AIResponsible AI

The EU AI Act for non-lawyers: a practical compliance playbook

The EU AI Act is now producing real obligations for companies deploying AI in Europe, and ignorance of the legal text is not a defence your board will accept. This playbook gives you a concrete sequence of steps to assess your exposure, assign ownership, and take action before regulators come looking.

🎙️

Listen to the podcast

4 min

The EU AI Act entered into force in August 2024 and has been phasing in its obligations since then. By August 2026, most of its core provisions apply, including the rules governing high-risk AI systems, the transparency requirements for certain AI interactions, and the outright prohibitions on a handful of practices. Companies that have been watching from the sidelines are now officially late. The question is no longer whether this regulation applies to you. For most organisations using AI in hiring, customer scoring, credit decisions, or internal performance management, it almost certainly does.

The Act works on a tiered logic. The higher the potential harm, the heavier the obligation. That sounds simple, but the classification exercise is where most teams get stuck, because the boundaries between a general-purpose productivity tool and a regulated high-risk system depend on how you deploy it, not just what the vendor labels it.

Your compliance playbook: a step-by-step sequence

Step 1: build your AI inventory

You cannot classify what you have not listed. Spend two to three weeks producing an inventory of every AI system in active use across your organisation. Include vendor-supplied tools (Salesforce Einstein, Workday's recruiting AI, Microsoft Copilot in HR workflows), internally built models, and any third-party API integrations where a model makes or informs a decision about a person.

The inventory should capture four things for each system: what it does, who it affects, what data it processes, and whether a human reviews its output before action is taken.

Step 2: classify each system against the Act's risk tiers

The Act defines four tiers. Prohibited practices include real-time biometric surveillance in public spaces and social scoring by public authorities. High-risk systems cover areas like recruitment screening, creditworthiness assessment, access to essential services, and worker monitoring. Limited-risk systems, such as chatbots, require basic transparency disclosures. Minimal-risk systems face no specific obligations.

For each item in your inventory, map it to the relevant annex. Annex III of the Act lists the high-risk categories explicitly. If your HR platform ranks candidates, that is Annex III territory. If your contact centre uses an AI to route complaints and score customer sentiment, the classification depends on whether the output influences a decision with legal or similarly significant effect. When in doubt, treat it as high-risk and work backwards.

Step 3: assign a system owner for each high-risk tool

Compliance without named accountability does not hold. For every high-risk system, appoint an owner who is responsible for four things: maintaining technical documentation, ensuring human oversight is real (not cosmetic), monitoring for performance drift, and logging incidents. This person does not need to be a lawyer or a data scientist. They need enough authority to pause or modify the system if something goes wrong.

This is also the moment to clarify whether your organisation is a provider (you built the model), a deployer (you put someone else's model to work), or both. The obligations differ. Deployers have fewer documentation burdens but still carry responsibility for the use context, human oversight, and certain transparency requirements.

Step 4: implement the transparency and oversight mechanics

For high-risk systems, the Act requires that affected individuals know an AI system is involved in decisions that significantly affect them. That means updating privacy notices, adding disclosure language in communications, and in some sectors, creating a right to explanation.

Human oversight is the piece most organisations underestimate. Clicking "approve" on an AI recommendation without the capacity to meaningfully challenge it does not satisfy the requirement. Oversight means the reviewer has access to the system's logic, enough context to disagree, and a documented process for escalation. Building this into your workflows takes time, so start with the systems that affect the most people.

Step 5: connect to your existing governance structures

The EU AI Act does not replace GDPR. They run in parallel. A high-risk AI system processing personal data will need both a Data Protection Impact Assessment under GDPR and a conformity assessment under the AI Act. Map those processes together rather than running them separately. Your Data Protection Officer, if you have one, should be in the room when high-risk AI systems are being classified and documented.

Pitfalls that derail compliance efforts

The most common failure is delegating this entirely to legal or IT and treating it as a documentation project. The Act's obligations are operational. If your HR director does not understand why the candidate-ranking tool on their screen is a high-risk system, the paper trail your lawyers produce will not protect you when a rejected applicant challenges the decision.

A second trap is over-relying on vendor assurances. A vendor telling you their tool is "compliant" means their product documentation meets provider-level requirements. It says nothing about whether your specific deployment, in your specific decision context, meets deployer obligations. Ask vendors for their technical documentation and model cards. If they cannot or will not provide them, that is a signal.

Scope creep in the other direction is also real. Teams sometimes classify everything as high-risk out of caution, which produces an unworkable compliance burden and slows down genuinely useful AI adoption. Calibrate carefully. A spell-checker is not a high-risk system. A tool that flags employee performance for a manager to review before any action is taken sits in a different category depending on how consequential that review actually is in practice.

Finally, do not treat this as a one-time exercise. AI systems drift. The model your team deployed eighteen months ago may behave differently today due to retraining, data shifts, or changes in how staff use it. Build a quarterly review into your governance calendar.

Quick wins to start this week

  • Pull a list of every SaaS tool in use across HR, finance, and customer-facing operations, and mark which ones involve automated decision-making or scoring.
  • Download Annex III of the EU AI Act (the official text is free at eur-lex.europa.eu) and cross-reference your list against it.
  • Send a one-page briefing to your HR and operations leads explaining what high-risk classification means and why their tools may be in scope.
  • Schedule a 90-minute working session with legal, IT, and one business unit head to agree on who owns the classification process.
  • Check whether your top three AI vendors have published conformity documentation or model cards, and log any gaps.

The EU AI Act is a durable piece of regulation, not a temporary wave of enforcement attention. Companies that build compliance into their AI deployment process now will spend less time and money on remediation later, and will have documentation that protects them when challenged. Start with your inventory. Everything else follows from knowing what you have.

Finished reading?

Validate your read to earn XP and feed your radar.