These are the best ways to prepare your company for EU AI Act compliance: 

  1. Define the scope of the AI Act compliance programme
  2. Create a reliable AI system inventory
  3. Determine the company’s regulatory role
  4. Classify each AI system by risk
  5. Identify obligations and assign responsibility
  6. Introduce proportionate AI controls
  7. Review AI suppliers and contracts
  8. Connect AI Act compliance with GDPR and existing governance
  9. Build an evidence and documentation system
  10. Monitor AI systems throughout their lifecycle

The EU AI Act is changing how companies develop, purchase and use artificial intelligence. Compliance is no longer an issue only for technology providers. Organisations using AI for recruitment, customer service, fraud detection, credit decisions, healthcare, education or other business activities may also have significant responsibilities.

Preparation begins with understanding where AI is already being used, what purpose each system serves and whether the organisation acts as a provider, deployer, importer or distributor. From there, companies can identify the relevant obligations, introduce suitable controls and collect the evidence needed to demonstrate compliance.

The work should not be treated as a single legal review. AI systems, vendors, data sources and business purposes change over time. Companies therefore need an operating model that connects legal, privacy, security, procurement, risk and technology teams throughout the AI lifecycle.

10 phases for preparing your company for EU AI Act compliance

The following phases provide a practical route from identifying AI systems to establishing an ongoing compliance programme.

Phase 1: Define the scope of the AI Act compliance programme

The first step is to determine which parts of the organisation should be included. Companies often begin with obvious tools, such as internally developed machine learning models, while overlooking AI features embedded in software already used by marketing, human resources, finance, security or customer support teams.

The scope should cover AI systems that are developed internally, purchased from vendors, accessed through cloud services or integrated into wider business platforms. It should also include pilot projects and systems being tested before formal deployment.

Companies should identify:

  • The business purpose of each AI system.
  • The department using or managing it.
  • The individuals affected by its outputs.
  • The data processed by the system.
  • The supplier or developer involved.
  • The geographical markets in which it is used.
  • Whether the output influences a decision about a person.
  • Whether the system is connected to a regulated product or service.

A clear scope prevents compliance work from becoming limited to a small number of visible systems while unmanaged AI continues to operate elsewhere.

Phase 2: Create a reliable AI system inventory

An AI inventory is the foundation of an effective compliance programme. Without it, the company cannot classify systems, assign responsibilities, monitor suppliers or determine which controls are required.

The inventory should contain more than a list of product names. It should record enough information to support legal and operational decisions.

Useful inventory fields include:

  • System name and description.
  • Business purpose and intended use.
  • System owner and operating team.
  • Developer, supplier and relevant subcontractors.
  • Users and affected individuals.
  • Data categories and data sources.
  • Countries in which the system is available.
  • Regulatory role of the organisation.
  • Preliminary risk classification.
  • Human oversight arrangements.
  • Existing assessments and approvals.
  • Links to contracts, technical documents and policies.
  • Monitoring and review dates.

Companies also need a process for discovering new AI systems. Procurement reviews, privacy assessments, security reviews, software registers and expense records can all reveal tools that have not been formally declared.

An intake process should require teams to register proposed AI systems before purchase, development or deployment. This allows compliance questions to be addressed before the company becomes operationally dependent on a product.

Phase 3: Determine the company’s regulatory role

The organisation’s responsibilities depend partly on its role in relation to each AI system. A company may be a deployer for one system and a provider for another.

A company that purchases an AI tool and uses it according to the supplier’s instructions will often act as a deployer. However, its position may change if it substantially modifies the system, places it on the market under its own name or changes its intended purpose.

The role assessment should consider:

  • Who developed the system.
  • Whose name or trademark appears on it.
  • Who defined its intended purpose.
  • Whether the system has been substantially modified.
  • Whether it is supplied to customers or other organisations.
  • Whether it has been integrated into another product.
  • Who controls the instructions, documentation and updates.

The result should be recorded for each system. Where the answer is uncertain, the company should document the reasoning and escalate the matter for specialist review.

Phase 4: Classify each AI system by risk

The AI Act follows a risk based approach. Some practices are prohibited, certain systems are classified as high risk and others are subject to transparency or more limited obligations.

Classification should begin with the intended purpose and the way the system is actually used. A product description or supplier label is not enough. The same underlying technology can fall into different categories depending on the context.

The assessment should consider whether the system:

  • Uses a practice prohibited by the AI Act.
  • Falls within one of the high risk areas listed in the legislation.
  • Performs profiling or influences decisions about individuals.
  • Interacts directly with people.
  • Generates or manipulates text, images, audio or video.
  • Uses emotion recognition or biometric categorisation.
  • Forms part of a regulated product.
  • Supports employment, education, credit, insurance or access to essential services.
  • Incorporates a general purpose AI model.

