Skip to main content
STATUS: PRE-CONSTRUCTION · SITE A UNDER EXCLUSIVITYNODE: VASILIKOS-01 — 34.7246°N, 33.2247°ECAMPUS: RISC-V PHASE 1 · MULTI-SILICON EVAL · PLANNEDPOWER: 42MW ON-SITE GENERATION · DESIGN TARGETSTATUS: PRE-CONSTRUCTION · SITE A UNDER EXCLUSIVITYNODE: VASILIKOS-01 — 34.7246°N, 33.2247°ECAMPUS: RISC-V PHASE 1 · MULTI-SILICON EVAL · PLANNEDPOWER: 42MW ON-SITE GENERATION · DESIGN TARGET
AGICY.AI
StackTechnology OverviewRISC-V sovereign stackComputeBare-metal EU compute
FacilitiesData CentersVasilikos campusSustainability100% renewable mission
HardwareTenstorrent GalaxyPhase 1 Blackhole fleet (pre-COD)AESOLAR AlpineEnergy stack · hail-class PV + BESSAMD HeliosPhase 2 open rack-scale (eval · pre-COD)Taalas HC1Phase 2+ · model-hardwired ASIC (watchlist · pre-COD)CerebrasPhase 2 · wafer-scale eval (pre-COD)IBM z17 / LinuxONE 5Phase 2+ · trusted AI next to data (pre-COD)d-Matrix CorsairPhase 2–3 · on Watchlist (pre-COD)AWS Trainium 4Phase 2+ · custom XPU watchlist (pre-COD)
Submit your Hardware for reviewPropose accelerators for the Vasilikos fleet
GatewayCopperwayEU-sovereign OpenAI-compatible gatewayTry PlaygroundNewLive Copperway demo · PII vaultSovereign Exchange5-year cross-org sovereign planFor BuildersWhat developers can run today
ProductsReserve CapacityPre-construction LOI tiersMarketplaceCompute marketplaceGPUs Rent LiveLiveEU partner GPU now · until CODCompute VouchersSovereign compute creditsModel LeaderboardFrontier model rankingsPricingSubscription tiers
SolutionsInferenceProduction inferenceTrainingtt-train · planned campusFine-TuningLoRA, PEFT, domain modelsSovereign CloudEU-jurisdiction cloudAgentic PlatformAutonomous AI agentsReadinessPublic-data AI readiness scan
IndustriesFinancial ServicesRegulated finance AIHealthcareClinical & life sciencesGovernmentSovereign govt workloadsSemiconductorsFab & EDA data, EU-residentEnergyGrid & generation forecastingUtilitiesNIS2 essential entitiesPublic SectorCivil & public benefitProcurementLawful tender criteria
PricingTiers
Capital & EducationInvestInstitutional data room & deal flowAcademyAI training programs
Individuals & Family OfficesLiving in EUNewClass B capital allocation · no visa framingInternationalNewPlan B · equity alternative to propertyGreece Golden Visa€250k / €400k / €800k bands · vs Class BCyprus Permanent ResidenceReg. 6(2) parallel counsel · vs Class B
IntelligenceResearchPublications & portalsPublic-Record DeskGEMI registry · filings · courtsData CentersVasilikos campus briefing
CompanyAboutBrand · HoldCo targetMissionCharter & sovereigntyTrust CenterSecurity portal · docs · status
Schedule Briefing
Sign In
Regulation

EU AI Act Compliance for AI Infrastructure:
The Complete Guide

What deployers, GPAI providers, and infrastructure operators need to know before enforcement begins

July 2026~15 min readAGICY Research Team
EU AI Act compliance infrastructure architecture

Executive Summary

The EU AI Act entered into force on 1 August 2024, with enforcement rolling out in phases through August 2028. Infrastructure providers are affected primarily through two mechanisms: Article 26 deployer obligations (applying to any organisation that puts an AI system into service) and Article 53 obligations for general-purpose AI (GPAI) model providers. Compliance is not optional — penalties reach up to €35 million or 7% of global annual turnover. This guide explains what infrastructure providers must do, when each deadline hits, and why your choice of underlying hardware and cloud architecture directly affects your compliance posture.

Key Insight

Infrastructure providers occupy a unique position in the EU AI Act value chain. They are simultaneously deployers (Art. 26), potential providers of AI systems (Art. 16), and in some cases GPAI model integrators (Art. 53). This multi-role exposure means compliance cannot be addressed with a single checklist — it requires architectural decisions at the hardware, software, and operational layers.

