Context
The EU AI Act entered into force in August 2024, with phased implementation obligations running through 2027. For a DACH-region enterprise with 23 active AI deployments across five business units, the immediate question was not whether compliance was required — it was which systems were in scope and what each classification meant operationally.
Leadership needed a clear, defensible view of their AI portfolio before external regulatory scrutiny intensified and before procurement partners began requiring AI Act compliance documentation.
Problem
The organization underestimated the breadth of the Act's reach. Several systems assumed to be low-risk fell into Annex III high-risk categories once sector, affected user groups, and decision autonomy were properly assessed.
- No consistent definition of what constituted an AI system under the Act across business units.
- Provider versus deployer obligations were misunderstood — the client was a deployer for several third-party systems but had assumed compliance responsibility sat with vendors.
- No governance structure owned the classification and remediation program across business units.
Workflow
The engagement followed three phases: system inventory and profile collection, risk tier classification against EU AI Act criteria, and obligations mapping with a phased remediation roadmap.
Each AI system was characterized by its purpose, affected user groups, sector context, decision autonomy, and reversibility — the minimum profile needed to apply the Act's classification criteria consistently.
- Structured system inventory across five business units.
- Deterministic risk tier assignment using EU AI Act Article 5, Annex III, and Article 50 criteria.
- Per-system compliance checklist with article references and named compliance owners.
01
23 systems catalogued
System inventory
Each AI deployment was catalogued with purpose, affected user groups, sector, decision mode, and deployment role — capturing the minimum profile needed for consistent risk classification.
02
4-tier mapping
Risk tier classification
Systems were mapped against EU AI Act criteria: prohibited under Article 5, high-risk under Annex III, transparency obligations under Article 50, or minimal risk.
03
Per-system checklist
Obligations mapping
Each high-risk and limited-risk system received a per-system compliance checklist with article references, named owners, and required evidence.
04
18-month roadmap
Remediation sequencing
Compliance actions were prioritized by obligation urgency, implementation complexity, and business unit capacity into a phased 18-month program.
Architecture
The compliance architecture treated each AI system as a governed asset: classified by risk tier, assigned a compliance owner, tracked against mandatory obligations, and scheduled for periodic review as systems evolve and regulatory guidance develops.
The architecture separated the classification layer from the obligations tracker, allowing risk tiers to be updated independently as system configurations changed without requiring a full reassessment.
System registry
A single source of truth for all AI deployments, capturing purpose, deployment role, affected groups, and classification status with version history.
- System owner
- Deployment context
- Affected groups
Classification layer
Deterministic risk tier assignment based on EU AI Act criteria, with documented rationale, regulatory article references, and flagged triggers for each system.
- Risk tier assignment
- Trigger documentation
- Article references
Obligations tracker
Per-system compliance requirements organized by obligation type, with status, named owner, and deadline — updated as implementation progresses.
- Checklist by system
- Owner assignment
- Evidence status
Governance
Governance was structured around the distinction the Act draws between providers and deployers. For most third-party AI tools, the client was a deployer — which carries different but significant obligations under Article 25.
- Each high-risk system was assigned a named compliance owner responsible for technical documentation, monitoring, and incident reporting.
- A quarterly review cadence was established to update classifications as systems changed and EU Commission guidance developed.
- Systems flagged for possible unacceptable risk received immediate escalation outside the standard compliance program.
Metrics
The assessment produced a clear portfolio view: 23 systems classified, 7 confirmed high-risk, 4 with limited-risk transparency obligations, and 12 classified as minimal risk.
The 7 high-risk systems required conformity assessments, Annex IV technical documentation, human oversight protocols, and EU database registration — forming the core of the 18-month compliance program.
- AI systems assessed
- 23
- High-risk systems
- 7
- Compliance program
- 18 months
Active deployments mapped against EU AI Act risk tiers and obligation categories.
Systems requiring conformity assessment, technical documentation, and EU database registration.
Phased remediation horizon from risk classification to full regulatory compliance.
Roadmap
The remediation roadmap sequenced compliance work by obligation urgency, implementation complexity, and business unit capacity.
0–3 months
Inventory and classification
Complete system inventory across all business units, finalize risk tier classifications with documented rationale, assign compliance owners to all high-risk systems.
3–9 months
Documentation and oversight
Prepare Annex IV technical documentation for high-risk systems, design human oversight protocols, conduct data governance review, establish incident reporting procedures.
9–18 months
Conformity and registration
Complete conformity assessments for high-risk systems, register in EU AI Act database, deploy post-market monitoring, and implement transparency measures for limited-risk systems.
