The tiers
The Act sorts AI systems by the risk they present, and attaches a different obligation set to each band.
- Prohibited practices. A narrow set of uses that cannot be deployed at all. The first thing to check, because no amount of controls fixes a system in this band.
- High-risk systems. The bulk of the compliance burden — risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, and conformity assessment.
- Limited-risk systems. Transparency obligations, principally telling people they are interacting with a machine or looking at generated content.
- Minimal-risk systems. No specific obligation, though the rest of your regulatory stack still applies.
Know which role you hold
Obligations follow the role, and one organisation frequently holds several at once across different systems. Most enterprises are deployers of third-party systems, providers of anything they build or substantially modify, and importers or distributors in some supply chains. Substantially modifying a third-party system — or putting your name on it — can move you from deployer to provider, which is a materially heavier obligation set.
Building the readiness program
- Inventory and classify. Every AI system, its role, its tier, and its jurisdictional exposure.
- Gap assessment against the obligations for each tier and role combination you actually hold.
- Close on the high-risk set first — technical documentation and logging take the longest to produce retroactively.
- Wire transparency into the product, not into a policy page. Disclosure obligations are visible to every user and cheap to fail.
- Stand up post-market monitoring and the serious-incident reporting route before you need them.
Alongside GDPR, not instead of it
The AI Act does not displace data protection law. A high-risk system processing personal data owes obligations under both, and the assessments are complementary rather than duplicative: the DPIA asks about the individual's data, the AI conformity work asks about the system's behaviour. Running them as one combined assessment with two output sections saves substantial effort and produces a more coherent evidence pack.
What good readiness looks like
Not a certificate. A current inventory, a defensible classification for each system, technical documentation that a regulator could read without you in the room, and a log showing that oversight actually happened.