Skip to content
Lucas BarriosApplied AI & Operational Transformation

European Enterprise Client · DACH Region

EU AI Act Compliance Assessment

A structured regulatory advisory engagement mapping an enterprise AI system portfolio against EU AI Act risk tiers, compliance obligations, and a phased remediation program.

Context

The EU AI Act entered into force in August 2024, with phased implementation obligations running through 2027. For a DACH-region enterprise with 23 active AI deployments across five business units, the immediate question was not whether compliance was required — it was which systems were in scope and what each classification meant operationally.

Leadership needed a clear, defensible view of their AI portfolio before external regulatory scrutiny intensified and before procurement partners began requiring AI Act compliance documentation.

Problem

The organization underestimated the breadth of the Act's reach. Several systems assumed to be low-risk fell into Annex III high-risk categories once sector, affected user groups, and decision autonomy were properly assessed.

  • No consistent definition of what constituted an AI system under the Act across business units.
  • Provider versus deployer obligations were misunderstood — the client was a deployer for several third-party systems but had assumed compliance responsibility sat with vendors.
  • No governance structure owned the classification and remediation program across business units.

Workflow

The engagement followed three phases: system inventory and profile collection, risk tier classification against EU AI Act criteria, and obligations mapping with a phased remediation roadmap.

Each AI system was characterized by its purpose, affected user groups, sector context, decision autonomy, and reversibility — the minimum profile needed to apply the Act's classification criteria consistently.

  • Structured system inventory across five business units.
  • Deterministic risk tier assignment using EU AI Act Article 5, Annex III, and Article 50 criteria.
  • Per-system compliance checklist with article references and named compliance owners.

01

23 systems catalogued

System inventory

Each AI deployment was catalogued with purpose, affected user groups, sector, decision mode, and deployment role — capturing the minimum profile needed for consistent risk classification.

02

4-tier mapping

Risk tier classification

Systems were mapped against EU AI Act criteria: prohibited under Article 5, high-risk under Annex III, transparency obligations under Article 50, or minimal risk.

03

Per-system checklist

Obligations mapping

Each high-risk and limited-risk system received a per-system compliance checklist with article references, named owners, and required evidence.

04

18-month roadmap

Remediation sequencing

Compliance actions were prioritized by obligation urgency, implementation complexity, and business unit capacity into a phased 18-month program.

Architecture

The compliance architecture treated each AI system as a governed asset: classified by risk tier, assigned a compliance owner, tracked against mandatory obligations, and scheduled for periodic review as systems evolve and regulatory guidance develops.

The architecture separated the classification layer from the obligations tracker, allowing risk tiers to be updated independently as system configurations changed without requiring a full reassessment.

System registry

A single source of truth for all AI deployments, capturing purpose, deployment role, affected groups, and classification status with version history.

  • System owner
  • Deployment context
  • Affected groups

Classification layer

Deterministic risk tier assignment based on EU AI Act criteria, with documented rationale, regulatory article references, and flagged triggers for each system.

  • Risk tier assignment
  • Trigger documentation
  • Article references

Obligations tracker

Per-system compliance requirements organized by obligation type, with status, named owner, and deadline — updated as implementation progresses.

  • Checklist by system
  • Owner assignment
  • Evidence status

Governance

Governance was structured around the distinction the Act draws between providers and deployers. For most third-party AI tools, the client was a deployer — which carries different but significant obligations under Article 25.

  • Each high-risk system was assigned a named compliance owner responsible for technical documentation, monitoring, and incident reporting.
  • A quarterly review cadence was established to update classifications as systems changed and EU Commission guidance developed.
  • Systems flagged for possible unacceptable risk received immediate escalation outside the standard compliance program.

Metrics

The assessment produced a clear portfolio view: 23 systems classified, 7 confirmed high-risk, 4 with limited-risk transparency obligations, and 12 classified as minimal risk.

The 7 high-risk systems required conformity assessments, Annex IV technical documentation, human oversight protocols, and EU database registration — forming the core of the 18-month compliance program.

AI systems assessed
23

Active deployments mapped against EU AI Act risk tiers and obligation categories.

High-risk systems
7

Systems requiring conformity assessment, technical documentation, and EU database registration.

Compliance program
18 months

Phased remediation horizon from risk classification to full regulatory compliance.

Roadmap

The remediation roadmap sequenced compliance work by obligation urgency, implementation complexity, and business unit capacity.

0–3 months

Inventory and classification

Complete system inventory across all business units, finalize risk tier classifications with documented rationale, assign compliance owners to all high-risk systems.

3–9 months

Documentation and oversight

Prepare Annex IV technical documentation for high-risk systems, design human oversight protocols, conduct data governance review, establish incident reporting procedures.

9–18 months

Conformity and registration

Complete conformity assessments for high-risk systems, register in EU AI Act database, deploy post-market monitoring, and implement transparency measures for limited-risk systems.

