Skip to main content

EU AI Act Readiness Guide

A working guide to preparing for the EU AI Act: who it reaches, how its risk tiers work, what high-risk obligations actually require in artifacts, and a readiness sequence that starts where every assessment starts — with the AI model inventory.

Who the EU AI Act Reaches

The EU AI Act is the first comprehensive, horizontal AI regulation, and its reach is deliberately wide. It applies to providers who place AI systems on the EU market, to deployers who use AI systems within the EU, and — the part that surprises many organizations — to providers and deployers outside the EU whenever the system's output is used in the EU. A US-based company whose AI-assisted screening affects EU candidates is in scope regardless of where the model runs.

Roles matter as much as geography: the Artificial Intelligence Act assigns different obligations to providers, deployers, importers, and distributors, and one organization can hold several roles at once for different systems. The first readiness question is therefore not "does the AI Act apply to us?" but "for which systems, and in which role?"

The Risk-Tier Model

The EU AI Act regulates by risk tier, not by technology:

Tier What falls here Obligation weight
Prohibited Social scoring that leads to detrimental treatment (public and private actors alike), certain manipulative or exploitative systems, and real-time remote biometric identification in publicly accessible spaces for law enforcement (narrow exceptions) Banned outright
High-risk AI in employment, credit, essential services, education, safety components, law enforcement contexts (Annex use cases) The full obligation set below
Limited risk Chatbots, systems generating synthetic content Transparency duties — users must know they are interacting with AI, and AI-generated content must be disclosed as such
Minimal risk The long tail: spam filters, recommendation features, internal productivity AI No new obligations; voluntary codes

Tier classification is itself a governed decision worth recording: the classification, the reasoning, and who made the call. When a regulator or customer asks why a system was treated as limited-risk, "we assessed it in 2026 and here is the record" is a materially different answer from a shrug.

What High-Risk Obligations Require

For high-risk systems, the AI Act requires a documented risk management system operating across the lifecycle, data governance over training and testing data, technical documentation sufficient for authorities to assess compliance, automatic event logging, transparency to deployers, human oversight, and demonstrated accuracy, robustness, and cybersecurity.

The practical reading: each obligation is an artifact demand. A risk management system means a living risk register with AI-specific entries and review cadence. Data governance means documented provenance and bias examination of training data. Logging means retained, reviewable records of system behavior. Readiness work is the work of being able to produce these artifacts on request — organizations that can already show a governance evidence trail for each model are most of the way there.

Start with the AI Model Inventory

Every credible EU AI Act readiness effort starts with an AI model inventory, because every downstream obligation attaches to a specific system. A sufficient inventory entry records: the system, its purpose and deployment context, the provider/deployer role held, the risk-tier classification with its rationale, the responsible owner, and links to the system's evidence — assessments, test results, logging locations.

Organizations frequently discover during inventory construction that they operate materially more AI than leadership believed, once vendor-embedded AI and team-built automations are counted. That discovery is the point: an obligation cannot be met for a system nobody registered. The model inventory converts the Act from an abstract legal risk into a bounded work list.

Human Oversight Under the Act

The EU AI Act makes human oversight a design obligation for high-risk systems: they must be built so that the people overseeing them can understand the system's capabilities and limitations, remain aware of automation bias, correctly interpret output, and intervene — including stopping the system. Oversight that exists on an org chart but cannot act in practice does not meet the bar.

Deployers carry their own duty to assign oversight to people with the competence, training, and authority to exercise it. For readiness purposes this converts to three checkable properties per system: a defined human-in-the-loop or human-on-the-loop role, an intervention path that has been tested rather than assumed, and a record of interventions when they occur.

Evidence, Documentation, and the Audit Trail

The Act's documentation obligations reward organizations that treat governance evidence as a product. Technical documentation must be current, not archaeological — reconstructed documentation is both expensive and visibly reconstructed. Event logging must produce an audit trail that can answer what the system did, when, and under which model version. Deployers and providers both benefit when audit evidence — test results, classification rationales, oversight records, incident history — is retrievable per system rather than scattered across teams.

A useful internal bar: for any high-risk system, can the responsible owner produce the current technical documentation and last quarter's audit trail in under a day? If not, the gap is operational, not legal.

Timeline and Sequencing

The EU AI Act phases in over years: prohibitions and AI literacy duties first, general-purpose AI model obligations next, then the main high-risk obligation set, with some embedded-product categories trailing. Rather than anchoring to specific dates — which shift with implementing acts and guidance — treat the sequence as the plan: prohibitions checked immediately, inventory and tier classification now, high-risk artifact construction as the sustained middle phase, and conformity-assessment preparation last.

The sequencing insight most organizations miss: inventory and classification are cheap relative to the high-risk artifact set, but they determine its size. Doing them early converts an unbounded compliance program into a costed one.

A Practical Readiness Checklist

# Readiness item Evidence it exists
1 AI model inventory covering vendor-embedded AI Inventory with owners and roles per system
2 Risk-tier classification per system, with rationale Recorded classification decisions
3 Prohibited-practice screen completed Signed-off screening record
4 Risk register entries for each high-risk system Register with triggers, owners, review dates
5 Human oversight designed and tested per high-risk system Oversight roles, tested intervention path, override log
6 Logging and audit trail operational Retrievable event records per system
7 Technical documentation current Documentation produced within the last review cycle
8 Supplier obligations flowed down Contract clauses and vendor attestations for embedded AI

Where Governance Tooling Helps

The EU AI Act rewards exactly the capabilities that AI governance platforms exist to provide: a living model inventory instead of a spreadsheet that decayed the week after it was built; obligations mapped to a control framework so each requirement traces to controls and their evidence; classification and oversight decisions recorded as governance records rather than meeting minutes; and audit evidence retrievable per system on demand. Control mapping is the connective tissue — when each Act obligation is mapped to named controls with owners and evidence, readiness stops being a project and becomes a reportable state.

None of this replaces legal counsel on scope questions. It replaces the scramble that follows when counsel asks "show me what we have."