All guides
EU AI ActAI

EU AI Act Readiness

The walkthrough most teams skip — classifying your systems before the 2026 obligations bite. ~12 min for AI builders & deployers.

5 min read

A builder’s walkthrough of the one regime that now reaches almost every AI product touching the EU — and how to get ahead of the 2026 obligations instead of scrambling at the deadline.

Dossier

For
AI-native startups, SaaS products adding AI features, and US or global teams that need EU market access.
Covers
Applicability · risk-tier classification · gap analysis · prioritised action plan.
Why now
Obligations phase in through 2026; prohibited-use and AI-literacy duties already apply.
Outcome
A documented classification and a plan you can hand to your board, investors, or enterprise buyers.

Does the EU AI Act apply to you?

Start here, because everything else depends on it. The Act can apply even if your company sits entirely outside the EU. If your system is placed on the EU market, or its output is used in the EU, the rules can reach you — much the way GDPR does. A US team serving European users is rarely out of scope by default.

Identify your role. Your obligations differ depending on what you are in the chain for a given system. Most teams hold more than one role across their products:

  • Provider — you develop the system, or have it developed, and put it on the market under your name. This role carries the heaviest obligations.
  • Deployer — you use an AI system in the course of your business (for example, an off-the-shelf model embedded in your workflow).
  • Importer / distributor — you bring a third-party system into the EU market or make it available.

Classify each system by risk tier

This is the step most teams skip, and the one every other obligation flows from. The Act sorts systems into four tiers. Classification is a reasoned, documented judgement — not a label you pick by vibe.

  • Prohibited — uses the Act bans outright (for example, certain social-scoring and manipulative techniques). If anything you build sits here, it needs to change before launch, not after.
  • High-risk — systems used in sensitive areas such as recruitment, credit scoring, biometrics, education, or critical infrastructure. These attract the bulk of the substantive requirements.
  • Limited-risk — systems with transparency duties, such as telling users they’re interacting with AI or labelling generated content.
  • Minimal-risk — most other systems, with light or no specific obligations today.

Map your systems to the timeline

The Act phases in rather than landing all at once, so "when do we need to be ready" has a different answer for each obligation. Prohibited-use rules and AI-literacy duties already apply. Requirements for general-purpose AI and the bulk of high-risk obligations arrive through 2026.

The practical task is to take each system from step 02 and attach the dates that actually bind it. A minimal-risk feature and a high-risk hiring tool are on completely different clocks, and planning runway around a single “deadline” is how teams get caught short.

Run a gap analysis

With roles, tiers, and timelines in hand, compare where your product, processes, and documentation are today against what the applicable tier requires. Gaps usually cluster in three places:

  • Product — data governance, human oversight, accuracy and robustness measures, logging.
  • Process — risk management, post-market monitoring, incident handling, the way decisions get reviewed.
  • Documentation — technical documentation, instructions for use, conformity records, and the evidence that ties it all together.

The output is a concrete list of what’s missing, not a general sense that “we should do more on AI governance.”

Build a prioritised action plan

A gap list isn’t a plan until it’s sequenced. Order the work so the items with deadline or enforcement risk come first, and group the rest into what’s achievable before each phase-in date. Plain-language and prioritised beats exhaustive — a roadmap nobody can act on protects nobody.

Turn it into a report you can hand over. The final artefact is a written report: your systems, their classifications and the reasoning, the gaps, and the sequenced plan to close them. That’s the document your board, your investors, and the enterprise customers running diligence on you will actually ask to see — and the one that turns “we take compliance seriously” into something demonstrable.

Get a readiness assessment

Want it done for you? See our EU AI Act Readiness solution, or try Compass — our AI assistant for EU regulation.

Book a consultation
guideAIEU AI Act

More from the journal

See all

FATF Publishes Targeted Report on DeFi Regulatory Challenges, 21 July 2026

On 21 July 2026, the Financial Action Task Force published its Targeted Report on Regulatory Challenges from Decentralised Finance. The report finds that 93% of surveyed jurisdictions have not implemented FATF Recommendation 15 as it applies to qualifying DeFi arrangements, and only two jurisdictions have licensed or registered a DeFi arrangement. The FATF issues recommendations to jurisdictions and DeFi operators to close identified regulatory gaps and reduce illicit finance risk.

EU Digital Omnibus Regulation 2026/1744 Enters Into Force, Extending AI Act Compliance Timelines

Regulation (EU) 2026/1744 (the AI Digital Omnibus) entered into force on 27 July 2026, amending the EU AI Act to extend compliance timelines for high-risk AI systems. Operators covering Annex III sectors have until 2 December 2027 to meet Chapter III obligations. AI systems embedded in Annex I products have until 2 August 2028. The Omnibus cites CEN and CENELEC standardisation delays as justification for both extensions.

EU AI Act Article 50 Transparency Obligations Apply from 2 August 2026

Article 50 of Regulation (EU) 2024/1689 (the EU AI Act) takes general application on 2 August 2026. Providers of interactive AI systems must notify users they are communicating with an AI and embed machine-readable marks in AI-generated content. Deployers must inform individuals exposed to deep fakes and AI-generated public-interest content published without human review. The European Commission published final implementation guidelines on 20 July 2026.