EU AI Act readiness
The EU AI Act is risk-tiered, so readiness starts with honest classification and ends with evidenced obligations. This guide takes a system from “we think the Act applies” to a defensible readiness position.
When to use this
Section titled “When to use this”You need to demonstrate readiness for the EU AI Act for a specific system, or to triage which of your systems the Act touches and how heavily.
What you will produce
Section titled “What you will produce”A system classified into the correct EU AI Act risk category, with the applicable obligations identified and evidenced, and a readiness report.
- Register and ground the system. Capture it in AI System Records and run intake, the intake signals (automated decisions, public-facing, personal and special-category data, sector) drive classification.
- Route against the Act. Use the EU AI Act framework to establish scope, Article 5 status, high-risk classification, Article 50 behaviours, GPAI position and other independently applicable routes. These are not one mutually exclusive risk-class selector.
- Identify every role. Provider, deployer, product manufacturer, importer, distributor, authorised-representative and GPAI roles can create different duties. Determine roles from the facts rather than the contract label.
- Assess the atomic obligations. Work every routed item, recording the legal answer separately from its assurance depth and non-applicability governance.
- Evidence them. Through the Evidence Tracker and Testing Centre, capture the evidence each obligation needs: risk management, data governance, transparency, human oversight, accuracy and robustness, and record-keeping.
- Add depth where it matters. For high-risk systems, pair the Act with GTSAF for control depth and ISO/IEC 42005 for an impact assessment.
- Track and report. Work gaps on the Remediation Roadmap and produce a readiness workpaper pack.
Evidence and conclusion checklist
Section titled “Evidence and conclusion checklist”- Legal snapshot, territorial nexus, system boundary and relevant dates.
- Every economic-operator role and independently applicable route.
- Article 5 screen, high-risk route, transparency route and GPAI route considered separately.
- Evidence linked to the correct obligation, system version and assessment period.
- Current law separated from voluntary or future readiness.
- Named legal/compliance reviewer, limitations and reassessment triggers.
Record compliance conclusion, evidence assurance and readiness work separately. A high completion percentage does not by itself establish legal compliance.
Modules and frameworks involved
Section titled “Modules and frameworks involved”intake & risk tiering, EU AI Act, GTSAF, ISO/IEC 42005, evidence & findings and reporting.
- Govern a GenAI chatbot: a common limited-risk case.
- Board assurance pack: roll readiness up for leadership.
- Scenario guides: the full set.