EU AI Act compliance software,
run as a workflow.
The obligations are set out in our guide. This is the other half: the order you do them in, who inside the company owns each step, what a conformity assessment actually consumes, and which of it you have already built for SOC 2 without noticing.
The unit of work is a system, not a company
This is the first thing that trips teams coming from privacy or security work. GDPR programmes are organised around the organisation. SOC 2 is organised around the organisation. The AI Act is product safety law: every obligation attaches to an individual AI system, and your role can differ from one system to the next. You can be a deployer of four systems and a provider of one, in the same quarter, and owe entirely different things for each.
Which is why an inventory comes before anything else, and why it is usually the longest step. Models arrive embedded in product features, bought as SaaS, wrapped around a foundation model API, and fine-tuned by a team that did not think of it as procurement. A list that says "we use AI in support triage" is not an inventory; a list naming the system, its purpose, its provider, its training data and its outputs is.
Six steps, in this order
| Step | What it produces | Who owns it |
|---|---|---|
| 1. Inventory | Every AI system, with purpose, provider, data and outputs named | Engineering, with procurement |
| 2. Classify | A risk tier per system, and the Annex III reference if high-risk | Legal, on engineering's description |
| 3. Assign the role | Provider, deployer, importer or distributor: per system | Legal. Fine-tuning for a new purpose usually makes you a provider |
| 4. Design oversight | Human oversight that a person can actually exercise, plus Article 50 disclosures | Product |
| 5. Evidence the controls | Risk management, data governance, logging, robustness: operating, not described | Security and engineering |
| 6. Assemble and monitor | Annex IV documentation, conformity assessment, registration, post-market monitoring | Whoever owns release |
Steps 1 and 2 gate everything after them. Teams that start at step 5 because it looks like familiar work produce evidence for systems they have not classified.
What you have already built
The reusable fraction is larger than it looks, and knowing which fraction changes the size of the project considerably.
- Already yours if you hold SOC 2 or ISO 27001. Access control, change management, incident response, vendor management, and much of Article 15 robustness and cybersecurity
- Already yours if you run a privacy programme. Data inventory, lawful basis and retention for the personal data inside training sets, though the Act asks separate questions about relevance and bias
- Genuinely new. Risk classification, Annex IV documentation, human oversight design, post-market monitoring, serious-incident reporting, and registration
On a shared control set the first column costs nothing to reuse: the control result that satisfies SOC 2 CC7.2 is the same result an AI Act logging requirement reads. That reuse is the whole argument of coverage, and it is why the second framework is cheaper than the first.
Where this runs in the platform
The AI governance engine holds the system register, the risk classification and the evaluation records, and writes results into the same evidence ledger as everything else. What that buys you concretely: documentation generated from live state rather than maintained by hand, so a substantial modification updates the record rather than silently invalidating it, and one control result reaching the AI Act, ISO 42001 and your existing security framework at once.
ISO 42001 is worth reading about separately, because a certificate is frequently mistaken for a conformity assessment: what certification covers and what it does not.
The things people ask us
Where does EU AI Act work actually start?
With an inventory, not with a policy. You cannot classify systems you have not listed, and in most companies nobody holds a complete list: models are embedded in product features, bought as SaaS, and fine-tuned by individual teams. Expect the inventory to take longer than the classification that follows it.
Who inside the company should own this?
It splits three ways and fails when it is given to one function. Engineering owns the system inventory, logging and technical documentation; legal owns risk classification and the provider-versus-deployer determination; product owns human oversight design and the transparency disclosures. Security owns the Article 15 robustness and cybersecurity requirements, which are largely controls you already run.
How long does a conformity assessment take?
The assessment itself is short. Assembling what it consumes is not: Annex IV technical documentation, evidence that the risk management system has been operating rather than merely documented, data governance records for training and test sets, and logs. Teams that start three months out are assembling evidence retrospectively, which is visible in the dates.
Do we need to redo this for every model release?
No, but substantial modification restarts parts of it, and the definition is broader than teams expect. A change to intended purpose almost always counts. Retraining on materially different data often does. This is why the documentation has to be generated from live state rather than written once.
What does this share with work we have already done?
More than most teams assume. Access control, logging, incident response, vendor management and change management are already in your SOC 2 or ISO 27001 programme and are directly reusable for Articles 12, 15 and 17. The genuinely new work is risk classification, Annex IV documentation, human oversight design and post-market monitoring.
Is this page the law?
No. This is the operating procedure. The obligations themselves, the four risk tiers and the timeline as amended by the Digital Omnibus are set out in the EU AI Act guide, and the fine tiers in the penalties page.
See a model classified and evidenced.
We register a real system, classify it, attach the controls that treat it, and show the documentation assembling itself from live state. Thirty minutes.