Not sure where your AI use stands?
Run the free AI compliance checkup to get a practical readiness score, likely risk bucket, missing controls and next actions.
Requirement categories
- Prohibited practices: avoid or stop banned unacceptable-risk uses.
- High-risk systems: maintain risk management, documentation, data governance, logging, transparency, human oversight, robustness and monitoring.
- Transparency obligations: inform people when they interact with AI or view certain AI-generated content.
- GPAI obligations: specific rules for providers of general-purpose AI models, with additional expectations for systemic-risk models.
- AI literacy: ensure relevant people understand AI use, limitations and risks.
How to translate requirements into tasks
Create one task list for each AI system. Do not create a generic compliance plan detached from real use cases. For a chatbot, focus on transparency, escalation, data handling and monitoring. For an HR tool, focus on risk classification, human oversight, bias, documentation and legal review. For a GPAI model provider, focus on provider-specific obligations and evidence.
Who should be involved
AI Act readiness is cross-functional. Product understands functionality. Engineering understands architecture and logs. Security understands misuse and access risk. Privacy understands personal data. HR understands employee impact. Legal and compliance interpret obligations. Leadership decides risk appetite and resources.
FAQ
Are requirements the same for providers and deployers?
No. Obligations vary by role and use case.
What is the best first document?
An AI inventory with classification notes and responsible owners.
Can requirements change?
Guidance and implementation support can evolve, so monitor official updates.
Sources and review method
This page is written as general business guidance, not legal advice. It is maintained from official AI Act materials, European Commission / AI Office updates, the NIST AI Risk Management Framework and practical AI governance controls.