Reflection

The most valuable output was not the classification list. It was the operating clarity it created: which teams needed to act, which systems required immediate attention, and what evidence each compliance program needed to produce.

EU AI Act compliance proved to be an organizational question before a technical one. The systems carrying the most regulatory risk were not the most technically complex — they were the systems deployed closest to high-stakes decisions about people.

Risk Classifier

The assessment methodology used in this engagement is reproduced here as a working tool. Enter an AI system profile to receive an instant EU AI Act risk classification, per-tier obligations checklist, and a five-question compliance readiness score — the same classification logic applied across the 23 systems in the engagement.

Interactive tool · Deterministic

EU AI Act Risk Classifier

Enter your AI system profile to receive an instant risk classification under the EU AI Act, a compliance obligations checklist, and a readiness gap score. All analysis runs locally — no data is transmitted.

Who does it affect?

Select all that apply.

Does it make autonomous decisions?

Can decisions be appealed or reversed?

Technical depth

System assumptions and operating controls.

Architecture diagram

The compliance architecture treats each AI system as a governed asset with a documented risk tier, named owner, per-system obligations checklist, and scheduled review cadence — separate from the organization's general IT governance.

  1. 01

    System inventory

    AI deployments are catalogued with purpose, sector, affected groups, decision mode, deployment role, and vendor information.

  2. 02

    Classification engine

    Each system is mapped against Article 5 (prohibited), Annex III (high-risk), and Article 50 (transparency) criteria to assign a risk tier and document the primary regulatory trigger.

  3. 03

    Obligations tracker

    Each classified system receives a per-system compliance checklist with article references, current status, named owner, and required evidence.

  4. 04

    Review and escalation

    A quarterly governance cadence updates classifications as systems change, with escalation paths for prohibited category findings and material system changes.

Process reasoning steps

  1. Step 1

    Inventory

    Collect system profile: name, purpose, sector, affected groups, decision mode, reversibility, and deployment role.

  2. Step 2

    Classify

    Apply EU AI Act criteria to assign risk tier and identify the primary regulatory trigger and applicable articles.

  3. Step 3

    Map obligations

    Generate a per-system compliance checklist aligned to the classification, with article references and evidence requirements.

  4. Step 4

    Sequence

    Prioritize compliance actions by obligation urgency, implementation complexity, and business unit capacity into a phased program.

System component reference

Tool

System profiler

Purpose

Structure the system inventory with consistent classification fields.

Input

System owner interviews, technical documentation, vendor contracts

Output

Standardized system profile

Guardrail

System owner validates profile before classification.

Tool

Classification engine

Purpose

Apply EU AI Act criteria to assign risk tier with documented rationale.

Input

Standardized system profile

Output

Risk tier, primary trigger, and article references

Guardrail

Legal counsel reviews all high-risk and unacceptable risk findings.

Tool

Obligations mapper

Purpose

Generate per-system compliance checklist with status tracking.

Input

Risk tier and system profile

Output

Per-system compliance checklist

Guardrail

Named compliance owner reviews and accepts obligations.

Knowledge source assumptions

EU AI Act regulatory text

Legal counsel

EU AI Act final text (July 2024) and EU Commission guidance are used as the authoritative classification reference.

System documentation

System owner

Technical documentation and system descriptions are current and complete enough to support accurate profile collection.

Deployment context

Business owner

Information about affected user groups, decision workflows, and deployment scope is available from system and business owners.

Evaluation metrics

Classification defensibility

100% of classifications documented with regulatory article reference

Audit all system classifications for documented trigger and regulatory basis.

Inventory completeness

95% of active AI systems in scope

Cross-reference system inventory against IT asset register and vendor contracts.

High-risk coverage

100% of high-risk systems with named owner and remediation plan

Verify compliance owner assignment and phased action plan for all Annex III systems.

Risk and failure scenarios

Inventory gaps

Shadow AI deployments or undocumented third-party tools miss compliance obligations and create unmanaged regulatory exposure.

Cross-reference system inventory against procurement records, vendor contracts, and IT access logs.

Provider vs. deployer confusion

Organizations acting as deployers under Article 25 underestimate their obligations, assuming compliance responsibility sits with the vendor.

Map each system against the provider/deployer distinction and document deployer obligations explicitly.

Static classification

Risk tiers change as systems evolve. Without a review cadence, an initially minimal-risk system can grow into a high-risk deployment without triggering compliance action.

Establish a quarterly review trigger for any material system change, scope extension, or new affected user group.

Human review checkpoints

System profile validation

System owner

Confirm purpose, affected groups, and deployment context before classification is finalized.

Risk tier sign-off

AI program office and legal counsel

Confirm risk tier assignment and required compliance obligations for high-risk and prohibited category findings.

Quarterly review

Compliance owner

Update classifications and obligations as systems change and EU Commission guidance develops.

Next step

Review the supporting profile.

Use CV access and LinkedIn for background, or return to selected work for more examples of structured AI thinking.