Illustrative scenarios · Not client engagements

Example Compliance Scenarios

Worked examples showing where EU AI Act, DORA, GDPR and NIS2 obligations land in practice, and what a compliance programme has to produce in response. These are illustrative and do not describe real organisations.

For data protection and client confidentiality reasons, these scenarios are illustrative rather than accounts of individual client engagements. No organisation is named, and no figures, timelines, or outcomes are claimed. They are drawn from enquiries, scoping calls, and experience of working inside regulated organisations, and gathered here to show how we would support an organisation like yours.

Most organisations arrive at the EU AI Act with the same question: does any of this apply to us, and if so, where. The four scenarios below are the patterns that come up most often. Each sets out who is caught, what applies, the sequence of work that follows, and the one thing worth remembering.

The four risk tiers

Prohibited

Banned outright. Article 5.

High-risk

Full conformity regime. Annex I and III.

Limited risk

Transparency duties. Article 50.

Minimal risk

No mandatory obligations.

When obligations bite

Feb 2025

Article 5 prohibitions and Article 4 AI literacy. Enforceable now.

Aug 2026

Article 50 transparency. Live, not deferred.

Dec 2026

Marking of legacy generative systems. Two new prohibitions apply.

Dec 2027

Annex III standalone high-risk. Deferred.

Aug 2028

Annex I embedded high-risk. Deferred.

Deferrals introduced by Regulation (EU) 2026/1744, the Digital Omnibus, in force 27 July 2026. The deadline for national AI regulatory sandboxes moved separately to 2 August 2027.

The date most summaries miss

2 December 2026 does two things. It is the end of the transitional period for the machine-readable marking and detection obligation in Article 50(2), which applies to generative AI systems that were already placed on the market before 2 August 2026. Anything placed on the market on or after that date had no transition at all and had to comply from day one. Content generated before 2 August 2026 does not need to be labelled retroactively. Separately, 2 December 2026 is the date from which the two new Article 5 prohibitions introduced by the Digital Omnibus apply, covering AI systems used to generate child sexual abuse material or non-consensual intimate imagery.

There is also a transitional rule worth knowing if you already have systems in the field. Article 111 limits how far the high-risk obligations reach back to systems placed on the market before the relevant date, and a significant change to a system's design brings it fully into scope. Whether a particular deployment benefits from that treatment is a question to check against your own facts rather than to assume.

Scenario one

Credit scoring in financial services

Annex III, point 5(b)

High-risk EU AI Act DORA GDPR Article 10 data governance Annex IV documentation

Who is caught

Lenders, credit bureaux, scoring model vendors

Role

Often provider and deployer at once

Deadline

2 December 2027

The regulatory position

AI used to evaluate the creditworthiness of natural persons or establish a credit score is high-risk under Annex III. Regulation (EU) 2026/1744 deferred standalone Annex III obligations to 2 December 2027, but the preparation window is shorter than the date suggests. Data governance, bias testing, technical documentation and human oversight all have to be built and evidenced before that date, not on it. DORA and GDPR obligations run alongside and are already live.

How we would approach it

Classify the system and confirm whether the firm is provider, deployer, or both. Assess the training and validation data against the Article 10 governance requirements. Design the risk management system under Article 9 and the human oversight arrangements under Article 14. Build the Annex IV technical documentation and the record-keeping required by Article 12. Then move to continuous monitoring so the position stays defensible as models are retrained.

The takeaway

The deferral moved the deadline, not the workload. Firms that treat December 2027 as a start date rather than an end date will be assembling evidence they should have been generating all along.

Scenario two

Employment screening in HR technology

Annex III, point 4(a)

High-risk EU AI Act GDPR Article 22 Article 25 provider transfer Post-market monitoring

Who is caught

Screening software vendors and the employers using them

Role

Vendor is provider, employer is deployer, unless Article 25 shifts it

Deadline

2 December 2027

The regulatory position

AI used to place targeted job advertisements, filter applications or evaluate candidates is high-risk under Annex III. Vendors selling screening software to employers are usually providers, and their customers are deployers, so obligations fall on both. Article 25 matters here: a customer who puts its own name on the system, or modifies its intended purpose, can become the provider itself. GDPR applies in parallel to candidate data, and the Article 22 automated decision-making rules are frequently in play.