Understanding the EU AI Act Architecture

The EU AI Act (Regulation (EU) 2024/1689) establishes a risk-based classification framework for AI systems. Understanding where infrastructure providers fit within this framework is the first step toward compliance.

Risk-Based Classification

  • Unacceptable Risk (Art. 5): Banned AI practices including social scoring, real-time biometric identification in public spaces (with exceptions), and manipulation of vulnerable groups. Infrastructure providers must ensure they do not enable these prohibited uses.
  • High Risk (Annex III):AI systems in critical domains — biometrics, critical infrastructure, education, employment, essential services, law enforcement, border control, and administration of justice. Subject to strict requirements including conformity assessments, risk management systems, and data governance.
  • Limited Risk (Art. 50):AI systems with transparency obligations — including chatbots, deepfake generators, and emotion-recognition systems. Users must be informed they are interacting with AI.
  • Minimal Risk: All other AI systems. Subject to voluntary codes of conduct but no mandatory requirements.

Infrastructure providers typically do not develop AI systems themselves, but they enable their deployment. This places them in the deployercategory under Article 26 — with all the obligations that entails. When infrastructure providers also host or serve GPAI models, Article 53 obligations layer on top.

Article 26 — Deployer Obligations for Infrastructure

Article 26 of the EU AI Act defines obligations for “deployers” — any natural or legal person that uses an AI system under its authority, except where the AI system is used in the course of a personal, non-professional activity. For infrastructure providers, the key obligations are:

1. Use in Accordance with Instructions (Art. 26(1))

Deployers must use high-risk AI systems in accordance with the instructions for use accompanying the system. Infrastructure providers must ensure their platforms enable customers to access and follow these instructions, and must not configure systems in ways that contravene manufacturer guidance.

2. Human Oversight Measures (Art. 26(2))

Deployers must assign human oversight to natural persons who have the necessary competence, training, and authority. Infrastructure providers must build platforms that support human-in-the-loop controls, including the ability to override, interrupt, or stop AI system outputs.

3. Input Data Relevance (Art. 26(4))

Where deployers exercise control over input data, they must ensure that data is relevant and sufficiently representative for the system's intended purpose. Infrastructure platforms must provide data quality monitoring and validation capabilities.

4. Monitoring & Incident Reporting (Art. 26(5))

Deployers must monitor the operation of high-risk AI systems based on the instructions for use and inform the provider or distributor of any serious incidents. The reporting window is 72 hours for serious incidents that constitute a serious risk to health, safety, or fundamental rights. Infrastructure must support real-time monitoring and automated incident detection.

5. Record-Keeping / Automatic Logging (Art. 26(6))

Deployers of high-risk AI systems must keep logs automatically generated by the system, to the extent they are under their control. Logs must be retained for a period appropriate to the intended purpose — at least six months unless otherwise specified. Infrastructure must provide immutable, tamper-resistant logging capabilities.

6. Data Protection Impact Assessments (Art. 26(9))

Deployers of high-risk AI systems that process personal data must carry out a Data Protection Impact Assessment (DPIA) under GDPR Article 35. Infrastructure providers must ensure their platforms provide the transparency and data-flow documentation necessary to support customer DPIAs.

Article 53 — GPAI Model Provider Obligations

General-purpose AI (GPAI) models — defined as AI models that display significant generality and are capable of competently performing a wide range of distinct tasks — carry additional obligations under Article 53. Infrastructure providers hosting or serving GPAI models must understand these requirements.

Core Obligations (Art. 53(1))

  • Technical Documentation: GPAI model providers must draw up and maintain technical documentation of the model, including its training and testing process, and make it available to the AI Office and national competent authorities upon request.
  • Information to Downstream Providers:Providers must supply information and documentation to downstream providers who integrate the GPAI model into their own AI systems, enabling them to understand the model's capabilities and limitations.
  • Copyright Compliance: Providers must implement a policy to comply with EU copyright law, including the Copyright Directive (EU) 2019/790, and must provide a sufficiently detailed summary of training data content.
  • Training Data Summary: A publicly available summary of the content used for training, following a template provided by the AI Office.

Systemic Risk Models (Art. 55)

GPAI models classified as posing systemic risk face additional obligations: adversarial testing (red-teaming), ongoing incident monitoring, adequate cybersecurity protections, and reporting of serious incidents to the AI Office. Infrastructure providers hosting systemic-risk GPAI models inherit responsibility for ensuring the technical infrastructure supports these requirements.

“If you host a GPAI model, you don't just provide compute — you inherit compliance obligations. Art. 53 makes infrastructure providers part of the AI supply chain, not mere utility providers.”

