. If you deploy a high-risk system, Article 26 puts its own obligations on you: trained human oversight, input-data control, monitoring, log retention and worker notification. Vendor compliance does not transfer.
What exactly is free, and what do I pay for?
Free, forever: the full risk classification, your compliance score, every open obligation, the 30-day remediation plan and the downloadable gap report — real results, not a teaser. Paid plans unlock the counsel-ready document set: Annex IV technical documentation, the Fundamental Rights Impact Assessment, the organisation policy pack, and a multi-system inventory.
What happens to our answers? This is sensitive information.
They never leave your browser. The assessment, your inventory and every generated document are processed and stored on your device only — our servers never receive them. That is architecture, not policy: there is no database of customer assessments to breach.
How is a purchase delivered?
While we complete our payment-processor setup, the buy buttons collect your email and we send a secure payment link within one business day. The moment you pay, your licence key appears on screen and by email — paid features unlock in your browser on the spot, and the key unlocks any other machine at /activate. No account, no password, no onboarding call. Growth purchases also receive legal-change notices at the purchase email when the rule set is updated, alongside the public changelog on the methodology page.
The site won't load on our office network. Why?
Some corporate security gateways block domains they haven't categorised yet, regardless of content. AnnexWise is safe to whitelist — assessments run entirely in your browser and no assessment data ever reaches our servers, so there is nothing for a gateway to inspect. Ask your IT team to allow annexwise.com; until then, the full product works from any other network, including mobile.
What if it isn't right for us?
A flat 14-day, no-questions refund on the self-serve plans (Starter and Growth). Compliance software gets bought under deadline pressure; we'd rather refund than keep money from someone the product didn't help. The partner agreement is a negotiated contract and carries its own termination terms rather than this blanket refund. Details in the refund policy.
Ten minutes from now, you'll know exactly where you stand.
Run the assessment on your riskiest AI system first. It's free, anonymous, and the report is yours to keep.