The European Commission has published guidance on the classification of high risk AI systems. Companies should compare that guidance with the facts of each use case and preserve the analysis behind the final classification.

Classification should not be a one time exercise. A change in purpose, data, user group, model, supplier or deployment environment may alter the risk category and the organisation’s obligations.

Phase 5: Identify obligations and assign responsibility

Once systems have been classified, the company can map the applicable obligations to responsible teams.

Legal and compliance teams can interpret regulatory requirements, but they cannot operate the entire programme alone. Technology, data, security, privacy, procurement, human resources and business teams will often own significant parts of the control environment.

Responsibility should be assigned for:

  • Approving new AI use cases.
  • Completing risk and impact assessments.
  • Reviewing training and input data.
  • Maintaining technical documentation.
  • Providing information to users.
  • Implementing human oversight.
  • Monitoring system performance.
  • Managing supplier relationships.
  • Recording incidents and complaints.
  • Reviewing significant system changes.
  • Retaining compliance evidence.
  • Reporting material risks to senior management.

A responsibility model should identify who performs each activity, who approves it and who must be consulted. It should also establish an escalation route for systems that cannot be classified confidently or that create significant legal, ethical or operational concerns.

Phase 6: Introduce proportionate AI controls

Controls should reflect the system’s purpose, risk and the company’s regulatory role. Applying the same process to every AI tool can waste resources while failing to address the systems that create the greatest exposure.

Depending on the use case, controls may include:

  • Documented approval before development or purchase.
  • Data quality and data governance checks.
  • Privacy assessments where personal data is processed.
  • Security testing and access restrictions.
  • Accuracy and performance criteria.
  • Bias and discrimination testing.
  • Human review of significant decisions.
  • Clear instructions for employees and operators.
  • Transparency notices for affected individuals.
  • Logging and record retention requirements.
  • Incident reporting and corrective action procedures.
  • Periodic review of system performance and purpose.

Human oversight must be meaningful. Naming a person as an approver does not provide effective oversight if that person cannot understand the output, challenge the recommendation or intervene when the system behaves unexpectedly.

Companies should define when human review is required, what information the reviewer receives and what authority the reviewer has to disregard or stop the system.

Phase 7: Review AI suppliers and contracts

Many companies rely on external providers for AI models, software platforms, infrastructure and data. The organisation may not control how these products were developed, but it still needs enough information to understand and manage its own obligations.

Supplier due diligence should examine:

  • The intended purpose and limitations of the system.
  • The supplier’s role under the AI Act.
  • The system’s claimed risk classification.
  • Technical and user documentation.
  • Data sources and data governance practices.
  • Testing for accuracy, robustness and bias.
  • Security and incident management arrangements.
  • Human oversight features.
  • Logging and monitoring capabilities.
  • Use of subcontractors and external models.
  • Change notification procedures.
  • Cooperation with audits, investigations and regulatory requests.

Contracts should address access to necessary documentation, notification of material changes, incident reporting, audit support, data use, security requirements and responsibility for corrective action.

Existing contracts may not contain sufficient AI specific protections. Companies should prioritise reviews for strategically important systems and use upcoming renewals as an opportunity to strengthen the terms.

Phase 8: Connect AI Act compliance with GDPR and existing governance

AI Act compliance should not operate separately from privacy, security, procurement and enterprise risk processes. Many required activities already exist in another form.

An AI assessment may need to connect with:

  • A data protection impact assessment.
  • A legitimate interests assessment.
  • A security risk assessment.
  • A vendor review.
  • A product approval process.
  • A model validation process.
  • An internal audit plan.
  • An incident response procedure.

Where personal data is involved, companies should assess both the AI Act and the GDPR. Compliance with one does not automatically establish compliance with the other.

Organisations can also align their controls with ISO 42001 and AI governance practices. A management system approach can help integrate policies, ownership, objectives, monitoring and continual improvement into normal business operations.

Phase 9: Build an evidence and documentation system

A company may have appropriate practices but still struggle to demonstrate compliance if decisions and controls are not documented consistently.

Evidence should be created as part of normal workflows rather than reconstructed when a customer, auditor or regulator requests it.

The evidence record may include:

  • AI inventory entries.
  • Role and risk classification decisions.
  • Legal and impact assessments.
  • Approval records.
  • Supplier questionnaires and contracts.
  • Technical and user documentation.
  • Testing and validation results.
  • Human oversight instructions.
  • Training records.
  • Monitoring reports.
  • Incident and complaint records.
  • Corrective actions.
  • Change assessments.
  • Management review records.

