The EU AI Act is not simply a legal text for the compliance team. It changes how organisations need to identify AI systems, classify their role, understand use cases, manage providers, retain evidence and govern deployment across countries and business functions.
Practical situation: A global group buys the same recruitment platform in several regions. The product includes AI ranking, but procurement records describe only a software subscription. The European entity, the group HR team and the vendor each hold different information about purpose, data, model updates and human review.
Readiness begins with a reliable AI inventory and a repeatable classification workflow. Global organisations should create one control backbone for AI governance, then attach EU obligations and other jurisdictional requirements to the systems and uses to which they apply.
Why this belongs on the ERM agenda now#
AI functionality is embedded in ordinary products#
Organisations may deploy AI through recruitment, fraud, customer service, security, productivity and analytics tools without a separate “AI project” being approved. For risk teams, the implication is operational rather than theoretical. The test is whether the issue changes a real decision on resources, controls, suppliers, customers or strategy.
Roles and obligations vary by use#
The same organisation may act differently depending on whether it develops, provides, deploys, imports or distributes an AI system. Classification cannot be inferred from the vendor category alone. That matters because traditional controls often react after the exposure has already moved. The ERM response should therefore define an owner, a decision trigger and evidence showing whether the organisation’s approach to EU AI Act readiness is improving or deteriorating.
Requirements are phased and still operationally detailed#
Policies, literacy, transparency, provider management, risk assessment and evidence need different lead times. Waiting for a final deadline creates a rushed inventory and weak control design. The practical consequence is easy to miss. A useful response converts the concern into observable signals, named decisions and time-bound actions rather than adding another narrative risk to the register.
What good looks like#
For EU AI Act readiness, good governance means that the next decision is easier to make and defend. The organisation can identify the owner, find the current evidence, explain movement and act before the reporting cycle has passed. It does not ask every activity to carry the same control burden; scrutiny increases with authority, exposure and reversibility. The first visible sign of progress is: A group AI inventory covers internally developed, purchased and embedded capabilities.
Look for these five characteristics in the operating process:
-
A group AI inventory covers internally developed, purchased and embedded capabilities.
-
Each system is classified by purpose, role, jurisdiction, affected people and impact.
-
Applicable obligations are mapped to controls, owners, evidence and due dates.
-
Material changes in model, data, purpose or provider trigger reassessment.
-
Global minimum controls and local legal overlays are visible in one workflow.
A practical AI Act readiness programme#
1. Build an AI inventory that reflects real use#
This is where ownership becomes visible. Search beyond data-science teams. Review procurement, SaaS features, HR, customer operations, fraud, security, marketing, coding and embedded analytics. Record the business purpose and affected users, not just the product name.
Minimum evidence should include system ID, business owner, technical owner, provider, model, purpose, users, decisions influenced, data, jurisdictions and deployment status. The result should be reusable in monitoring and reporting, not a one-off document that disappears after the Build an AI inventory that reflects real use step is complete.
2. Determine organisational role and scope#
Design the step around the exception that management would need to understand quickly. For each use, assess whether the organisation develops, provides, deploys, imports or distributes the system and whether EU persons or operations are affected. Record the legal rationale and uncertainty.
A reviewer should be able to find role determination, entity, geography, contractual position, legal review and approval of scope conclusion. This allows challenge to focus on the quality of the decision rather than on reconstructing the history of EU AI Act readiness.
3. Classify risk and applicable requirements#
Start by making the decision explicit. Use a governed decision tree to identify prohibited, high-risk, transparency-related, general-purpose or lower-risk uses as applicable. Keep the classification linked to the specific purpose because changing use can change the result.
The practical output is classification, rationale, evidence, reviewer, date, assumptions and triggers for reassessment. Clear evidence also makes it easier to distinguish a genuine change in EU AI Act readiness from a change in wording or presentation.
4. Map obligations to controls and evidence#
Keep this step deliberately simple. Translate requirements into operational controls such as human oversight, data governance, transparency, monitoring, documentation, provider due diligence and incident handling. Assign each control to a real owner.
Do not close the step without obligation ID, control mapping, responsible function, implementation status, evidence type, due date and testing approach. The record should enable another qualified person to understand the decision, test it and continue the work without relying on personal memory.
