AI Act readiness & insights

Understand the timeline. Build the capability. Keep the evidence.

AI Act readiness is not a single deadline. It is an ongoing program of system classification, security controls, accountability, and evidence that evolves with the systems you deploy.

Timeline last reviewed: August 2026 · verify with counsel before reliance

What matters now

Use the current legal timeline to plan—not to create false urgency.

The following is a practical orientation for leadership teams. Applicability depends on your role, jurisdiction, system type, and use case; obtain legal advice for your specific circumstances.

Already applicable · February 2025

Prohibited practices and AI literacy

Ensure the organization understands which practices are prohibited and that people operating AI systems have appropriate knowledge and awareness.

Already applicable · August 2025

Governance and GPAI obligations

Governance rules and obligations for general-purpose AI models entered into application.

Upcoming · 2 December 2027

Certain high-risk AI systems

High-risk systems in sensitive areas—such as biometrics, critical infrastructure, education, employment, migration, and border control—have this stated application date in current Commission guidance.

Upcoming · 2 August 2028

AI embedded in regulated products

High-risk AI embedded in products such as machinery, lifts, toys, and medical devices follows a later timeline.

Readiness questions

Three questions that reveal where work needs to start.

Inventory

Can you name every AI system in scope?

Include models, agents, vendor tools, internal uses, data sources, owners, decision rights, and where systems are deployed.

Accountability

Can you show who approves and monitors each use case?

Define human owners, risk acceptance, approval gates, escalation paths, and how you challenge or change system behavior.

Evidence

Can you demonstrate the controls in operation?

Policies are not enough. Build usable technical and governance evidence from design through deployment and monitoring.

Practical insight library

Decision-ready guidance you can act on today.

Concise, practical briefs designed to help leaders and delivery teams have a better first conversation. They are not substitutes for legal or technical review.

Decision guide

Is your AI system “high-risk”? A 5-step decision guide.

Work through the questions in order. If you answer yes at a step, treat the system as in scope for closer review until counsel confirms otherwise.

  1. Prohibited? Does the system use a prohibited practice (e.g. manipulative techniques, social scoring, untargeted scraping of facial images)? If yes, it is not permitted—stop and escalate.
  2. Safety component of a regulated product? Is the AI a safety component of, or itself, a product covered by EU harmonization law (machinery, medical devices, toys, lifts)? If yes, likely high-risk.
  3. Listed high-risk use case? Does the use fall in a sensitive area—biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice? If yes, likely high-risk.
  4. Profiling or significant effect? Even within those areas, does it profile people or materially affect rights, access, or outcomes? If yes, do not rely on the narrow exemption without documented justification.
  5. Provider or deployer? Confirm your role. Obligations and evidence differ for providers versus deployers of the same system.

Outcome: a defensible first-pass classification per system, ready for legal confirmation. Get help classifying

Checklist

AI security assessment checklist.

The control domains a credible AI security assessment should cover—beyond the model itself.

  • Inventory: models, agents, vendor tools, data sources, owners
  • Threat model: LLM, RAG, and agentic workflow abuse paths
  • Identity & access: least privilege for humans, services, and agents
  • Secrets & keys: storage, rotation, and scope of tool credentials
  • Data governance: training/inference data, retention, and residency
  • Supply chain: model, library, and plugin provenance
  • Guardrails: input/output filtering, approval gates, rate limits
  • Monitoring: logging, tracing tool calls, anomaly detection
  • Response: rollback, kill-switch, and incident runbooks
  • Evidence: reviewable artifacts mapped to obligations

Outcome: a shared baseline for scoping an assessment. Scope an assessment

AI system inventory: the minimum fields that matter
For each system, capture the business purpose, owner, provider/deployer role, users, data categories, model or service, connected tools, markets, decisions affected, autonomy level, and existing security controls. This turns a spreadsheet into a real governance starting point.
Why AI agent governance requires a different control model
Agents can select tools, retrieve data, trigger workflows, and act quickly. Treat them as governed identities: use least-privilege access, explicit approval boundaries, traceable tool calls, red-team testing, runtime monitoring, and a clear method to stop or roll back actions.
How to connect regulatory requirements to engineering work
Translate every material obligation into a system owner, control objective, technical or process control, observable evidence, review frequency, and escalation route. A requirement has not been operationalized until someone can show that the control works.

Need a precise view of what applies to your AI program?

Start with an inventory and scoped readiness conversation—not a generic compliance checklist.

Request a discovery call