All resources
Playbook 10 min read

An EU AI Act readiness playbook: seven steps to a defensible programme

C1The Compliance One team26 August 2026

Teams stall on the EU AI Act for one reason: they try to read the whole regulation before doing anything. Don't. Work it as a sequence — classify first, then build only what your classification demands. Here's the order that works.

The seven steps

  • 1. Inventory every AI system and GPAI model you build, buy, embed or deploy — one register, with an owner for each.
  • 2. Classify each one: your role (provider/deployer/importer/distributor) and its risk tier. This determines everything downstream.
  • 3. Screen for the prohibited practices (Art. 5) and stop anything that lands there.
  • 4. For high-risk systems, build the Article 9–15 requirements: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity.
  • 5. Run the conformity assessment (Art. 43), draw up the EU Declaration of Conformity, CE-mark the system and register it in the EU database.
  • 6. Deploy with human oversight and a post-market monitoring plan; complete a Fundamental Rights Impact Assessment where required.
  • 7. Report serious incidents on time (Art. 73) and review continually — the file is living, not a one-off.

Where the time actually goes

Steps 1–3 are quick if you're organised and slow if you're not — the whole programme hinges on an accurate, classified inventory. Step 4 is the bulk of the effort for providers of high-risk systems; steps 5–7 are process and paperwork that recur. The trap is doing step 4's documents by hand, from scratch, for each system.

How the platform compresses it

Compliance One does the classification-driven filtering for you: tag a system's role and tier, and it surfaces only the obligations that apply, with the mandatory documents pre-filled and ready to tailor. Obligations that need your lawyer's judgement sit in a separate review queue with a clear disclaimer — you promote them into your Statement of Applicability once confirmed, so nothing unreviewed is presented as done. And because it cross-maps to ISO 42001 and 27001, evidence you already have carries straight over.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map this to your environment.