Updated for July 2026: Further requirements under the EU AI Act will apply from 2 August, 2026. We have therefore updated these eight steps to help organizations understand where they stand and identify areas that may still require attention.
The implementation of the EU AI Act is entering a new phase. Organizations need a clear overview of where and how AI is being used across the business, which requirements apply, and where action may be needed.
Preparing for the AI Act is not only a legal exercise. Every AI system comes with its own data, processes, users, impacts, and risks. Organizations therefore need to translate the regulatory requirements into practical processes, documentation, controls, and clear responsibilities.
A good starting point is to establish an overview of your organization’s AI systems and use cases. This can help you determine how relevant systems should be classified, clarify your organization’s role as a provider or deployer, and prioritize the actions needed to strengthen compliance and responsible AI governance.
For a broader introduction to the regulation and its implications, explore what your organization needs to know about the EU AI Act. The European Commission’s overview of the AI Act provides further information about the risk-based framework, applicable requirements, and implementation timeline.
While there is no single route to compliance, organizations can take the following eight steps to assess their readiness and prepare for the requirements ahead.