Regulation · 12 min read
EU AI Act Readiness: A Practical Roadmap for Regulated Enterprises
The EU AI Act is the world's first comprehensive, horizontal AI regulation. Compliance is not a policy exercise — it is a system-level programme spanning inventory, classification, technical documentation, human oversight, post-market monitoring and evidence.
Why readiness is harder than firms expect
Most enterprises underestimate the Act because they read it as a compliance checklist rather than an operating-model change. The Act introduces obligations that cut across data science, engineering, procurement, legal, risk and product. Provisions on high-risk systems require conformity assessments, quality management systems, logging, human oversight and post-market monitoring — each of which touches multiple functions. Firms that treat readiness as a legal deliverable rather than a cross-functional programme routinely discover, six months in, that they do not have the evidence pipeline, control library or ownership model needed to demonstrate compliance to a regulator.
The five workstreams that actually matter
A defensible readiness programme organises around five workstreams: (1) applicability and inventory — identifying every in-scope AI system, including embedded third-party components and general-purpose AI models fine-tuned or deployed by the firm; (2) risk classification — mapping systems to prohibited, high-risk, limited-risk or minimal-risk categories with a documented rationale; (3) obligation mapping — translating Article-level requirements into concrete controls, artefacts and owners; (4) technical documentation — producing the Annex IV file, data governance evidence, and conformity assessment records; and (5) post-market surveillance — standing up monitoring, incident reporting and serious-incident notification workflows.
General-purpose AI and the deployer trap
Firms using foundation models via API often assume the provider carries the compliance burden. In practice, the moment a firm fine-tunes, prompts or substantially modifies a general-purpose AI model, or deploys it into a high-risk use case, obligations shift onto the deployer. This is the single most common gap we see in readiness assessments: procurement contracts that assume vendor responsibility, without the contractual, technical or governance mechanisms to actually receive and act on the information the deployer needs.
What good evidence looks like
Regulators will not accept assertions. They will ask for logs, sign-offs, test results, model cards, data sheets, human-oversight procedures and change history. The single strongest indicator of readiness maturity is whether a firm can produce, on demand, a coherent evidence pack for any in-scope AI system — showing who approved it, on what basis, against what risk assessment, with what controls, and with what monitoring in place. Firms that can do this are ready. Firms that cannot are exposed, regardless of how sophisticated their policies read on paper.