Business Consulting

EU AI Act Compliance Roadmap: 10 Practical Steps

An EU AI Act compliance roadmap turns regulatory duties into named owners, repeatable controls and evidence that can be reviewed. Start by finding how AI is actually used, classify each use by role and risk, then apply proportionate training, oversight, documentation and monitoring. Not every AI system is high-risk, and no inventory, policy, course or software platform proves compliance by itself.

What an operational AI governance programme looks like

A useful programme connects rules to everyday decisions: which tools people may use, which data may enter them, when a person must intervene, who approves a change and what evidence is retained. The legal duties depend on the organisation’s role, the system, its intended purpose and its risk category.

The consolidated EU AI Act is the legal authority. Commission and Irish guidance help interpretation; recommendations such as an AI register or governance committee are implementation practices unless a specific provision makes them mandatory. For the regulatory background and amended dates, read Dadakai’s EU AI Act for businesses executive guide.

EU AI Act compliance roadmap: ten practical steps

1. Establish accountable ownership and cross-functional governance

Why it matters: AI decisions span operations, legal, HR, security, procurement and technology. Unclear ownership creates gaps.

  • Participants: Executive sponsor, compliance/legal, IT/security, HR/L&D, procurement and operational owners.
  • Activity: Define decision rights, escalation routes, meeting cadence and accountable owners for each use case.
  • Retain: Terms of reference, RACI, named system owners and decision log.
  • Common mistake: Giving one “AI officer” responsibility without authority or functional support.
  • Start this week: Name an executive sponsor and convene a 45-minute cross-functional working session.

2. Discover approved and unofficial AI use

Why it matters: Governance cannot cover tools the organisation has not found. Shadow AI often appears through browser tools, free accounts and AI features added to existing software.

  • Participants: IT, security, procurement, finance, department managers and employees.
  • Activity: Combine surveys, interviews, expense and contract reviews, application discovery and process observation.
  • Retain: Discovery method, responses, tool list and open questions.
  • Common mistake: Treating a procurement list as a complete inventory.
  • Start this week: Ask each manager for three AI uses: approved, experimental and suspected unofficial.

3. Record purpose, users, data and decisions

Why it matters: A product name is not enough to assess obligations. The same tool may be low-impact for drafting and consequential when used in recruitment.

  • Participants: System owner, users, data protection, security and affected process owners.
  • Activity: Document intended purpose, users, inputs, data categories, outputs, affected people and business decisions.
  • Retain: Minimum viable AI register entry and process map where consequences are significant.
  • Common mistake: Recording “productivity” instead of the actual task and decision.
  • Start this week: Complete one register entry for the organisation’s most-used AI assistant.

4. Determine the organisation’s role for each system

Why it matters: Providers, deployers, importers and distributors have different duties. Substantial modification, a changed intended purpose or supplying a system under your own name can alter the role.

  • Participants: Legal/compliance, procurement, product, IT and system owner.
  • Activity: Map the supply chain and classify the organisation’s role per use case—not once for the whole company.
  • Retain: Role determination, rationale, contracts and assumptions.
  • Common mistake: Assuming every software customer is only a deployer.
  • Start this week: Choose one externally supplied system and draw who builds, sells, configures and uses it.

5. Screen prohibited practices and classify potential risk

Why it matters: Prohibited practices require urgent action; high-risk classification triggers specific duties. Most AI uses are not automatically high-risk.

  • Participants: Legal/compliance, risk, system owner, HR where workers are affected and technical specialists.
  • Activity: Screen against Article 5, Annex I and Annex III using the actual intended purpose and statutory conditions. Escalate uncertain or consequential cases for legal advice.
  • Retain: Screening questions, classification rationale, reviewer and review date.
  • Common mistake: Labelling every generative-AI tool “high-risk” because it is powerful.
  • Start this week: Screen recruitment, employee-monitoring and customer-eligibility uses first.

6. Review vendors, contracts, data handling and limitations

Why it matters: A deployer needs reliable instructions, limitations and supplier information to use a system safely. GDPR, confidentiality, security and intellectual-property requirements may apply independently.

