Six Months Into Full Enforcement, the Compliance Landscape Has Fractured Into Dozens of "AI Act Hubs" Promising Clarity. Some Deliver. Most Don't.
Here's how to navigate the noise and find resources that will actually help a team ship compliant systems.
The EU AI Act entered into force on 1 August 2024, but the real test started in August 2026 when high-risk AI system compliance requirements became fully enforceable. That deadline separated teams who had been preparing from teams who had been hoping the problem would solve itself. Now the scramble is on, and everyone with a website has launched an "EU AI Act Hub."
The problem isn't a lack of information. The problem is too much information, scattered across official portals, vendor marketing pages, and well-meaning but outdated explainers. A compliance lead trying to figure out whether their CV-screening tool needs a conformity assessment shouldn't have to wade through fifteen tabs to find a straight answer.
The Official Stack: Start Here, But Don't Stop Here
The European Commission's AI Act Single Information Platform is the canonical source. It includes two tools that actually work: the AI Act Explorer for navigating the regulation's text, and the Compliance Checker for a first-pass assessment of whether a system falls under specific obligations. The Service Desk also lets teams submit questions and get answers from experts working with the EU AI Office.
This is the right starting point. But official resources optimize for legal precision, not operational clarity. The Commission's guidance tells teams what the law says. It doesn't tell them how to build the internal processes that make compliance sustainable.
The European AI Office itself now employs more than 125 staff across six units, including technology specialists, lawyers, and economists. They're hiring aggressively, with 40 new posts announced for enforcement roles. That hiring round closes . The scale of the Office signals that enforcement won't be theoretical.
Independent Hubs: Sorting Signal from Noise
Several independent resources have emerged that translate regulatory text into operational guidance. The quality varies enormously.
ArtificialIntelligenceAct.eu has become a de facto reference for many practitioners. It offers a high-level summary, a small business guide, and a visual timeline of AI Office and Member State tasks through 2025. The site serves over 150,000 users monthly and responds to user feedback quickly, sometimes publishing requested resources within two weeks. The compliance checker here provides a useful second opinion against the official tool.
The EU AI Act Hub at aiacthub.eu offers an "Ask Me Anything" feature that answers questions based on the regulation's text. The disclaimer is important: answers are informational, not legal advice. But for quick lookups on specific provisions, it's faster than scrolling through the official Explorer.
AI Ireland's EU AI Act Hub takes a different approach, aggregating blogs, videos, and podcasts from practitioners. The podcast archive includes conversations with European Commission officials and compliance strategists. This is useful for teams that learn better through discussion than documentation.
What the Hubs Actually Cover
The regulation sorts AI systems into four risk tiers: prohibited (banned outright), high-risk (heavily regulated), limited risk (transparency requirements), and minimal risk (largely unregulated). Ireland's Department of Enterprise provides a clear breakdown of the eight prohibited practices, including social scoring, emotion inference in workplaces, and untargeted facial image scraping.
High-risk systems face the heaviest obligations. These include AI used in critical infrastructure, education, employment, law enforcement, and democratic processes. Requirements cover risk management, data quality, documentation, human oversight, accuracy, and cybersecurity. The EU AI Act Hub's FAQ notes that penalties reach up to €35 million or 7% of global annual turnover for prohibited practices, €15 million or 3% for other violations, and €7.5 million or 1.5% for providing incorrect information.
General-purpose AI (GPAI) models, including large language models, have their own obligations. OpenAI's guidance page explains how they're approaching compliance and what customers need to know about prohibited practices when using their APIs. The page explicitly lists Article 5 prohibitions and notes that OpenAI has technical safeguards in place, but customers remain responsible for their own compliance.
What's Missing from Most Hubs
Here's the gap: most hubs explain what the law requires. Few explain how to operationalize those requirements in a real organization.
A team that knows they need "human oversight" for a high-risk system still needs to answer: Who reviews outputs? How often? What's the escalation path when the system behaves unexpectedly? What training do reviewers need? How is that training documented?
A team that knows they need "post-market monitoring" still needs to build the infrastructure: logging pipelines, drift detection, incident reporting workflows, and clear ownership for each.
The best hubs are starting to address this. Look for resources that include templates, checklists, and decision frameworks rather than just regulatory summaries. Look for content that acknowledges what can go wrong, not just what should happen in the ideal case.
Practical Triage for Compliance Teams
Before diving into any hub, answer three questions:
What role does the organization play? Provider, deployer, importer, and distributor each have different obligations. A company using a third-party LLM API has different responsibilities than a company that trained the model.
What risk tier applies? Use both the official Compliance Checker and an independent tool. If they disagree, dig deeper. The classification determines everything downstream.
What's the timeline? The phased rollout means different requirements hit at different times. Prohibited practices have been banned since . High-risk system requirements became fully enforceable in . Annex I high-risk systems (AI embedded in products) have until .
Once those questions are answered, the hub resources become useful rather than overwhelming. Without those answers, teams end up reading everything and implementing nothing.
The Enforcement Reality
The EU AI Office isn't just publishing guidance. It has powers to conduct evaluations of GPAI models, request information from providers, and apply sanctions directly. The Office's mandate includes investigating possible infringements, requesting technical documentation, and accessing models to assess capabilities.
National supervisory authorities in each Member State handle enforcement for most provisions, coordinated by the European Artificial Intelligence Board. The Commission retains direct enforcement powers for certain aspects, particularly around GPAI models.
This isn't a regulation that will sit on a shelf. The hiring, the infrastructure, and the explicit penalty structure all point toward active enforcement. Teams that treat compliance as a checkbox exercise will discover that the checkbox has teeth.
The hubs are a starting point. The real work is building systems that don't just comply on paper but operate compliantly in production, with monitoring, documentation, and human oversight that actually function when something goes wrong.
For teams tracking the evolving enforcement landscape and implementation patterns across Europe, the Human × AI Content Hub continues to cover developments as they unfold.
Frequently Asked Questions
Q: What is the EU AI Act Single Information Platform?
A: The Single Information Platform is the European Commission's official portal for AI Act compliance. It includes the AI Act Explorer for browsing the regulation, a Compliance Checker tool, and a Service Desk where teams can submit questions to experts.
Q: When did high-risk AI system requirements become enforceable?
A: High-risk AI system compliance requirements became fully enforceable on 2 August 2026. Prohibited practices were banned earlier, from February 2025, and Annex I high-risk systems have until August 2027.
Q: What are the maximum fines under the EU AI Act?
A: Fines reach up to €35 million or 7% of global annual turnover for prohibited AI practices, €15 million or 3% for other violations, and €7.5 million or 1.5% for providing incorrect information to authorities.
Q: How do I determine if my AI system is high-risk?
A: Use the official Compliance Checker on the Single Information Platform and cross-reference with independent tools. High-risk systems include those used in critical infrastructure, education, employment, law enforcement, border control, and democratic processes.
Q: What is the difference between a provider and a deployer under the EU AI Act?
A: A provider develops or places an AI system on the market. A deployer uses an AI system under their authority. Each role carries different obligations, with providers generally facing heavier requirements around documentation, conformity assessment, and post-market monitoring.
Q: Where can I find practical templates for EU AI Act compliance?
A: Independent hubs like ArtificialIntelligenceAct.eu offer guides and checklists. Look for resources that include decision frameworks and operational templates rather than just regulatory summaries. The official Service Desk can also direct teams to specific guidance documents.