"EU AI Act compliance" isn't one deadline — it's a staggered rollout where different obligations activate on different dates, and where the obligations that actually apply to your company depend on classifying each AI system you use against the Act's risk tiers. For a mid-sized corporation, the practical starting point isn't a generic compliance checklist; it's an inventory of every AI system in active use, checked against Annex III's list of high-risk use cases.
Building a compliance approach that actually maps to the law
1. Inventory every AI system in use and classify its risk tier. Check each system against Annex III's high-risk categories (employment/HR tools, credit scoring, and others) — most general-purpose chat assistants used for drafting or research won't qualify as high-risk, but purpose-built decision-automation tools often will.
2. Track the applicable dates for your specific systems. A high-risk recruitment tool and a general-purpose AI assistant are on different compliance timelines — don't apply the same deadline to every system in your inventory.
3. For anything classified high-risk, build the required documentation and oversight. High-risk obligations include a risk management system, technical documentation, logging capability, and human oversight measures — these need to exist before the applicable deadline, not be retrofitted after.
# A starting template for an AI system risk-classification inventory
# -- fill one row per AI system your company actually uses
| System | Purpose | Annex III Match? | Risk Tier |
|--------------------|---------------------------|-------------------|-------------|
| Resume screening AI| Candidate ranking | Yes (employment) | High-risk |
| Support chatbot | Customer Q&A | No | Limited-risk (transparency) |
| Internal drafting assistant | Document drafting | No | Minimal-risk |
| Applicable Date | What Activates |
|---|---|
| February 2, 2025 | Prohibited AI practices banned; AI-literacy obligations begin |
| August 2, 2025 | Governance rules and general-purpose AI model provider obligations |
| August 2, 2026 | Most high-risk system obligations (Annex III) and transparency rules (Article 50) |
Because the timeline has already been revised once (the 2026 "Digital Omnibus" simplification package pushed some high-risk deadlines later), treat any specific date you read — including the ones above — as something to verify against the European Commission's official AI Act Service Desk before finalizing a compliance calendar, rather than something to hardcode into a policy document indefinitely.
Practical Challenge
Build an inventory like the template above for 3-5 AI tools your organization actually uses, and for each one, check it against Annex III's high-risk categories on the official AI Act text.
Concept Check
Sources & Further Reading
- EU AI Act Service Desk: Timeline for Implementation — the official European Commission timeline for phased applicability dates.
- European Commission: AI Act — Shaping Europe's Digital Future — the official policy page for the regulation, including risk-tier definitions.
- EU Artificial Intelligence Act: Implementation Timeline — an independent, frequently-updated tracker of applicability dates, useful for cross-checking the official source.
AI