Reflection
The most valuable output was not the classification list. It was the operating clarity it created: which teams needed to act, which systems required immediate attention, and what evidence each compliance program needed to produce.
EU AI Act compliance proved to be an organizational question before a technical one. The systems carrying the most regulatory risk were not the most technically complex — they were the systems deployed closest to high-stakes decisions about people.
Risk Classifier
The assessment methodology used in this engagement is reproduced here as a working tool. Enter an AI system profile to receive an instant EU AI Act risk classification, per-tier obligations checklist, and a five-question compliance readiness score — the same classification logic applied across the 23 systems in the engagement.
Interactive tool · Deterministic
EU AI Act Risk Classifier
Enter your AI system profile to receive an instant risk classification under the EU AI Act, a compliance obligations checklist, and a readiness gap score. All analysis runs locally — no data is transmitted.
Who does it affect?
Select all that apply.
Does it make autonomous decisions?
Can decisions be appealed or reversed?
Technical depth
System assumptions and operating controls.
Architecture diagram
The compliance architecture treats each AI system as a governed asset with a documented risk tier, named owner, per-system obligations checklist, and scheduled review cadence — separate from the organization's general IT governance.
01
System inventory
AI deployments are catalogued with purpose, sector, affected groups, decision mode, deployment role, and vendor information.
02
Classification engine
Each system is mapped against Article 5 (prohibited), Annex III (high-risk), and Article 50 (transparency) criteria to assign a risk tier and document the primary regulatory trigger.
03
Obligations tracker
Each classified system receives a per-system compliance checklist with article references, current status, named owner, and required evidence.
04
Review and escalation
A quarterly governance cadence updates classifications as systems change, with escalation paths for prohibited category findings and material system changes.
Process reasoning steps
Step 1
Inventory
Collect system profile: name, purpose, sector, affected groups, decision mode, reversibility, and deployment role.
Step 2
Classify
Apply EU AI Act criteria to assign risk tier and identify the primary regulatory trigger and applicable articles.
Step 3
Map obligations
Generate a per-system compliance checklist aligned to the classification, with article references and evidence requirements.
Step 4
Sequence
Prioritize compliance actions by obligation urgency, implementation complexity, and business unit capacity into a phased program.
System component reference
Tool
System profiler
Purpose
Structure the system inventory with consistent classification fields.
Input
System owner interviews, technical documentation, vendor contracts
Output
Standardized system profile
Guardrail
System owner validates profile before classification.
Tool
Classification engine
Purpose
Apply EU AI Act criteria to assign risk tier with documented rationale.
Input
Standardized system profile
Output
Risk tier, primary trigger, and article references
Guardrail
Legal counsel reviews all high-risk and unacceptable risk findings.
Tool
Obligations mapper
Purpose
Generate per-system compliance checklist with status tracking.
Input
Risk tier and system profile
Output
Per-system compliance checklist
Guardrail
Named compliance owner reviews and accepts obligations.
Knowledge source assumptions
EU AI Act regulatory text
Legal counsel
EU AI Act final text (July 2024) and EU Commission guidance are used as the authoritative classification reference.
System documentation
System owner
Technical documentation and system descriptions are current and complete enough to support accurate profile collection.
Deployment context
Business owner
Information about affected user groups, decision workflows, and deployment scope is available from system and business owners.
Evaluation metrics
Classification defensibility
100% of classifications documented with regulatory article reference
Audit all system classifications for documented trigger and regulatory basis.
Inventory completeness
95% of active AI systems in scope
Cross-reference system inventory against IT asset register and vendor contracts.
High-risk coverage
100% of high-risk systems with named owner and remediation plan
Verify compliance owner assignment and phased action plan for all Annex III systems.
Risk and failure scenarios
Inventory gaps
Shadow AI deployments or undocumented third-party tools miss compliance obligations and create unmanaged regulatory exposure.
Cross-reference system inventory against procurement records, vendor contracts, and IT access logs.
Provider vs. deployer confusion
Organizations acting as deployers under Article 25 underestimate their obligations, assuming compliance responsibility sits with the vendor.
Map each system against the provider/deployer distinction and document deployer obligations explicitly.
Static classification
Risk tiers change as systems evolve. Without a review cadence, an initially minimal-risk system can grow into a high-risk deployment without triggering compliance action.
Establish a quarterly review trigger for any material system change, scope extension, or new affected user group.
Human review checkpoints
System profile validation
System owner
Confirm purpose, affected groups, and deployment context before classification is finalized.
Risk tier sign-off
AI program office and legal counsel
Confirm risk tier assignment and required compliance obligations for high-risk and prohibited category findings.
Quarterly review
Compliance owner
Update classifications and obligations as systems change and EU Commission guidance develops.