EU AI Act — Article 10 enforcement: August 2026

The AI you deployed today
could be your biggest
compliance risk tomorrow.

Article 10 isn't about your model. It's about proving your training data was fit to build it. If regulators ask — and they will — you need documentation that holds up. KCCI helps regulated organisations prepare before that question arrives.

Are you exposed? Ask yourself:
  • Can you document how your training data was collected and prepared?
  • Have you examined your dataset for bias across protected characteristics?
  • Do you have an Annex IV technical file ready for regulatory review?
  • Does your data provenance trail survive a third-party audit?
Enforcement deadline
August 2026
Fines up to €30M or 6% of global revenue
Understanding the obligation

What is Article 10 —
and why does it matter to you?

What is Article 10 of the EU AI Act?

Most AI Act conversations focus on the model. Article 10 focuses on the data that trained it — and whether you can prove it was fit for purpose.

Article 10 requires organisations deploying high-risk AI systems to document and demonstrate the quality, governance, and provenance of the datasets used to train and validate those systems. It is not enough to have a good model. You must be able to show the data behind it meets defined standards. The full regulatory text is published in the Official Journal of the EU (Regulation 2024/1689) ↗.

Which AI systems are covered?

Article 10 applies to any AI system classified as high-risk under Annex III of the EU AI Act ↗ — including systems used in credit scoring, healthcare diagnostics, recruitment, education assessment, critical infrastructure, and law enforcement. If your organisation uses AI in any of these areas, Article 10 applies to you.

What happens if you cannot demonstrate compliance?

Regulators may require you to suspend or withdraw your AI system. Fines for high-risk AI system violations can reach €15 million or 3% of global annual turnover — whichever is higher. More immediately: if a client, partner, or procurement team asks for evidence of Article 10 compliance and you cannot provide it, that is a commercial problem today, not just a regulatory problem in 2026.

When does Article 10 come into force?

Article 10 obligations for Annex III high-risk systems apply from August 2026. The EU AI Act entered into force in August 2024. No extension is expected for high-risk system obligations. See the European Commission AI Act timeline ↗ for the full phased implementation schedule.

The six Article 10(2) requirements
  • 10(2)(a)
    Data collection design Relevant data management and processing practices must be documented.
  • 10(2)(b)
    Data preparation operations Annotation, labelling, cleaning, and enrichment processes must be recorded.
  • 10(2)(c)
    Formulation of assumptions Assumptions made about what the data represents must be explicit.
  • 10(2)(d)
    Relevance and representativeness Training data must be representative of the population the AI will affect.
  • 10(2)(e)
    Freedom from errors Possible errors, deficiencies, and gaps in the dataset must be assessed.
  • 10(2)(f)
    Statistical properties and bias Characteristics relevant to the specific context — including potential bias — must be examined and documented.
Common questions
What is an Article 10 dataset audit?

A structured assessment of your AI training and validation datasets against Article 10(2)(a)–(f). The output is a compliance gap report and Annex IV-ready technical documentation you can present to regulators or procurement teams.

What is Annex IV documentation?

Annex IV specifies the technical file providers of high-risk AI systems must maintain — covering system description, training data governance, performance metrics, and risk measures. It must be kept up to date and made available to national competent authorities on request.

Does Article 10 apply to us?

If your organisation deploys or provides an AI system that falls under any of the Annex III categories — healthcare, credit scoring, recruitment, education, critical infrastructure, biometrics, or law enforcement — Article 10 applies. Our EU AI Act Readiness Scan confirms your classification in two weeks.

How long does an Article 10 audit take?

Our Article 10 Dataset Audit typically takes two to four weeks from engagement to final report, depending on the complexity of your training dataset and the number of AI systems in scope. The Readiness Scan that precedes it takes one to two weeks.

Services

A focused practice.
Five services. One clear purpose.

Every service either prepares you for the Article 10 Audit, delivers it, or protects the compliance you have achieved.

Start here
EU AI Act Readiness Scan

Assessment of your AI systems against Article 10 obligations. Annex III classification, data governance gap analysis, and compliance risk score (Low / Medium / High / Critical). Delivered as executive report and technical annex.

Alternative entry
Data Governance & GDPR Audit

Audit of existing data collection practices against GDPR. Consent framework review, data retention assessment, DPA template design. Article 10 exposure flagged wherever AI training data is involved.

Core Service ★
Article 10 Dataset Audit

Full Article 10(2)(a)–(f) assessment of your existing training dataset. Representativeness, bias, provenance, quality gap analysis. Annex IV-ready technical documentation. Remediation roadmap. Legal sign-off available.

Follow-on
Annex IV Compliance Documentation

Full EU AI Act Annex IV technical documentation package for one AI system. System description, data governance summary, risk classification, conformity assessment preparation. Reusable framework for future system updates.