The Enforcement Timeline

The EU AI Act employs a phased enforcement approach. Infrastructure providers must track each deadline to ensure timely compliance:

  • 2 FEB 2025AI literacy obligations (Art. 4) and prohibited AI practices (Art. 5) take effect. Organisations must ensure staff interacting with AI have sufficient AI literacy.
  • 2 AUG 2025GPAI model obligations (Art. 53–55) and governance provisions apply. GPAI model providers must have technical documentation and copyright compliance in place.
  • 2 AUG 2026Main body of the Act applies. High-risk AI systems (Annex III) and deployer obligations (Art. 26) take effect. This is the primary compliance deadline for infrastructure providers.
  • 2 AUG 2027High-risk AI systems in Annex I (regulated products such as medical devices, machinery, aviation) must be fully compliant.
  • 2 AUG 2028AI systems already on the market must comply if they have been significantly modified. Full enforcement across all categories.

Why Infrastructure Choice Matters for Compliance

The EU AI Act does not prescribe specific technology choices. But the practical requirements of compliance create strong incentives toward certain architectural decisions. Infrastructure choice affects compliance across four critical dimensions:

1. Data Jurisdiction & GDPR Interplay

Where AI processing occurs matters. Art. 26(9) links to GDPR's DPIA requirements. Infrastructure located in an EU member state, operated by an EU-incorporated entity, eliminates cross-border data transfer complexities and reduces DPIA scope. Infrastructure subject to the US CLOUD Act introduces jurisdictional uncertainty that complicates compliance documentation.

2. Audit Trail Requirements

Art. 26(6) mandates automatic log retention. Infrastructure must support immutable, tamper-resistant logging of AI system operations, inputs, and outputs. Cloud platforms with limited logging transparency or vendor-controlled log access create compliance gaps.

3. Supply Chain Transparency

The Act's risk management framework requires understanding the full AI supply chain. Infrastructure with opaque hardware provenance, proprietary firmware, or undisclosed vendor dependencies makes supply-chain risk assessment difficult or impossible.

4. Incident Response

The 72-hour serious incident reporting window (Art. 26(5)) requires infrastructure that enables rapid detection, triage, and reporting. Platforms must provide automated anomaly detection, real-time alerting, and integration with national authority reporting channels.

How RISC-V Open Hardware Aids Auditability

Article 26 requires deployers to monitor AI systems and maintain oversight. Meaningful oversight requires understanding how the system operates at every layer — including the hardware executing inference computations. This is where the choice of instruction set architecture (ISA) becomes a compliance consideration.

Proprietary hardware(NVIDIA CUDA, Intel x86) operates with closed instruction sets. The ISA-level logic, firmware, and microcode are trade secrets. Organisations cannot independently verify what the hardware is doing at the silicon level — they must trust the vendor's attestation.

RISC-V open hardware uses an open instruction set architecture governed by RISC-V International, a Swiss-domiciled non-profit. The ISA specification is publicly available and auditable. This creates a verifiable chain:

  • Open ISA → auditable at the instruction-set level
  • Auditable firmware → verifiable boot and runtime integrity
  • Transparent software stack → open-source TT-Metalium (Apache 2.0)
  • Documented AI inference pipeline → end-to-end auditability

This aligns with the Cyber Resilience Act (CRA) security-by-design requirements and NIS2's supply-chain security provisions, which penalise opaque vendor dependencies in critical infrastructure.

AGICY's Compliance Architecture

European AI infrastructure providers face not one regulation but a convergence of four complementary frameworks. AGICY's architecture is designed to address all four simultaneously:

  • GDPR: Data processing within Cyprus (EU member state), full data jurisdiction control, DPIA-ready infrastructure with comprehensive data-flow documentation.
  • NIS2: Critical infrastructure cybersecurity compliance, supply-chain transparency through RISC-V open hardware, incident reporting to national CSIRT.
  • EU AI Act: Deployer obligations (Art. 26) met through full-stack logging, human oversight capabilities, automated monitoring, and 72-hour incident reporting pipeline. GPAI obligations (Art. 53) addressed through technical documentation and downstream provider information APIs.
  • DORA:For financial services customers — ICT risk management, digital operational resilience testing, and third-party risk monitoring capabilities built into the platform.
Multi-Regulation Compliance

AGICY's sovereign infrastructure is designed for multi-regulation compliance from the ground up: GDPR data jurisdiction through Cyprus (EU member state), NIS2 supply-chain transparency through RISC-V open hardware, EU AI Act audit capabilities through full-stack logging, and DORA-ready ICT risk management for financial services workloads.

