EU AI Act

EU AI Act compliance software,
run as a workflow.

The obligations are set out in our guide. This is the other half: the order you do them in, who inside the company owns each step, what a conformity assessment actually consumes, and which of it you have already built for SOC 2 without noticing.

01

The unit of work is a system, not a company

This is the first thing that trips teams coming from privacy or security work. GDPR programmes are organised around the organisation. SOC 2 is organised around the organisation. The AI Act is product safety law: every obligation attaches to an individual AI system, and your role can differ from one system to the next. You can be a deployer of four systems and a provider of one, in the same quarter, and owe entirely different things for each.

Which is why an inventory comes before anything else, and why it is usually the longest step. Models arrive embedded in product features, bought as SaaS, wrapped around a foundation model API, and fine-tuned by a team that did not think of it as procurement. A list that says "we use AI in support triage" is not an inventory; a list naming the system, its purpose, its provider, its training data and its outputs is.

02

Six steps, in this order

StepWhat it producesWho owns it
1. InventoryEvery AI system, with purpose, provider, data and outputs namedEngineering, with procurement
2. ClassifyA risk tier per system, and the Annex III reference if high-riskLegal, on engineering's description
3. Assign the roleProvider, deployer, importer or distributor: per systemLegal. Fine-tuning for a new purpose usually makes you a provider
4. Design oversightHuman oversight that a person can actually exercise, plus Article 50 disclosuresProduct
5. Evidence the controlsRisk management, data governance, logging, robustness: operating, not describedSecurity and engineering
6. Assemble and monitorAnnex IV documentation, conformity assessment, registration, post-market monitoringWhoever owns release

Steps 1 and 2 gate everything after them. Teams that start at step 5 because it looks like familiar work produce evidence for systems they have not classified.

03

What you have already built

The reusable fraction is larger than it looks, and knowing which fraction changes the size of the project considerably.

  • Already yours if you hold SOC 2 or ISO 27001. Access control, change management, incident response, vendor management, and much of Article 15 robustness and cybersecurity
  • Already yours if you run a privacy programme. Data inventory, lawful basis and retention for the personal data inside training sets, though the Act asks separate questions about relevance and bias
  • Genuinely new. Risk classification, Annex IV documentation, human oversight design, post-market monitoring, serious-incident reporting, and registration

On a shared control set the first column costs nothing to reuse: the control result that satisfies SOC 2 CC7.2 is the same result an AI Act logging requirement reads. That reuse is the whole argument of coverage, and it is why the second framework is cheaper than the first.

04

Where this runs in the platform

The AI governance engine holds the system register, the risk classification and the evaluation records, and writes results into the same evidence ledger as everything else. What that buys you concretely: documentation generated from live state rather than maintained by hand, so a substantial modification updates the record rather than silently invalidating it, and one control result reaching the AI Act, ISO 42001 and your existing security framework at once.

ISO 42001 is worth reading about separately, because a certificate is frequently mistaken for a conformity assessment: what certification covers and what it does not.

Questions

The things people ask us

Where does EU AI Act work actually start?

With an inventory, not with a policy. You cannot classify systems you have not listed, and in most companies nobody holds a complete list: models are embedded in product features, bought as SaaS, and fine-tuned by individual teams. Expect the inventory to take longer than the classification that follows it.

Who inside the company should own this?

It splits three ways and fails when it is given to one function. Engineering owns the system inventory, logging and technical documentation; legal owns risk classification and the provider-versus-deployer determination; product owns human oversight design and the transparency disclosures. Security owns the Article 15 robustness and cybersecurity requirements, which are largely controls you already run.

How long does a conformity assessment take?

The assessment itself is short. Assembling what it consumes is not: Annex IV technical documentation, evidence that the risk management system has been operating rather than merely documented, data governance records for training and test sets, and logs. Teams that start three months out are assembling evidence retrospectively, which is visible in the dates.

Do we need to redo this for every model release?

No, but substantial modification restarts parts of it, and the definition is broader than teams expect. A change to intended purpose almost always counts. Retraining on materially different data often does. This is why the documentation has to be generated from live state rather than written once.

What does this share with work we have already done?

More than most teams assume. Access control, logging, incident response, vendor management and change management are already in your SOC 2 or ISO 27001 programme and are directly reusable for Articles 12, 15 and 17. The genuinely new work is risk classification, Annex IV documentation, human oversight design and post-market monitoring.

Is this page the law?

No. This is the operating procedure. The obligations themselves, the four risk tiers and the timeline as amended by the Digital Omnibus are set out in the EU AI Act guide, and the fine tiers in the penalties page.

Book a walkthrough

See a model classified and evidenced.

We register a real system, classify it, attach the controls that treat it, and show the documentation assembling itself from live state. Thirty minutes.