Recurring ★
AI Compliance Retainer

Quarterly Article 10 dataset review · Dataset change assessment (new data sources, model retraining) · EU AI Act regulatory update briefings · Annex IV document maintenance · Priority access to audit team · Annual compliance health check. Minimum 12-month commitment.

★ Compliance Launch Bundle
Readiness Scan + GDPR Audit + Article 10 Audit — complete compliance foundation

EU AI Act Readiness Scan + Data Governance Audit + Article 10 Dataset Audit, delivered as one integrated engagement over 4–6 weeks. Single contract. Full compliance foundation before the August 2026 deadline.

How it works

Two ways in. One destination.

Most clients enter through the Readiness Scan. Some enter through the GDPR Audit if data governance concerns came first. Both paths lead to the Article 10 Dataset Audit — and then to ongoing compliance.

1
Readiness Scan
Identifies Article 10 exposure. Ends with recommended audit scope.
2
GDPR Audit
Surfaces Article 10 exposure through data governance gaps.
3
Article 10 Audit ★
Full compliance assessment. Annex IV documentation package.
4
Annex IV Package
Formal compliance documentation ready for regulators.
5
Compliance Retainer
Ongoing monitoring, updates, and regulatory maintenance.

Not sure where to start? Begin with the EU AI Act Readiness Scan. In two weeks you will have a clear picture of your Article 10 exposure, a risk score, and a recommended next step. No commitment beyond the scan required. Send an enquiry →

Our Focus

Categorised by regulatory exposure.
Mapped to your exact risk level.

KCCI works with organisations across all sectors deploying AI systems. Whether your system falls under Annex III high-risk obligations ↗ or sits in adjacent territory, we help you understand your Article 10 exposure and build the documentation that demonstrates compliance. Below are the sectors we work with most.

★★★ Annex III · High Risk
Healthcare AI
Annex III §2(a) — diagnostic, triage, treatment
★★★ Annex III · High Risk
Financial Services AI
Annex III §5(b) — credit scoring, underwriting
★★★ Annex III · High Risk
HR Technology AI
Annex III §4(a) — recruitment, performance, promotion
★★ Annex III · High Risk
Critical Infrastructure
Annex III §2(b) — energy, water, transport
★★ Annex III · High Risk
Education AI
Annex III §3(a) — student assessment, admissions
Standard System
General Enterprise AI
Not explicitly Annex III — customer, ops, forecasting
★ Founding Compliance Partner Programme

5 organisations.
Shaping the standard.

We are inviting a small number of NL/BE organisations to join as Founding Compliance Partners — with early methodology input, priority access, and permanent recognition in our published materials. An exclusive founding membership, not a standard client engagement.

Founding Partner slots remaining
1 of 5 slots remaining · Year 1 only · Limited founding membership
  • Founding Partner recognition
    Named on our website and in client proposals as a Founding Compliance Partner.
  • Methodology influence
    Your feedback shapes our audit deliverable format and future Article 10 frameworks.
  • Priority access
    Direct line to senior audit partner throughout the engagement. No account management delays.
  • Reference partnership
    Named reference for one prospect call per quarter. Mutual value: your recognition, our pipeline.
Client story

From first scan to full audit.
A compliance journey in 8 weeks.

Financial Services Article 10 Dataset Audit
"We came in thinking we had a data quality problem. KCCI showed us it was an Article 10 compliance problem — and that the gap between the two was significant. The audit gave us documentation we could take directly to our board and to our legal team. That did not happen with any of the generic AI governance work we had done before."
Chief Data Officer, NL-based financial services firm
01
The situation

A mid-market financial services firm operating in the Netherlands had deployed a credit risk scoring model trained on five years of customer transaction data. With the EU AI Act enforcement deadline approaching, their legal team flagged the system as a probable Annex III high-risk AI application — meaning Article 10 dataset obligations would apply. The firm had no documentation of their training data's representativeness, no bias examination on record, and no Annex IV technical file in preparation.

02
The EU AI Act Readiness Scan

The firm engaged KCCI for a two-week EU AI Act Readiness Scan. The scan confirmed the credit scoring system's classification under Annex III §5(b) and identified three specific Article 10(2) gaps: insufficient documentation of data collection methodology, absence of bias examination across protected characteristics, and no provenance trail for the historical transaction data used in training. The output was a structured compliance risk report with a severity rating of High and a recommended Article 10 Audit scope.

The scan report was presented to the firm's CDO and General Counsel in a single debrief session. By the end of that meeting, the decision to proceed to the full Article 10 Dataset Audit had been made. The quality and specificity of the scan output made the conversation straightforward — the gaps were documented, the regulatory obligation was clear, and the path forward was explicit.