Compliant vs Non-Compliant Infrastructure

The following table illustrates the practical differences between infrastructure designed for EU AI Act compliance and infrastructure that was not architected with these requirements in mind.

RequirementCompliant InfrastructureNon-Compliant Infrastructure
Data jurisdictionEU-sovereign, single jurisdiction, no CLOUD Act exposureMulti-jurisdiction, potential US CLOUD Act data access
Hardware auditabilityOpen ISA (RISC-V), inspectable firmware, verifiable boot chainProprietary closed architecture, vendor attestation only
Logging & monitoringFull inference audit trails, immutable tamper-resistant logsLimited or vendor-controlled logging, potential data gaps
Incident reportingAutomated 72-hour reporting pipeline to national authoritiesManual processes, delayed notification, uncertain escalation
Supply chain transparencyDocumented hardware provenance, open-source software stackOpaque vendor dependencies, proprietary supply chain
GPAI documentationTechnical documentation APIs, training data summaries availableDocumentation responsibility shifted entirely to customer
Human oversight enablementBuilt-in oversight dashboards, interrupt/kill switches, role-based accessBasic API access only, limited override capabilities
Cost of non-complianceProactive investment in compliance architectureUp to €35M or 7% of global annual turnover in penalties

Frequently Asked Questions

Does the EU AI Act apply to infrastructure providers who don't develop AI models?

Yes. Article 26 applies to “deployers” — defined as any natural or legal person that uses an AI system under its authority. Infrastructure providers that host, serve, or enable AI inference workloads are deployers even if they did not build the AI model. The obligation arises from use, not from development.

What is the penalty for non-compliance with the EU AI Act?

Penalties are tiered based on the severity of the violation. Breaches of prohibited AI practices (Art. 5): up to €35 million or 7% of global annual turnover, whichever is higher. Non-compliance with other obligations (including Art. 26 deployer duties): up to €15 million or 3% of global turnover. Supplying incorrect, incomplete, or misleading information to authorities: up to €7.5 million or 1% of global turnover.

How does the EU AI Act interact with GDPR?

The EU AI Act and GDPR are complementary, not duplicative. The AI Act addresses AI-specific risks — transparency, human oversight, technical documentation, risk management — while GDPR governs the processing of personal data. Where an AI system processes personal data, both regulations apply simultaneously. Notably, Art. 26(9) explicitly requires deployers of high-risk AI systems to conduct Data Protection Impact Assessments under GDPR Art. 35 before putting the system into use.

Do open-source AI models have different obligations under the EU AI Act?

Partially. Art. 53(2) provides limited exemptions for open-source GPAI models — specifically those with openly available model parameters, architecture, and usage information. These models are exempt from certain documentation and information-sharing requirements. However, this exemption does not apply if the model poses systemic risk. Open-source GPAI models classified as systemic risk must comply with the full Art. 55 obligations, including adversarial testing, incident monitoring, and cybersecurity protections.

When do infrastructure providers need to be fully compliant?

The primary deadline for infrastructure providers is 2 August 2026, when deployer obligations (Art. 26) and high-risk AI system requirements take effect. However, GPAI model provider obligations (Art. 53) already took effect on 2 August 2025, and AI literacy requirements applied from 2 February 2025. Infrastructure providers hosting GPAI models should already be addressing Art. 53 compliance. Providers are strongly advised to begin compliance work immediately rather than waiting for the August 2026 deadline.

Sources & References

  • 1 Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (EU AI Act). Official Journal of the European Union, L series, 12 July 2024.
  • 2EU AI Act, Article 26 — Obligations of deployers of high-risk AI systems. Sections 1–11.
  • 3EU AI Act, Article 53 — Obligations for providers of general-purpose AI models. Article 55 — Obligations for providers of general-purpose AI models with systemic risk.
  • 4 Regulation (EU) 2016/679 (General Data Protection Regulation / GDPR), particularly Art. 35 (Data Protection Impact Assessments) and Art. 48 (transfers or disclosures not authorised by Union law).
  • 5 Directive (EU) 2022/2555 (NIS2 Directive) on measures for a high common level of cybersecurity across the Union. Applicable from 17 October 2024.
  • 6 Regulation (EU) 2022/2554 (Digital Operational Resilience Act / DORA) for the financial sector. Applicable from 17 January 2025.
  • 7 Regulation (EU) 2024/2847 (Cyber Resilience Act / CRA) on horizontal cybersecurity requirements for products with digital elements.
  • 8 Regulation (EU) 2023/1781 (European Chips Act), establishing a framework for strengthening the European semiconductor ecosystem.

