EU AI Act: What Your Business Should Do Now
The EU AI Act requires organisations to identify which AI they provide or use, determine their legal role and risk category, and then apply the obligations that match that classification. The practical decision is not “Do we need a large compliance programme?” but “Which of our AI systems are in scope, what applies now, and what evidence or controls are genuinely missing?” Start with an AI inventory and role-and-risk classification before buying a governance platform, rewriting every policy or commissioning a major transformation. A technology request such as “build an AI register” is not the same as solving the business problem: knowing which obligations attach to which AI use cases and who is accountable for them.
As of 9 August 2026, the Act is broadly applicable, with important staged exceptions. Prohibited-practice and AI-literacy rules have applied since 2 February 2025; governance and general-purpose AI obligations since 2 August 2025; and the Commission states that the Act became broadly applicable on 2 August 2026. The 2026 AI Omnibus extended key high-risk transition dates, so organisations should validate older roadmaps against the amended timetable.
This guide helps business, technology, data, risk, privacy, security and procurement leaders decide what to do internally, when a short diagnostic is enough, when a defined EU AI Act readiness project is justified, and when ongoing specialist support is useful.

Quick Answer: Classify First, Then Remediate
For most organisations, the fastest sensible route is to create or validate an AI inventory, identify whether the organisation is acting as a provider, deployer, importer, distributor or product manufacturer, and classify each use case against prohibited, high-risk, transparency and general-purpose AI requirements. Only then should you design controls and evidence.
Use internal teams when the AI estate is small, ownership is clear and legal, risk and technical expertise are available. Use a short diagnostic when the inventory is incomplete or teams disagree about scope. Use a defined consulting project when multiple systems, vendors or business units need evidence, controls and remediation. Choose ongoing support when the AI portfolio changes continuously and internal governance capacity is not yet sufficient.
The main caution is simple: do not hire a consultant, buy tooling or build a control framework before defining the AI use cases and business decisions that need to be governed. The EU AI Act is risk- and role-based; a generic compliance checklist can create work without clarifying what is actually required.
Key Takeaways
- Inventory the real AI estate: record purpose, owner, vendor, model, data, users, geography and lifecycle status.
- Classify legal roles and risk: obligations differ for providers, deployers and other actors, and by risk category.
- Use the current timetable: the 2026 AI Omnibus changed high-risk transition dates, so older plans may be wrong.
- Keep business ownership internal: legal, risk, data, security and system owners must approve classifications and controls.
- Scope evidence before remediation: determine which documents, logs, notices, contracts and procedures are actually required.
- Connect AI governance to data governance: data quality, lineage, access, privacy and monitoring often determine whether controls are credible.
- Plan knowledge transfer: external support should leave an operating process, accountable owners and reusable evidence—not permanent dependency.
Table of Contents
- Decide whether the EU AI Act applies
- Classify AI roles, risks and deadlines
- Build the evidence and data foundation
- Choose internal, project or ongoing support
- Turn requirements into an operating model
- Estimate cost, timeline and resources
- Apply the decision to real AI use cases
- Measure readiness and continuing compliance
- Decide where specialist support fits
- Summary
Does the EU AI Act Apply to Your AI Estate?
Do not start with the assumption that every automated tool is regulated in the same way. Start by mapping the actual AI systems and general-purpose AI models your organisation provides, deploys, imports, distributes or embeds in products, then assess the territorial scope and intended purpose.
The authoritative starting point is the official text of Regulation (EU) 2024/1689. The European Commission AI Act overview is useful for the implementation timetable and practical navigation.
Map legal role before control design
A company can have different roles for different AI systems. It may deploy a third-party recruitment model, provide an AI-enabled product to customers and use a general-purpose model through an external API. Those scenarios do not create identical obligations. Record the role for each use case and retain the reasoning, especially where several suppliers or group entities are involved.
Test territorial scope, not headquarters
A non-EU business should not assume it is outside the Act because it is incorporated elsewhere. The Act can apply in defined situations involving AI placed on the EU market or outputs used in the Union. Map where systems are offered, where users operate, where outputs affect people or decisions, and which group entity contracts with the vendor.
Decision rule: if you cannot produce a current list of material AI use cases with an accountable owner, vendor, intended purpose, geography and legal role, your first project is discovery and classification—not policy expansion.
Classify AI Risk Using the Current 2026 Timetable
Risk classification determines the compliance path. Separate prohibited practices, high-risk AI, transparency obligations and general-purpose AI model responsibilities, then map the dates that apply to each category.
As of 9 August 2026, the Commission states that the Act became broadly applicable on 2 August 2026. It also states that the 2026 AI Omnibus extended high-risk rules for certain Annex III sensitive-area use cases to 2 December 2027 and high-risk AI embedded in regulated Annex I products to 2 August 2028. The Digital Omnibus on AI, Regulation (EU) 2026/1744 is the official amending text.
For borderline or sensitive cases, use the Commission’s high-risk AI guidance alongside legal review. Vendor labels such as “assistive”, “decision support” or “copilot” do not replace analysis of intended purpose and real deployment.
Build Evidence Around AI, Data and Human Oversight
EU AI Act readiness becomes practical when obligations are translated into evidence that system owners can maintain. The correct evidence set varies by role and risk, but most organisations need a governed inventory, classification rationale, accountable owners and traceable links to technical and operational controls.
Prepare the minimum useful evidence set
- AI inventory with purpose, lifecycle status, owner, vendor, model, users and geography.
- Legal role and risk classification with documented rationale and review date.
- Data-source, quality, lineage, access and privacy information relevant to the AI use case.
- Human-oversight roles, escalation paths and decision authority where applicable.
- Transparency notices, user information and content-labelling processes where required.
- Vendor due diligence, contractual obligations, model documentation and change-notification terms.
- Monitoring, logging, incident handling, security and change-management procedures.
- AI-literacy evidence for people who operate, oversee or make decisions about AI.
Treat data governance as a control dependency
A compliance document cannot compensate for unknown training data, weak source-data quality, uncontrolled access or missing lineage. Where AI relies on enterprise data, connect AI controls to existing data ownership, privacy, security, retention and quality processes. This is where data consultants can add value alongside legal and risk specialists: translating obligations into inventories, metadata, control evidence, monitoring data and accountable operating processes.
Choose the Smallest EU AI Act Support Model That Works
The right delivery model depends on how clear your AI estate is, how much internal expertise exists and whether the work is a one-off remediation or a continuing governance workload. Do not default to a large programme if a focused classification exercise can resolve the uncertainty.
| Option | Best fit | Typical outputs | Internal requirement | Main risk |
|---|---|---|---|---|
| Internal team | Small AI estate, clear roles and capable legal, risk and technical owners | Inventory, classification, controls and evidence maintained internally | Protected time and cross-functional expertise | Blind spots where teams mark their own assumptions |
| Software tool | Requirements and governance process are already defined | Register, workflow, evidence repository and reporting | Configuration, ownership and data discipline | Digitising an unclear process without fixing it |
| Short diagnostic | Inventory is incomplete or classification is disputed | Scope, role map, risk classification, gap findings and roadmap | Interviews, system evidence and legal input | Findings stall without accountable owners |
| Defined consulting project | Several systems need controls, evidence and remediation | Operating model, control design, documentation, implementation plan and handover | Business, legal, risk, data, security and technology participation | Scope expands if acceptance criteria are vague |
| Ongoing consultant support | AI use cases, regulation and vendor landscape change continuously | Reviews, change assessments, governance support and evidence refresh | Regular prioritisation and internal decision ownership | Dependency if knowledge transfer is weak |
| Dedicated specialist or managed team | Large, continuous multi-business AI governance workload | Predictable capacity across inventory, controls, monitoring and reporting | Executive sponsor and operating cadence | Cost without value if governance is not embedded |
A hybrid model is often appropriate: internal legal and risk teams retain interpretation and accountability, while data and AI specialists structure the inventory, evidence, controls, technical discovery and implementation work.
Turn EU AI Act Requirements Into Daily Governance
A readiness assessment is useful only if it becomes a repeatable operating process. Design the workflow around the AI lifecycle: intake, classification, approval, deployment, monitoring, change, incident response and retirement.
Start with a controlled intake process
Require new AI use cases and material changes to enter a common governance path. Capture intended purpose, business owner, supplier, model, data, geography, affected users and decision impact. Use those fields to route legal, privacy, security, data and risk review proportionately.
Make vendor changes visible
Third-party AI can change without an internal code release. Contracts and operating procedures should define how model, feature, training-data, subprocessor or material-risk changes are communicated and assessed. Where general-purpose AI is involved, the Commission’s General-Purpose AI Code of Practice provides a practical reference for transparency, copyright and safety obligations relevant to providers.
Keep legal judgement with accountable owners
Data consultants can help operationalise controls, evidence and monitoring, but they should not replace qualified legal advice where statutory interpretation is required. A strong implementation model makes those boundaries explicit and records who approved the classification and remediation decision.
EU AI Act Cost Depends on Evidence Gaps, Not Policies
The main cost drivers are the size and complexity of the AI estate, the number of legal entities and business units, third-party dependencies, the quality of existing evidence, the number of high-risk or sensitive use cases, and how much technical remediation is required. A company with ten well-documented use cases may need less work than one with three poorly understood systems spread across vendors and regions.
Estimate cost in layers: discovery and classification; legal and risk review; data and technical assessment; control and documentation design; vendor remediation; implementation; training; assurance; and ongoing monitoring. Include internal time from system owners, procurement, security, privacy and legal teams. A low external fee can still be expensive if the project repeatedly waits for evidence or decisions.
Commercial decision rule: use a fixed or tightly bounded diagnostic when uncertainty is the main problem. Use a milestone-based project when outputs and systems are known. Use a retainer or managed capacity only when the governance workload is genuinely recurring.
Three EU AI Act Decisions in Real Business Contexts
Recruitment team using an AI screening vendor
Situation: HR uses a third-party tool to rank candidates. Mistaken assumption: the vendor owns all compliance. Actual problem: the employer still needs to understand its own role, the intended use, human oversight, data and evidence, while the vendor relationship must support required information. Better decision: run a targeted classification and evidence review involving HR, legal, privacy, procurement and information security. Likely outputs include a role map, vendor evidence request, oversight procedure, inventory record and remediation plan.
Customer team adding a generative AI assistant
Situation: a business plans a customer-facing assistant using a general-purpose model. Mistaken assumption: the project is only a chatbot deployment. Actual problem: the organisation must assess transparency, content, data flows, vendor responsibilities, security and user impact. Better decision: combine product discovery with AI governance before launch. Likely outputs include intended-purpose documentation, disclosure requirements, data-flow mapping, vendor controls, testing criteria and a monitoring plan.
Enterprise with hundreds of AI-labelled tools
Situation: procurement and technology records contain hundreds of products described as AI-enabled. Mistaken assumption: every record needs the same deep assessment. Actual problem: the inventory lacks consistent definitions and prioritisation. Better decision: use a short discovery phase to filter, de-duplicate and classify use cases before detailed control work. Internal owners validate the business purpose; specialist support can accelerate data gathering, triage and evidence structuring.
Measure EU AI Act Readiness as an Operating Capability
Do not measure progress by the number of policies written. Measure whether the organisation can identify its AI, explain the applicable role and risk, produce current evidence, make controlled changes and escalate incidents.
- Inventory coverage: material AI use cases have verified owners, purpose, vendor and status.
- Classification quality: role and risk decisions have documented rationale and approval.
- Evidence completeness: applicable controls link to current documents, logs or records.
- Remediation closure: high-priority gaps have owners, due dates and acceptance criteria.
- Change control: new systems and material vendor changes trigger reassessment.
- AI literacy: relevant staff understand the risks and responsibilities attached to their work.
- Monitoring: incidents, performance concerns and control failures reach accountable owners.
Quality assurance should sample both “in scope” and “out of scope” decisions. A weak process can create risk by over-classifying harmless automation as easily as by missing genuinely sensitive AI.
When Specialist EU AI Act Support Is Worth Using
External support is most valuable when your organisation has a real execution gap rather than a need for generic awareness. Examples include building an AI inventory across fragmented business units, structuring evidence from vendors, connecting AI governance to data governance, defining metadata and ownership, designing monitoring, or translating a legal gap assessment into an implementation roadmap.
DataConsultant assessments and audits can support a bounded readiness diagnostic where scope and classification are uncertain. Where the primary challenge is control ownership, data lineage, metadata, quality or operating governance, the Data Governance Service may be relevant. For broader AI operating-model and implementation needs, the AI Data Service can be used where the work genuinely requires specialist data and AI capability.
The engagement should define deliverables, decision rights, evidence sources, legal dependencies, acceptance criteria, handover and ownership from the outset. External advisers should make the organisation more capable of operating the controls after the project, not less.
Summary
The EU AI Act is best approached as a classification and operating-governance problem. Internal staff may be sufficient where the AI estate is small, evidence is strong and expertise is available. A governance tool is useful when the underlying process is already defined. A short diagnostic is appropriate when inventory, scope or risk classification is unclear. A defined project is justified when multiple systems need structured evidence, controls and remediation. Ongoing support or a managed team makes sense only when the workload is substantial and continuing.
Before committing budget, validate business goals, AI use cases, legal role, risk category, data quality, access, privacy, security and internal ownership. Then set a scope that matches the current statutory timetable, with clear documentation, quality assurance, knowledge transfer and handover.
EU AI Act FAQs
What does the EU AI Act require from a business using AI?
The EU AI Act requires a business to first identify its legal role and classify each relevant AI system or model. Obligations then depend on whether the organisation is a provider, deployer, importer, distributor or product manufacturer, the risk category, and whether a general-purpose AI model is involved. A practical next step is to maintain an AI inventory that records purpose, owner, vendor, data, users, geography, risk classification and applicable controls.
Does the EU AI Act apply to companies outside the European Union?
It can. The Act has an extraterritorial reach in defined circumstances, including where providers place AI systems or general-purpose AI models on the EU market and where the output produced by an AI system is used in the Union. A non-EU organisation should therefore map where its AI is offered, deployed and consumed rather than relying only on its place of incorporation.
What changed for the EU AI Act in 2026?
The AI Omnibus entered into force on 27 July 2026 and simplified parts of implementation while extending important high-risk transition dates. The European Commission states that the AI Act became broadly applicable on 2 August 2026, while Annex III high-risk use cases have been extended to 2 December 2027 and high-risk systems embedded in regulated products under Annex I to 2 August 2028. Organisations should use the amended timetable rather than an older implementation plan.
How do I know whether an AI system is high-risk?
Start with the AI Act’s classification rules and the relevant annexes, then document why the system is or is not high-risk. Typical questions include whether the system is a safety component of a regulated product or is used in a sensitive Annex III area such as employment, education, essential services or certain biometric contexts. Classification should be based on the actual intended purpose and deployment context, not the vendor’s marketing label alone.
What evidence should we prepare for EU AI Act readiness?
Prepare an AI system inventory, role and risk classification, intended-purpose documentation, vendor contracts, data and model information, human-oversight procedures, transparency notices, incident and monitoring procedures, training evidence, security controls and governance approvals where applicable. The exact evidence set depends on your role and risk category, so avoid creating a large generic document pack before classification is complete.
Do we need a consultant for EU AI Act compliance?
Not always. Internal legal, risk, privacy, security, data and technology teams may be sufficient when the AI estate is small, roles are clear and evidence already exists. External support is more useful when the inventory is incomplete, classification is disputed, vendor evidence is inconsistent, multiple jurisdictions or business units are involved, or the organisation needs a structured readiness assessment and implementation roadmap.
How much does an EU AI Act readiness project cost?
There is no reliable single price because cost depends on the number and complexity of AI systems, legal roles, business units, vendors, jurisdictions, data flows, evidence quality and remediation required. A short diagnostic is usually more contained than a multi-system implementation programme. Buyers should compare scope, deliverables, internal time commitments, legal input, technical testing and handover rather than hourly rates alone.
How long does EU AI Act implementation take?
A focused inventory and readiness diagnostic can be completed relatively quickly when system owners and evidence are available, while remediation across many business units, vendors or high-risk systems can take substantially longer. Timeline is usually driven by discovery, classification, contract dependencies, control design, technical changes and approval cycles. The right plan should sequence urgent applicable obligations first and use the amended statutory dates for later high-risk requirements.
How should ongoing EU AI Act compliance be maintained?
Treat compliance as an operating process rather than a one-off policy exercise. Keep the AI inventory current, define change triggers, review new use cases and vendors, refresh risk classifications, maintain AI literacy, monitor incidents and performance, retain required evidence and track regulatory guidance. Ongoing specialist support is most useful where the AI portfolio changes frequently or internal governance capacity remains limited.
Need a structured starting point? If your AI inventory, role classification or evidence is incomplete, a focused readiness assessment can establish the gaps and prioritised actions before you commit to a larger implementation.
At DataConsultant.in, we help organisations turn data and AI priorities into governed, reliable, and practical business capability.