03
The Article 10 Dataset Audit

The full Article 10 Dataset Audit ran over three weeks. KCCI assessed the training dataset against all six Article 10(2)(a)–(f) requirements: data collection practices, data preparation operations, representativeness, error rates, and characteristics of the specific geographic and demographic populations for which the credit model was deployed. Bias examination was conducted across age, gender, and postcode-derived socioeconomic indicators — all protected or proxy characteristics relevant to consumer credit decisions under Dutch and EU law.

The audit identified two material gaps requiring remediation: a representativeness gap in the training data for applicants under 30, and insufficient documentation of the data preparation steps applied to historical records from a legacy system migration in 2021. A remediation roadmap was provided alongside the Annex IV-ready technical documentation package.

04
The outcome

Eight weeks after the initial scan engagement, the firm held a complete Article 10 compliance package: a risk-rated gap analysis, a full Article 10(2) audit report, an Annex IV technical documentation file, and a prioritised remediation roadmap. The documentation was reviewed and signed off by an external GDPR and AI Act legal specialist as part of the engagement. The firm's legal team confirmed the package met the standard required for regulatory disclosure.

The firm subsequently engaged KCCI on a Compliance Retainer to maintain the documentation as the credit model is periodically retrained and as EU AI Act guidance evolves toward the August 2026 enforcement date.

8 weeks
Scan to full compliance package
3 gaps
Article 10 obligations identified in scan
Annex IV
Technical documentation complete and legally reviewed
Retainer
Ongoing compliance relationship established
Client name withheld at their request. Sector, system type, and engagement timeline are accurate. Published with permission.
Why KCCI

A specialised firm
built specifically for Article 10.

Specialists, not generalists

We do not offer AI strategy, digital transformation, or general governance consulting. We do one thing: assess and document EU AI Act Article 10 dataset compliance. That focus is what makes us credible.

Annex IV documentation ready

Our audit output is not a gap report. It is a compliance package designed to satisfy Annex IV technical file requirements — the documentation your notified body or regulator will ask to see.

Focused on SMEs and mid-market organisations

We work with SMEs and mid-market organisations navigating EU AI Act compliance for the first time. Our engagements are designed to be practical, scoped, and proportionate — not enterprise frameworks applied at scale to smaller teams.

Compliance does not end at the audit

AI systems change. Regulation evolves. Our Compliance Retainer keeps your Article 10 documentation current without repeating the full audit each time — protecting your initial investment.

EDIH-SNL delivery partner

Registered delivery partner in the EU-funded EDIH-SNL network — the digital innovation hub supporting Dutch organisations navigating EU AI Act compliance. Access to structured guidance and peer benchmarking.

August 2026 is closer than it looks

Enterprise compliance projects typically run 4–12 weeks. A Readiness Scan takes 2 weeks. The Article 10 Audit takes 2–4. Starting now leaves time to remediate before the deadline. Starting in Q4 2025 may not.

About KCCI

Built for this moment.
Practised in this domain.

KCCI is a Cyprus and Netherlands-based AI data governance and EU AI Act compliance consultancy. We were founded by practitioners with backgrounds spanning AI/ML development, data law and GDPR practice, and large-scale commercial AI deployment across regulated sectors in Benelux and internationally.

Our focus is narrow by design. Article 10 of the EU AI Act creates a specific, technical compliance obligation that general AI consultancies are not built to address. We are.

Practice credentials
  • Cyprus and Netherlands incorporated — CY + NL registered
  • EU AI Act Article 10 specialist methodology — reviewed and validated
  • EDIH-SNL delivery partner — EU-funded digital innovation hub network
  • Annex IV documentation framework — built on regulatory text, not interpretation
  • GDPR-compliant data processing — DPA framework in place
  • Legal specialist network — GDPR/AI Act advisors on call for Svc 02/03
  • CAIRNE member — Coalition for AI Research and Innovation in Europe
  • EU AI Act Article 10 specialist — Benelux, Cyprus and international
Get in touch

August 2026.
Start now.

A 30-minute discovery call is enough to understand whether your AI system has Article 10 exposure and what a realistic compliance path looks like. No commitment. No jargon. Just an honest assessment.

  • Speak directly with a senior consultant — not a sales team
  • Receive an initial read on your likely Article 10 exposure
  • No obligation beyond the call
  • Response within one business day
  • 📍 Cyprus & Netherlands · Benelux + international coverage · Remote-first
  • 🌐 kcci.cy
  • 📅 Discovery calls available within 5 working days
  • ⏱️ Readiness Scan delivered within 2 weeks of engagement
Founding Partner enquiries

If you are enquiring about the Founding Compliance Partner Programme (limited to 5 founding organisations), please select "Founding Partner" in the form. We respond to all Founding Partner enquiries within 24 hours.