  • Participants: Procurement, legal, DPO/privacy, security, IT and business owner.
  • Activity: Review data flows, training-data settings, retention, subprocessors, security, instructions, change notices, audit support and exit arrangements.
  • Retain: Due-diligence record, contract clauses, risk acceptance and approved configuration.
  • Common mistake: Accepting a vendor’s “AI compliant” statement without use-case evidence.
  • Start this week: Add five AI-specific questions to the existing supplier questionnaire.

7. Design role-based AI literacy and practical training

Why it matters: Article 4 requires providers and deployers to support AI literacy while considering people’s knowledge, experience, education and the context of use. The amended provision does not mandate one universal level or certificate.

  • Participants: HR/L&D, system owners, compliance, security and managers.
  • Activity: Define role-specific behaviours, practise realistic scenarios and reinforce learning through guidance and manager coaching.
  • Retain: Needs analysis, materials, attendance, practice results and follow-up actions.
  • Common mistake: Delivering one awareness video to everyone and declaring the obligation complete.
  • Start this week: Run a 20-minute exercise on checking an AI-generated output before use.

8. Implement human oversight, escalation and override

Why it matters: Oversight must work in practice. For high-risk systems, deployers must assign suitably competent people and follow relevant instructions; the precise obligations depend on the system.

  • Participants: Process owner, frontline users, HR, compliance and technical teams.
  • Activity: Define when review is required, what the reviewer can see, thresholds for escalation and how to stop, disregard or override output.
  • Retain: Oversight procedure, authorised roles, training evidence, exception records and test results.
  • Common mistake: Calling a process “human-in-the-loop” when the reviewer lacks time, information or authority.
  • Start this week: Observe one real AI-assisted decision and test whether the reviewer can meaningfully challenge it.

9. Create proportionate records, monitoring and incident processes

Why it matters: Evidence supports control, investigation and improvement. Record-keeping duties vary: high-risk actors have specific requirements, while other organisations should keep records proportionate to risk and applicable law.

  • Participants: System owner, risk, compliance, security, privacy and operations.
  • Activity: Define performance and harm indicators, logging, review frequency, complaint handling, incidents and corrective action.
  • Retain: Monitoring reports, logs where applicable, complaints, incidents, decisions and remediation.
  • Common mistake: Collecting documents without reviewing whether controls work.
  • Start this week: Add AI incidents and near misses to the current incident-reporting route.

10. Review whenever tools, roles, purposes or rules change

Why it matters: AI features, vendor models, workflows and regulation change. A valid assessment can become stale when purpose or configuration changes.

  • Participants: Governance owner, system owner, procurement, legal/compliance and change management.
  • Activity: Set scheduled and event-driven reviews for new features, vendors, data, users, purposes, incidents and regulatory developments.
  • Retain: Review calendar, change assessments, approvals and retired-system records.
  • Common mistake: Treating approval as permanent.
  • Start this week: Add an AI-impact question to procurement, project-change and software-release forms.

A practical 90-day starting plan

PeriodPriorityOutputs
Days 1–30Name ownership, discover AI use and triage urgent cases.Governance charter, initial register, shadow-AI route and prohibited-practice screen.
Days 31–60Classify roles and risks, review priority vendors and define approved use.Role rationales, due-diligence files, risk decisions and interim guidance.
Days 61–90Practise role-based behaviours, test oversight and launch monitoring.Training records, oversight tests, incident route, metrics and review calendar.

Responsibility matrix

FunctionPrimary contributionEvidence
LeadershipRisk appetite, resources, accountability and escalation decisionsMandate, decisions and review minutes
Compliance/legalRole and risk interpretation; regulatory monitoringAdvice, classifications and obligations register
IT/securityDiscovery, access, configuration, security and technical monitoringTool list, settings, tests and incident records
HR/L&DWorkforce impacts, literacy needs and role-based learningNeeds analysis and learning records
ProcurementSupplier diligence, contracts and change notificationQuestionnaires, clauses and approvals
Operational teamsPurpose, real-world controls, oversight and feedbackProcedures, exceptions and performance reviews

Sample minimum viable AI register

FieldExample
System and vendorCustomer-service assistant / supplier name
Owner and usersService director / support agents
Intended purposeDraft replies; no autonomous complaint decisions
Inputs and dataCustomer query; personal-data categories recorded separately
Output and decisionDraft response reviewed before sending
Organisation’s roleProvisional deployer determination with rationale
Risk screenArticle 5 and Annex screening result; other legal risks
ControlsApproved access, data rules, human review and escalation
Vendor evidenceContract, instructions, limitations and security review
ReviewApproval date, next review and change triggers

An AI inventory is an enabling record, not automatic proof of compliance. Link each entry to the decisions and evidence that support it.