5. Govern providers and material change#
Treat this as an operating requirement, not a documentation exercise. Contracts should support information access, change notification, incident cooperation and documentation. Reassess when a provider changes the model, intended purpose, data handling or material functionality.
The control record should show provider records, contract clauses, change notices, review workflow, unresolved gaps and exit or compensating-control decisions. Recording those elements shows how the Govern providers and material change step supports the wider approach to EU AI Act readiness and gives the next reviewer a usable starting point.
6. Create defensible deployment gates#
The strongest programmes begin with a narrow, testable definition. Require approval before production and after material change. The approver should see classification, validation, control status, residual risk and open actions rather than relying on a general policy attestation.
The decision file should retain deployment decision, sign-offs, limitations, monitoring plan, accepted gaps, expiry and post-deployment review date. That evidence keeps the judgement on EU AI Act readiness traceable when ownership, assumptions or operating conditions change.
Ownership and decision rights#
Effective governance of EU AI Act readiness requires more than a name in the risk register. The operating chain should connect the business decision, the controls and data used to support it, independent challenge and the forum that can accept or change the exposure. Five responsibilities deserve explicit treatment.
- Executive sponsor: owns the outcome and approves trade-offs that exceed a function’s authority. The sponsor should understand how EU AI Act readiness affects the wider AI and Model Risk agenda and what delay would mean for customers, services, strategy or legal entities.
- First-line owner: runs the activity that creates or manages the exposure. This person should lead the work to build an ai inventory that reflects real use, keep the conclusion current and translate it into operating choices.
- Control and data owners: operate the controls and produce the evidence behind measures such as AI systems with confirmed purpose and owner. For EU AI Act readiness, they should explain lineage, exceptions, manual intervention and the response when a control or feed fails.
- Second-line challenge: tests scope, assumptions, rating, appetite interpretation and proposed action. It should challenge the risk of treating the programme as a legal memo, document disagreement and confirm when higher authority is required.
- Assurance and governance forums: assess whether the process works in practice and whether material conclusions reach the right committee. They should test whether the organisation can create defensible deployment gates, whether open weaknesses are visible and whether prior decisions produced the expected result.
For EU AI Act readiness, a responsibility matrix is only the beginning. The workflow should preserve who submitted, reviewed, challenged, approved, changed and closed each material record, together with the date and rationale. That history protects continuity when teams, suppliers or legal-entity leadership change.
A realistic maturity path#
Maturity in EU AI Act readiness should be earned through better decisions, not declared because a new methodology has been approved. A three-level path keeps investment tied to operating value.
Level 1: establish visibility#
Start with discoverability: one place to see EU AI Act readiness, its owner, status, evidence and next review. Track AI systems with confirmed purpose and owner and resolve the largest gaps before adding more scoring detail.
Level 2: connect decisions and controls#
At the second level, EU AI Act readiness becomes part of the operating rhythm. Controls, observations, incidents and actions update the same conclusion, while Systems with unresolved scope or classification and Applicable obligations without implemented control show whether intervention is working.
Level 3: anticipate and optimise#
Use scenarios, dependencies, leading indicators and cross-entity comparison to identify where EU AI Act readiness may move next. A global AI inventory with entity, jurisdiction, role, purpose and risk classification should shorten the time from weak signal to decision while leaving judgement and approval visible.
The maturity test for EU AI Act readiness is simple: can the organisation notice change, make a defensible decision and show whether the decision worked?
Measures that are useful in management meetings#
For EU AI Act readiness, reporting should combine coverage, outcome and timeliness. Use AI systems with confirmed purpose and owner as an initial indicator and add context on severity, concentration, overdue age and business effect. Leaders should be able to tell whether the number changed because the organisation found more records, because exposure worsened or because controls improved.
-
AI systems with confirmed purpose and owner: Measures inventory quality.
-
Systems with unresolved scope or classification: Shows legal and operational uncertainty.
-
Applicable obligations without implemented control: Identifies readiness gaps.
-
Provider changes assessed before deployment: Tests change governance.
-
High-impact systems with current monitoring and human-oversight evidence: Shows control operation.
-
AI literacy completion by relevant role: Supports appropriate use and oversight.
Common failure modes#
-
Treating the programme as a legal memo: Operational teams still lack inventory, controls and evidence.
-
Inventorying only internally built models: Most enterprise exposure may sit in purchased or embedded tools.
-
Classifying the product once for all uses: Purpose and affected people can change the legal and risk outcome.
-
Relying on vendor statements without evidence: The deployer still needs enough information to govern its use.
-
Building a separate EU-only workflow: Duplicate inventories and controls create inconsistency and missed change.
A 90-day implementation plan#
Days 1–30: establish the facts#
Launch a group AI discovery exercise and define the minimum inventory. Prioritise uses affecting employment, customers, critical services, financial decisions, safety or sensitive data. Record unresolved questions rather than excluding uncertain items.
Days 31–60: test the operating model#
Pilot the role and risk-classification workflow on ten representative systems. Map obligations to existing privacy, model, technology, procurement, compliance and incident controls. Identify where evidence or ownership is missing.
Days 61–90: embed the management rhythm#
Approve the global AI governance backbone, local EU overlay and deployment gate. Establish provider change notification, periodic monitoring and a regulatory-change process so the control model can evolve without rebuilding the inventory.
How technology should support the process#
Good tooling for EU AI Act readiness reduces hand-offs and improves traceability. It does not replace accountable judgement or turn uncertainty into an artificial decimal score. The first useful building block is A global AI inventory with entity, jurisdiction, role, purpose and risk classification. From there, the platform should support:
-
A global AI inventory with entity, jurisdiction, role, purpose and risk classification.
-
Regulatory obligation mapping to controls, policies, evidence and implementation actions.
-
Provider due diligence, contracts, changes and unresolved information gaps.
-
Maker–reviewer–approver gates for deployment and material change.
-
Monitoring, incident, exception and audit history linked to each AI system.
For EU AI Act readiness, the closest Vilfora product workspace is /regquanta/regulatory-compliance/circular-tracker. A useful implementation should connect that workspace to the relevant risks, controls, obligations, incidents, actions and reports rather than treating it as an isolated register.
Global implementation lens#
International implementation of EU AI Act readiness should distinguish the enterprise minimum from the local overlay. The group can standardise inventory and impact classification, while legal entities document the jurisdiction, language, market structure and delegated authority that change how the control operates.
For this topic, common records should support data, model and human oversight without forcing local teams to hide legitimate differences. The global view should report AI systems with confirmed purpose and owner consistently, preserve the source evidence and show where data or terminology cannot be aggregated safely.
Local governance should then specify who will build an ai inventory that reflects real use, which forum owns exceptions and how issues involving deployment and change approval are escalated. This produces comparable governance across countries without turning the global framework into identical paperwork everywhere.
Questions senior management should ask#
-
Which AI capabilities are embedded in products that are not recorded as AI systems?
-
Can every material use be linked to a business purpose, role and jurisdiction?
-
Which applicable obligations do not yet have an operating control and evidence owner?
-
How are vendor model changes detected and reassessed?
-
Can the organisation stop or constrain a deployment when required evidence is missing?
Frequently asked questions#
Does the EU AI Act affect companies outside the EU?#
It can affect organisations outside the EU depending on their role, market activity, users and where system outputs are used. Scope should be assessed for each use with qualified legal advice.
What is the first practical step for AI Act readiness?#
Build an inventory that captures real AI use across purchased, embedded and internally developed systems. Classification and control mapping depend on knowing the purpose, owner, data and affected people.
Should AI Act controls be separate from existing governance?#
Usually not. Privacy, model risk, technology, procurement, security, compliance and incident controls should be reused where they satisfy the requirement, with gaps added to a common control framework.
How should organisations handle changing implementation timelines?#
Maintain a regulatory-change record and map requirements to due dates, dependencies and actions. Build durable capabilities such as inventory, ownership, classification and evidence rather than waiting for the final date of one obligation.
Final takeaway#
The organisations best prepared for AI regulation will be those that can explain what AI they use, why they use it, who is accountable and what evidence supports the decision to deploy it. The aim is not to predict every outcome. It is to notice material change, compare exposure with appetite, choose an owner and preserve the evidence behind the decision. That is the practical standard for EU AI Act readiness.
Vilfora ERM is designed to keep EU AI Act readiness connected to the owners, controls, actions and approvals that determine the real outcome. Review the workflow around /regquanta/regulatory-compliance/circular-tracker against the steps above rather than evaluating the screen as an isolated register.




