Regulation

EU AI Act Readiness

The EU AI Act allocates obligations by risk tier and by role. Getting both right is most of the readiness work.

The tiers

The Act sorts AI systems by the risk they present, and attaches a different obligation set to each band.

Know which role you hold

Obligations follow the role, and one organisation frequently holds several at once across different systems. Most enterprises are deployers of third-party systems, providers of anything they build or substantially modify, and importers or distributors in some supply chains. Substantially modifying a third-party system — or putting your name on it — can move you from deployer to provider, which is a materially heavier obligation set.

Building the readiness program

  1. Inventory and classify. Every AI system, its role, its tier, and its jurisdictional exposure.
  2. Gap assessment against the obligations for each tier and role combination you actually hold.
  3. Close on the high-risk set first — technical documentation and logging take the longest to produce retroactively.
  4. Wire transparency into the product, not into a policy page. Disclosure obligations are visible to every user and cheap to fail.
  5. Stand up post-market monitoring and the serious-incident reporting route before you need them.

Alongside GDPR, not instead of it

The AI Act does not displace data protection law. A high-risk system processing personal data owes obligations under both, and the assessments are complementary rather than duplicative: the DPIA asks about the individual's data, the AI conformity work asks about the system's behaviour. Running them as one combined assessment with two output sections saves substantial effort and produces a more coherent evidence pack.

What good readiness looks like

Not a certificate. A current inventory, a defensible classification for each system, technical documentation that a regulator could read without you in the room, and a log showing that oversight actually happened.

← All AI Governance articles

Need help applying this?

Tell me the jurisdiction, the systems in scope and the deadline. I will tell you what is realistic.