Skip to main content
← All posts·
Regulatory Compliance

How to Implement EU AI Act Compliance: Enterprise Step-by-Step Guide [2026]

Practical implementation guide for EU AI Act compliance. Covers AI system inventory, risk classification, conformity assessment, technical documentation, human oversight design, and post-market monitoring. With timelines for the December 2027 high-risk deadline (postponed from August 2026).

Luca Berton14 min read

December 2027: The Clock Is Ticking for High-Risk AI

The EU AI Act's requirements for high-risk AI systems become applicable on 2 December 2027, after the EU's 2026 Digital Omnibus postponed the original 2 August 2026 date. If your enterprise deploys AI in healthcare, financial services, HR, education, law enforcement, or critical infrastructure, you likely have high-risk systems that need to comply.

This guide provides the practical steps to get there — not the legal theory, but the engineering and governance work that actually needs to happen.

Step 1: AI System Inventory (Weeks 1-3)

Find All Your AI

Most enterprises don't know how many AI systems they have. Start with discovery:

  • Formal AI/ML projects — Data science team models, production ML pipelines
  • Embedded AI — AI features in SaaS tools (CRM lead scoring, HR screening, fraud detection)
  • Generative AI — ChatGPT Enterprise, Copilot, internal LLM deployments
  • Rule-based systems — Some automated decision-making may fall under the AI Act's broad definition
  • Third-party AI — API-based AI services (translation, vision, NLP) embedded in your products

For each system, document: Purpose, input data, output decisions, affected persons, deployment context, and vendor (if third-party).

Step 2: Risk Classification (Weeks 3-5)

Classify Each AI System

Map each system to the AI Act's risk categories:

  • Prohibited (Art. 5): Social scoring, real-time biometric ID in public spaces (with exceptions), emotion recognition in workplace/education, subliminal manipulation
  • High-risk (Annex III): Biometrics, critical infrastructure, education, employment, essential services (credit, insurance), law enforcement, migration, justice
  • High-risk (Annex I): AI as safety component of regulated products (medical devices, machinery, vehicles, aviation)
  • Limited risk: Chatbots, deepfakes, emotion recognition (transparency obligations only)
  • Minimal risk: AI-enabled games, spam filters, search engines (no obligations beyond voluntary codes)

Grey areas: When classification is unclear, document your reasoning. The AI Office will provide guidance, but conservative classification is safer.

📘 Book

Kubernetes Recipes

A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).

Watch on Skillshare

Step 3: High-Risk AI Compliance Requirements (Weeks 5-16)

Art. 9 — Risk Management System

Continuous risk management throughout the AI lifecycle:

  • Identify known and foreseeable risks to health, safety, and fundamental rights
  • Estimate and evaluate risks using quantitative metrics where possible
  • Design risk mitigation measures (guardrails, thresholds, human escalation points)
  • Test for residual risk acceptability
  • Document everything — this forms the basis for conformity assessment

Art. 10 — Data Governance

Training, validation, and testing datasets must meet quality criteria:

  • Relevance and representativeness — Data must reflect the population the AI will serve
  • Error-free — Systematic effort to identify and correct errors in training data
  • Bias examination — Proactive testing for bias across protected characteristics
  • Data provenance — Document where training data came from, how it was collected, and what preprocessing was applied

Art. 11-12 — Technical Documentation

The AI Act requires comprehensive technical documentation including:

  • General description and intended purpose
  • Detailed description of AI system elements and development process
  • Monitoring, functioning, and control mechanisms
  • Risk management system description
  • Changes and updates throughout lifecycle
  • Performance metrics and testing results
  • Cybersecurity measures

Art. 14 — Human Oversight

Design human oversight appropriate to the risk:

  • Human-in-the-loop: Human approves every AI decision before action (highest risk)
  • Human-on-the-loop: Human monitors AI decisions and can intervene (moderate risk)
  • Human-in-command: Human can override AI and has a "stop button" (all high-risk)
  • Infrastructure requirement: Build dashboards, alert systems, and intervention mechanisms into the AI serving infrastructure

Step 4: Conformity Assessment (Weeks 12-20)

Two paths depending on your AI category:

  • Self-assessment (most Annex III high-risk): Internal conformity assessment following Annex VI. You assess yourself against the requirements and sign a declaration of conformity.
  • Notified body assessment (some high-risk): Biometric identification systems and AI in regulated products (medical devices, vehicles) need third-party assessment. Engage notified bodies early — they're going to be overwhelmed.
🎓 Course

Terraform for Beginners

Master Terraform to build scalable infrastructure using IaC principles.

Start on Udemy

Step 5: EU Database Registration and Post-Market Monitoring

  • Register high-risk AI in the EU database (Art. 71) before placing on market or putting into service
  • Post-market monitoring plan (Art. 72) — Continuous monitoring of AI performance in production, including user feedback and incident tracking
  • Serious incident reporting (Art. 73) — Report serious incidents to market surveillance authorities without delay

Timeline for December 2027 Compliance

  • Now: AI inventory + risk classification (if you haven't started, start today)
  • Through mid-2027: Risk management, data governance, and technical documentation complete
  • Q3 2027: Conformity assessment, internal audit, remediation
  • 2 December 2027: Compliance required — declaration of conformity, EU database registration
  • Ongoing: Post-market monitoring, incident reporting, periodic review
🚀 Need Help?

AI Platform Assessment

Get a 2-3 week infrastructure audit with a concrete roadmap. No big-consultancy overhead.

Book Your Free Assessment
EU AI Act
compliance
implementation
enterprise
risk classification
how-to guide
conformity assessment

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →