EU AI Act Compliance for Digital Products: What to Do Before Your Deadline
Most teams shipping AI features are in scope of the EU AI Act and have not classified a single system. Here is the work, in order.
Regulation (EU) 2024/1689 — the AI Act — is the first comprehensive statutory framework for artificial intelligence, and it applies along a staged timeline rather than arriving all at once. The practical consequence for most digital organisations is not dramatic: a handful of features need transparency notices and a documented risk assessment. The problem is that almost nobody has done the classification exercise that tells them which handful.
This is a practitioner's readiness guide, not legal advice. Treat it as a way to arrive at your legal review with the facts already assembled.
Are you in scope?
The Regulation distinguishes roles, and your obligations follow the role rather than your industry.
| Role | Who this is | Obligation weight |
|---|---|---|
| Provider | You develop an AI system and place it on the market under your name | Heaviest |
| Deployer | You use an AI system under your own authority | Moderate — oversight, information, monitoring |
| Importer / distributor | You bring a third-party system to the EU market | Verification duties |
| GPAI model provider | You provide a general-purpose model | Documentation, copyright policy, transparency |
Two traps catch product teams. First, extraterritorial reach: output used in the EU can bring a non-EU company into scope. Second, role drift — fine-tuning and rebranding a third-party model can move you from deployer to provider, and with it into a substantially heavier obligation set.
The risk tiers, in plain terms
Prohibited practices
Certain uses are banned outright, including social scoring by public authorities, exploitative manipulation of vulnerable groups, and specific biometric practices. If a proposal in your backlog resembles any of these, it is not a compliance question, it is a cancellation.
High-risk systems
These attract the real weight: risk management systems, data governance, technical documentation, logging, human oversight, accuracy and robustness measures, conformity assessment and post-market monitoring. Typical triggers are employment and recruitment, creditworthiness, education access, essential public and private services, and safety components of regulated products.
Transparency obligations
This is where most digital products land. Users must be told when they are interacting with an AI system, synthetic media must be disclosed, emotion recognition and biometric categorisation require notification, and AI-generated content needs to be marked in machine-readable form.
Minimal risk
Recommendation ranking, spam filtering, autocomplete and similar uses carry no specific obligations — but they still need to be inventoried, because classification is only credible if it covers everything.
The five deliverables to build now
- An AI system inventory. Every model, feature and third-party AI capability across the estate, with owner, purpose, data used, users affected, and role. This is the artefact everything else depends on and the one nobody has.
- Classification with reasoning. Not just a tier label — a written rationale per system. Regulators and customers will ask why.
- Transparency implementation. Interface disclosures, synthetic-content labelling, and clear documentation of system limitations for users.
- Human oversight design. Who can review, override and stop the system; how they are trained; how their intervention is recorded. Oversight that exists only in a policy document is not oversight.
- Logging and monitoring. Inputs, outputs, decisions and overrides retained appropriately, with drift and incident detection for anything consequential.
Where the AI Act meets GDPR — and where it does not
The two regimes stack rather than substitute. GDPR still governs your legal basis for processing personal data, purpose limitation, minimisation, transparency and data subject rights, including provisions on automated decision-making. The AI Act adds system-level duties: risk management, documentation, robustness and oversight. The practical implication is one combined assessment process — a Data Protection Impact Assessment and an AI risk assessment conducted together, by people who talk to each other — rather than two parallel documentation exercises.
The NIST AI Risk Management Framework is a useful structuring companion here. It is voluntary and not a compliance route, but its govern–map–measure–manage structure maps well onto the evidence the AI Act expects you to produce.
A pragmatic 90-day plan
Days 1–30: build the inventory. Interview product teams and check what AI capability arrived inside SaaS tools nobody classified as AI. Expect surprises.
Days 31–60: classify with written reasoning, identify anything prohibited or high-risk, and implement transparency disclosures — the cheapest and most visible compliance win.
Days 61–90: stand up risk assessment and human oversight for the highest-exposure systems, implement logging, and establish a gate so new AI features are classified at design time rather than discovered later.
The organisations that will struggle are not the ones with risky systems. They are the ones that cannot say what systems they have.
Frequently Asked Questions
Does the EU AI Act apply to our company if we are not in the EU?
It can. The Regulation applies to providers placing AI systems on the EU market and to deployers established in the EU, and it reaches non-EU actors whose system output is used in the EU.
What are the risk categories?
Prohibited practices, high-risk systems with substantial obligations, limited-risk systems with transparency duties, and minimal-risk uses. Separate rules apply to general-purpose AI models.
Is our chatbot high-risk?
Usually not. A customer-service assistant typically falls under transparency obligations — users must know they are interacting with AI, and synthetic content should be disclosed. High-risk status attaches to uses such as employment, credit, education and essential services.
What documentation will we need?
An inventory of AI systems and their classification, risk assessments, data governance records, technical documentation, human oversight arrangements, logging, and post-market monitoring for high-risk systems.
How does this relate to GDPR?
They stack. The AI Act governs the system and its risk; GDPR still governs personal data processing, legal basis, transparency and data subject rights. Compliance with one does not satisfy the other.