Each document should have an owner, approval status, review date and retention period. The company should also control access to sensitive technical, personal and commercial information.

Phase 10: Monitor AI systems throughout their lifecycle

Compliance does not end when an AI system is approved. Performance, data, suppliers, models and business purposes can change after deployment.

Monitoring should examine whether:

  • The system continues to operate as intended.
  • Accuracy remains within approved limits.
  • Users are following the instructions.
  • Human oversight is working in practice.
  • Complaints or incidents indicate a new risk.
  • The supplier has introduced material changes.
  • The system is being used for an additional purpose.
  • The regulatory classification remains correct.
  • Documentation and notices remain accurate.

Material changes should trigger a new assessment. The organisation should define which events require reassessment and who has authority to suspend or restrict the system while concerns are investigated.

10 EU AI Act compliance priorities at a glance

The following priorities provide a practical starting point for organisations preparing for the AI Act.

PriorityWhat the company should doExpected outcome
Establish scopeIdentify AI systems, business purposes, owners, users and suppliersA reliable AI inventory
Determine regulatory rolesAssess whether the company is a provider, deployer, importer or distributorClear responsibility for each system
Classify riskReview prohibited, high risk, transparency and general purpose AI categoriesA documented classification decision
Assign ownershipDefine who approves, operates, monitors and reviews AI systemsClear accountability
Implement controlsIntroduce proportionate legal, technical and operational safeguardsConsistent AI governance
Review suppliersAssess vendor evidence, contracts, documentation and monitoring arrangementsBetter control of third party risk
Maintain evidenceRecord decisions, assessments, approvals, incidents and changesA defensible compliance record
Monitor systemsReview performance, risks, changes and emerging obligationsOngoing compliance

Important AI Act dates for companies

The AI Act is being applied in stages. Organisations should confirm which provisions affect their systems and regulatory roles.

Key dates include:

  • 2 February 2025 for prohibited AI practices, relevant definitions and AI literacy requirements.
  • 2 August 2025 for governance provisions and obligations concerning general purpose AI models.
  • 2 August 2026 for most remaining provisions and transparency obligations.
  • 2 December 2027 for high risk systems covered by Annex III under the revised timetable.
  • 2 August 2028 for high risk AI systems connected to regulated products listed in Annex I.

The European Commission maintains an updated AI Act implementation timeline. Companies should use the official timetable when setting internal deadlines, especially where systems may fall within a high risk category.

How PrivaLex can support AI Act preparation

Preparing for the AI Act can become difficult when legal requirements have to be converted into decisions that procurement, technology, privacy, security and business teams can follow in practice. Companies may know that they need an AI inventory or AI risk assessment, but still be uncertain about what information to collect, who should approve a system and what evidence will satisfy customers, auditors or regulators.

PrivaLex helps organisations establish those practical foundations. The work normally begins with a review of the company’s AI use cases, existing governance processes and available documentation. Workshops with relevant teams can then reveal where AI is being developed, purchased or used, including tools that may not yet appear in a formal software register.

Once the organisation has a clearer picture of its AI portfolio, PrivaLex can help determine the company’s role for each system and assess whether the use case may involve prohibited practices, high risk requirements, transparency duties or general purpose AI obligations. Uncertain cases can be documented and escalated so that the company has a reasoned position rather than relying only on a vendor’s classification.

Support can include:

  • Designing an AI inventory suited to the organisation’s structure and risk profile.
  • Establishing a practical intake process for new AI systems and material changes.
  • Assessing provider, deployer, importer and distributor roles.
  • Reviewing preliminary risk classifications and sensitive use cases.
  • Developing AI policies, approval workflows and responsibility models.
  • Mapping legal requirements to controls, owners and evidence.
  • Coordinating AI assessments with GDPR, security and procurement reviews.
  • Preparing supplier questionnaires and reviewing supporting documentation.
  • Identifying contractual protections needed for AI products and services.
  • Defining human oversight, transparency and monitoring requirements.
  • Developing templates for assessments, approvals, incidents and change reviews.
  • Aligning AI governance with ISO 42001, ISO 27001 and existing management systems.
  • Supporting the selection and implementation of AI governance software.
  • Testing whether the completed programme creates a clear and defensible compliance record.

The approach is designed around the way the company already operates. A smaller organisation may need a focused inventory, approval process and set of essential controls. A larger or more complex business may require several governance layers, regional responsibilities, technical validation procedures and integration with existing risk platforms.

PrivaLex can also help teams decide which work should be performed internally, which evidence must come from suppliers and which issues require independent technical testing or conformity assessment.