Disclaimer & Disclosure

This article was prepared by the AGICY Research Team for informational purposes only. AGICY.AI is developing sovereign AI infrastructure in Cyprus and has a commercial interest in the regulatory compliance advantages of its architecture. This content does not constitute legal advice. Organisations should consult qualified legal counsel for compliance guidance specific to their circumstances. All regulatory references are based on published EU legislation and official guidance as of July 2026.

Last updated: July 2026. This is a living document; content will be revised as implementing acts, delegated acts, and official guidance are published by the European Commission and AI Office.

Prepare Your Infrastructure for EU AI Act Compliance

Build on sovereign, auditable infrastructure designed for multi-regulation compliance from day one.

Secure Your SRA Allocation →View Pricing

§ FIN — Close of Document

Ready to build on sovereign infrastructure?

Schedule a confidential briefing with our team. NDA-protected, no commitment.

Schedule a briefing →
EU JURISDICTION · CYPRUSGDPR ART. 28 DPA-READY · BY DESIGNNIS2-ALIGNED · BY DESIGNEU AI ACT ART. 12 LOGGING SUPPORT · BY DESIGNRISC-V NATIVE · OPEN ISA

Design-alignment statements for a pre-construction facility — not certifications or attestations. Basis: compliance FAQ, § 08. Careers: we aim for 50-50 gender balance across hiring cohorts.

AGICY.AI

Advanced Governance & Intelligence Cyprus

The sovereign architecture for the Cyprus mind.
Humanitarian mandate: civilian public benefit only — healthcare, education, civil resilience. Civilian / humanitarian mandate only.
VASILIKOS ENERGY CENTRE, LIMASSOL DISTRICT · PRE-CONSTRUCTION
34.7246°N · 33.2247°E
Principal campus: Cyprus Vasilikos (Phase 1). Parallel HoldCo path: sovereign compute project in Greece (TARGET / planning) — ~20 MW-class Tenstorrent / air-cooled inference positioning for EU diversification; separate CapEx, no offtake claimed.

The Ledger — monthly briefing
  • CopperwayEU-sovereign OpenAI-compatible gateway
  • Try PlaygroundNewLive Copperway demo · PII vault
  • Compression & PII vaultNewSovereign path controls in Playground
  • Sovereign Exchange5-year cross-org sovereign plan
  • For BuildersWhat developers can run today
  • Reserve CapacityPre-construction LOI tiers
  • MarketplaceCompute marketplace
  • GPUs Rent LiveLiveEU partner GPU now · until COD
  • Compute VouchersSovereign compute credits
  • Model LeaderboardFrontier model rankings
  • PricingSubscription tiers
  • Research HubPublications & portals
  • Public-Record DeskGEMI registry, filings, court decisions
  • Data CentersVasilikos sovereign campus briefing
  • Frontier AI EthicsSovereign alternative to frontier dominance
  • Cyprus Court DecisionsBilingual legal research feed
  • Intelligence DrainEU talent & compute outflow analysis
  • National Equity in AISovereign AI for smaller EU nations
  • Compiler-First ChallengeJim Keller thesis vs GPU orthodoxy
  • GDDR6 & Open InfrastructureGalaxy economics & sovereign TCO
  • Blackhole Performance RisksVendor benchmarks & due diligence
  • Security Audit ResearchCybersecurity methodology & findings
  • AI Readiness AuditExecutive readiness assessment
  • Readiness HubPublic-data scans & named assessments
  • ProcurementLawful sovereignty criteria for tenders
  • AboutProject identity & status
  • MissionCharter & sovereignty
  • CareersCulture, benefits & hiring ethos
  • Open PositionsEngineering, research & operations roles
  • Ethics & CharterAnti-misconduct & responsible AI
  • Editorial & MethodologySources, claims, corrections
  • Trust CenterSecurity portal · docs · status
  • InvestInstitutional data room & deal flow
  • Living in EUIndividuals & FOs · Class B allocation
  • International investorsPlan B · Greece / Cyprus rails · Class B
  • Equity participation (legacy)CY & GR individual interest · counsel-gated
  • AcademyAI training programs
  • ContactBriefings & inquiries
  • Privacy PolicyGDPR · data processing
  • Terms of ServicePlatform usage terms
  • Cookie PolicyTracking & consent
  • SRA TermsReserve capacity agreement
  • Gateway Pricing DisclaimerCopperway pricing basis
© 2026 AGICY· PROJECT / BRAND OPERATOR · PLANNED CYPRUS ENTITIES NOT YET INCORPORATEDDOC: AGICY.AI · REV 2.0 · SOVEREIGN LEDGER
AGICY