Role-based AI literacy training matrix

AudienceLearning focusPractical demonstration
General employeesApproved tools, confidentiality, hallucination, disclosure and escalationIdentify unsafe prompts and verify a generated answer
ManagersAccountability, review quality, automation bias and approval limitsChallenge an AI-assisted recommendation
HR/recruitmentEmployment use, discrimination, data protection and candidate impactReview a ranking workflow and escalation case
Technical teamsSystem limits, data, testing, logging, security and change controlTest failure modes and document mitigation
Governance/complianceRoles, classification, evidence, monitoring and regulatory changeComplete and defend a use-case assessment

Experiential learning changes behaviour

People demonstrate safe AI use through decisions made during real work, not by recognising definitions in a generic quiz. Contextual exercises expose weak judgement: copying confidential material, accepting fabricated citations, relying on biased ranking or approving an output without understanding limitations.

Use scenarios, supervised practice, peer review and short refreshers. The Commission’s AI literacy Q&A supports a context- and role-sensitive approach and confirms that no specific certificate is required.

Manage shadow AI without suppressing useful experimentation

A blanket ban can drive use out of sight. Provide a safe route for experiments: approved sandboxes, permitted data categories, time-limited pilots, named owners and a simple request process. Make disclosure psychologically safe while distinguishing good-faith experimentation from deliberate circumvention.

Integrate AI governance with systems you already have

AI governance should connect to GDPR records and impact assessments, information-security controls, supplier onboarding, enterprise risk registers, incident management and project-change gates. Reuse existing ownership and evidence where it fits, but do not assume GDPR compliance covers every AI Act obligation.

Frequently asked questions

Does every organisation need an AI governance board?

No specific board is mandated by Article 4. Choose a structure proportionate to the organisation, but make accountability and cross-functional decisions explicit.

Is an AI inventory legally required for every business?

The Act imposes specific documentation and record duties in defined contexts, particularly for high-risk systems. A general inventory is prudent because it enables classification and control, but it is not universal proof of compliance.

How should a company handle an uncertain high-risk classification?

Record the intended purpose and statutory analysis, use current official material and obtain specialist legal advice when consequences or uncertainty are material. The Commission’s high-risk guidance page should be checked for its current status.

What counts as meaningful human oversight?

An authorised, competent person must have enough information and time to understand limitations, detect problems and intervene. A nominal approval click is insufficient.

Can compliance software run the programme?

Software can support discovery, records and monitoring. It cannot replace accountable decisions, legal interpretation, competent oversight or safe behaviour.

Final self-assessment checklist

  • We know which approved and unofficial AI uses exist.
  • Every priority use has an owner, intended purpose and role determination.
  • We have screened prohibited and potentially high-risk uses.
  • Supplier evidence and system limitations are reviewable.
  • Learning reflects roles, systems and real work.
  • Oversight includes authority, information, time, escalation and override.
  • Monitoring captures performance, complaints, incidents and change.
  • AI governance connects with privacy, security, procurement and risk processes.
  • Reviews occur on schedule and when material changes happen.
  • Uncertain legal questions are escalated appropriately.

Turn the roadmap into working routines

The goal is not the largest governance binder. It is a proportionate system that makes responsible adoption easier to repeat and easier to evidence.

Dadakai can help facilitate an AI readiness workshop or implementation consultation focused on use-case discovery, ownership, practical governance and role-based capability building. For the broader support model, see AI compliance consulting and training.

What’s the Opportunity You’re Seeing?

Bring us a challenge, an idea or simply a question. We’ll bring an experienced perspective and explore where it could lead.

Book an Intro Call ↓

Have a quick question first? Send us a message

No hard sell. No pressure. No mailing list. No relentless follow-up.

Official sources

Regulatory information checked on 1 September 2026. This article provides aim to provide useful information, not legal advice.