PrivaLex is not a notified body and does not replace an independent conformity assessment where the AI Act requires one. Its role is to help the organisation build, document and test the governance system that management and any independent assessor will need to examine.

Companies can learn more about available AI compliance and governance support or request a free risk assessment.

A practical 90 day preparation plan

Companies do not need to solve every compliance question immediately. A focused 90 day programme can establish the foundations and identify the most urgent risks.

Days 1 to 30: Establish visibility

During the first month, appoint an executive sponsor and create a working group involving legal, privacy, security, procurement, technology and relevant business teams.

Define what qualifies as an AI system for internal reporting purposes. Launch the inventory process, review existing software registers and identify systems that may involve prohibited practices or high risk use cases.

Days 31 to 60: Assess and prioritise

Assign a regulatory role and preliminary risk category to each significant system. Review suppliers, existing contracts and available documentation.

Prioritise systems that affect employment, access to services, credit, insurance, education, biometrics or other sensitive decisions. Record uncertainties and assign owners to resolve them.

Days 61 to 90: Implement the operating model

Approve an AI policy, intake process and responsibility model. Introduce assessment templates, evidence requirements and escalation criteria.

Select several significant systems for pilot assessments. Use the results to test whether the governance process is practical before applying it more widely.

Senior management should then review the findings, confirm priorities and approve a longer implementation plan.

Questions to test your company’s readiness

A company should be able to answer the following questions clearly:

  • Do we know where AI is currently being used?
  • Does every significant AI system have a business owner?
  • Have we determined our regulatory role for each system?
  • Can we explain and evidence each risk classification?
  • Do new AI purchases require review before approval?
  • Have high risk or prohibited use cases been escalated?
  • Can we obtain sufficient evidence from our suppliers?
  • Are human reviewers trained and able to intervene?
  • Are AI assessments connected with privacy and security reviews?
  • Do we monitor systems after deployment?
  • Can we retrieve compliance evidence without reconstructing it?
  • Does senior management receive meaningful information about AI risk?

If several answers are unclear, the organisation should prioritise visibility, ownership and classification before investing in extensive policies or software.

Conclusion

Preparing for EU AI Act compliance requires more than identifying a legal deadline. Companies need a reliable inventory, a system specific assessment of regulatory roles and risks, clear ownership, proportionate controls and an evidence trail that remains accurate as technology and business use change.

The most effective programmes begin with the organisation’s actual AI portfolio and build governance around the way systems are developed, purchased and operated. Existing privacy, security, procurement and risk processes should be reused wherever possible, while gaps specific to AI should be addressed through focused controls.

Starting early gives the organisation time to correct weak supplier arrangements, test human oversight, improve documentation and integrate compliance into ordinary business decisions. Companies that need to identify their most immediate gaps can begin with the AI Act readiness scorecard.

A structured preparation programme does more than reduce regulatory exposure. It gives management better visibility over how AI is being used, helps teams identify unsuitable systems before deployment and creates clearer accountability for decisions that affect employees, customers and other individuals.

Organisations that would like support turning these requirements into a practical implementation plan can book a working session.

Frequently Asked Questions (FAQs) 

The obligations depend on the company’s activities, location, regulatory role and the types of AI systems involved. A company that uses an AI system in the European Union may have responsibilities even if it did not develop the technology.

The first practical step is to create an inventory of AI systems. The company should then identify the purpose, owner, supplier, affected individuals, regulatory role and preliminary risk classification for each significant system.

Responsibility should be shared across legal, compliance, privacy, security, procurement, technology and business teams. An executive sponsor should provide authority and ensure that unresolved risks receive appropriate attention.

The exact legal requirement depends on the organisation’s role and the systems involved. In practice, an inventory is necessary to determine which obligations apply and to demonstrate that the company has identified and assessed its AI systems.

The two laws apply separately but may overlap. An AI system processing personal data may need to comply with both. A data protection impact assessment does not automatically satisfy AI Act requirements, although some information and controls may be reused.

No. Supplier documentation and contractual commitments are important, but each organisation must assess its own role and use of the system. Deployers may have obligations relating to human oversight, input data, monitoring, records and transparency.

No. ISO 42001 can support governance, responsibility, risk management and continual improvement, but certification does not automatically prove compliance with every AI Act obligation.

Reviews should occur periodically and whenever there is a material change in the system, supplier, data, intended purpose, affected group or deployment environment. Incidents, complaints and unexpected performance should also trigger reassessment.

Free self-assessment
The EU AI Act deadlines are coming. Is your organisation ready?
Download our self-assessment and find out in under 10 minutes whether your organisation meets the requirements before the obligations kick in.
Download Free Self-Assessment