How we would approach it

Map the provider and deployer relationships across the customer base before anything else, because that determines who owes what. Establish a fairness testing methodology and the documentation that evidences it. Align the GDPR lawful basis and the automated decision-making safeguards with the AI Act oversight requirements rather than running them as separate workstreams. Set up the post-market monitoring plan required of providers.

The takeaway

Who counts as the provider is a contractual question as much as a technical one. Vendors who have never read Article 25 against their reseller agreements are usually carrying obligations they have not priced for.

Scenario three

Diagnostic AI in healthcare

Annex I embedded high-risk

High-risk EU AI Act Article 6(1) Medical Devices Regulation Notified body Article 15 accuracy

Who is caught

Device manufacturers embedding AI as a safety component

Route

Assessed through the existing device conformity process

Deadline

2 August 2028

The regulatory position

Where AI is a safety component of a product already covered by EU harmonisation legislation, such as a medical device, it is high-risk under Article 6(1) rather than Annex III. These embedded cases were deferred to 2 August 2028. The practical consequence is that AI Act conformity has to be folded into the existing device conformity assessment and notified body process rather than run as a separate exercise.

How we would approach it

Start from the existing technical file and identify the gaps the AI Act adds rather than duplicating what is already documented. Extend the existing risk management system to cover the Article 9 requirements. Address accuracy and robustness testing under Article 15, including performance across relevant patient groups. Bring the notified body into the conversation early, since AI Act requirements are assessed through the same route.

The takeaway

The longest deferral belongs to the organisations with the most existing documentation. Used well, that time is spent extending a technical file rather than building one.

Scenario four

Customer-facing chatbots and generated content

Article 50 · Already in force

Limited risk Live now Article 50 transparency Synthetic content marking Legacy systems December 2026

Who is caught

Almost any organisation with a public AI assistant or AI-generated output

Effort

Low, if addressed deliberately rather than discovered later

Deadline

Passed. 2 August 2026.

The regulatory position

This is the scenario most organisations assume does not apply to them. Article 50 requires that people interacting with an AI system are told so, unless it is obvious from the context. Providers of systems generating synthetic text, audio, image or video must mark the output in a machine-readable form. Deployers publishing AI-generated text on matters of public interest, or producing deepfake content, must disclose it. None of this was deferred by the Digital Omnibus. It has applied since 2 August 2026, and generative systems already on the market before that date come into the marking regime on 2 December 2026.

How we would approach it

Inventory every point where AI touches a customer, an employee or a published output, including tools adopted by individual teams without procurement oversight. Establish for each whether the organisation is provider or deployer, since the marking and disclosure duties differ. Draft the disclosure wording so it satisfies the Article 50 clarity requirement without reading as a legal disclaimer. Confirm marking is applied at generation rather than bolted on afterwards. Then put a control in place so newly adopted tools are assessed before deployment rather than after.

The takeaway

Limited risk does not mean no obligations, and this is the tier where the deadline has already passed. Organisations reassured by headlines about deferral have frequently missed the one part of the Act that binds them today.

What the four have in common

Classification comes first

Every obligation in the Act follows from what the system is for and what role you occupy. Work done before that is settled is usually work done twice.

Deferral is not exemption

Article 5 and Article 50 were untouched by the Digital Omnibus, and December 2026 adds obligations rather than removing them. Firms reading a single headline about delay have often missed the parts already in force.

Frameworks overlap

GDPR, DORA, NIS2 and sectoral rules cover much of the same ground. Running them as one programme is considerably less work than running four.

Which of these looks like you?

A 30 minute call will establish which frameworks apply to your organisation and where the priority obligations sit.

Book a Scoping Call