Overview
The EU AI Act is Regulation (EU) 2024/1689. It entered into force on 1 August 2024 and applies in stages. It was amended by the AI Omnibus, Regulation (EU) 2026/1744, which entered into force on 27 July 2026 and moved the high-risk dates. The dates below are those of the amended text, as of 30 September 2026. Most of the Act’s detailed duties attach to high-risk AI systems and fall on their providers (who develop a system and place it on the market or put it into service under their name) and deployers (who use it under their authority). Grantex is an authorisation layer: it records which agent was allowed to do what, on whose authority, and what happened. Those records can help evidence some of these duties. They do not make a system compliant. Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership or IP questions may be sent to sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.Timeline
The separate “Digital Omnibus” on data protection (COM(2025) 837) is still a
proposal; the GDPR is unchanged.
Roles and classification
- A team that builds an agent on a third-party model is usually the provider of an AI system, a deployer of it, or both. It is not a GPAI model provider unless it places a general-purpose model on the market.
- An authorisation layer such as Grantex is not itself a high-risk AI system. An agent is high-risk if it falls under Art. 6: a safety component of an Annex I product, or a use listed in Annex III (for example credit scoring, recruitment or access to essential services).
- Art. 6(3) lets a provider conclude that an Annex III system is not high-risk when it does not pose a significant risk, but never when it profiles natural persons; the provider documents that assessment and registers the system (Art. 6(4)). The Commission’s classification guidelines were published as a draft on 19 May 2026.
Obligations and what Grantex provides
GPAI model obligations are in Arts. 53-55, not Art. 50.
The EU AI Act evidence export
POST /v1/dpdp/exports with "type": "eu-ai-act-evidence" returns sections
mapped to Arts. 12, 14, 26, 50 and 73, each naming its data source, with an
applicability block of the dates above and a disclaimer that it is evidence
for the operator’s own assessment, not a conformity assessment:
eu-ai-act-conformance type is kept for compatibility;
despite its name, it is not a conformity assessment.
Examples
Register an agent with narrow scopes and ask a person for a grant (the grant bounds what the agent may do, and the person’s approval is recorded):Penalties (Art. 99)
- Prohibited practices (Art. 5): up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher.
- Most operator obligations, including those of providers (Art. 16), deployers (Art. 26) and Art. 50: up to EUR 15 million or 3%.
- Supplying incorrect or misleading information to authorities: up to EUR 7.5 million or 1%.
- For SMEs, including start-ups, and small mid-caps, each cap is the lower of the two amounts.
- GPAI model providers (Art. 101): up to EUR 15 million or 3%, enforceable by the Commission from 2 August 2026.
Cross-framework mapping
These are technical mappings, not a statement that any framework is met.Sources
- European Commission: AI Act regulatory framework
- European Commission: the AI Omnibus enters into force
- AI Act Service Desk: article texts (some article pages may still show the text before Regulation (EU) 2026/1744)
Related Resources
- DPDP Act 2023 — India’s data protection mapping
- DPDP Compliance Module — features and examples
- EU AI Act Evidence Pack — export reference
- Compliance Evidence Pack API — audit-chain evidence
- Compliance Matrix — cross-framework mapping
- OWASP Agentic Top 10 Blog — threat taxonomy mapping