Skip to main content


      Updated for July 2026: Further requirements under the EU AI Act will apply from 2 August, 2026. We have therefore updated these eight steps to help organizations understand where they stand and identify areas that may still require attention.

      The implementation of the EU AI Act is entering a new phase. Organizations need a clear overview of where and how AI is being used across the business, which requirements apply, and where action may be needed.

      Preparing for the AI Act is not only a legal exercise. Every AI system comes with its own data, processes, users, impacts, and risks. Organizations therefore need to translate the regulatory requirements into practical processes, documentation, controls, and clear responsibilities.

      A good starting point is to establish an overview of your organization’s AI systems and use cases. This can help you determine how relevant systems should be classified, clarify your organization’s role as a provider or deployer, and prioritize the actions needed to strengthen compliance and responsible AI governance.

      For a broader introduction to the regulation and its implications, explore what your organization needs to know about the EU AI Act. The European Commission’s overview of the AI Act provides further information about the risk-based framework, applicable requirements, and implementation timeline.

      While there is no single route to compliance, organizations can take the following eight steps to assess their readiness and prepare for the requirements ahead.

      Jens Krenk

      Nordic AI Lead & Partner, Advisory

      KPMG in Denmark


      Jesper Kaasgaard

      Director, Advisory

      KPMG in Denmark


      • Inventory and classify the current AI landscape

        Review existing AI applications and categorise them to identify high-risk applications that require compliance with the EU AI Act. Leveraging an automated detection/ identification solution, automating intake questionnaires, or implementing a workflow platform, for instance, can aid in accelerating the discovery, inventory, and classification activities required to support and map compliance obligations.

         

      • Conduct a GAP analysis

        Conduct a thorough gap analysis to identify areas of non-compliance and develop an immediate action plan to address these gaps. This analysis could be expedited using an automated or rapid AI assessment approach against established governance framework or EU AI Act compliance obligations.  

      • Review data privacy and security

        Review and, if necessary, update data handling practices to ensure they comply with GDPR and other data privacy aspects of the EU AI Act. Leveraging automated threat detection, analysis and intelligence solutions can drastically reduce the level of effort required to support testing and technical documentation of the requirements outlined in the EU AI Act. 

      • Train your employees

        Educate your workforce on the legal and ethical implications and intended use of AI systems, ensuring they are prepared to handle new responsibilities and compliance tasks. Additionally, ensure the right roles and responsibilities within the organisation, as this will help to ensure the correct processes and functioning.

      • Implement (or reimagine) the AI strategy & governance framework

        Implement standards and best practices for AI model development, deployment, and maintenance in alignment with the EU AI Act’s requirements and other emerging regulatory standards. Leveraging an automated solution to manage various aspects of compliance mapping, obligations tracking, and workflow management can aid in supporting and scaling various governance activities. 

      • Automate model management and evaluation

        Optimise, automate and streamline AI model management processes, ensuring models are transparent, explainable, and trustworthy. Leverage automation to extract and map technical metrics and data from AI model and application metadata to your governance framework, enabling automated compliance and management processes. 

      • Maintain an AI inventory

        This will ensure that AI systems are easily traceable and continuously monitored. Review existing AI systems and use cases and categorise them to identify high-risk systems requiring compliance with the AI Act.

         

         

      • Communicate with all stakeholders

        Communicate transparently with all stakeholders, including customers and partners, about how your company addresses the AI Act requirements and outlines expectations and requirements for each stakeholder group in managing ongoing compliance.


      How we can help your organisation

      We can help you streamline your compliance journey and successfully adapt to the challenges of the AI Act. Our team can operationalise and scale your AI governance, management, and monitoring programs, while sharing key learnings from prior engagements and our own AI automation journey to help improve processes and policies.

      We help you fully understand the eight steps, as well as educate your employees so they know how to respond.

      Additionally, it is important to ensure that your existing systems are compliant. To achieve the highest level of compliance, we can assist by suggesting alternative systems or developing compliant tools if your current ones are non-compliant. Introducing fairness principles early in the process is also crucial to ensure the final products are ethical and fair. We conduct courses on how fairness can be compromised by the wrongful execution or usage of tools.

      We also help clients understand the overlaps between the Artificial Intelligence Act (AIA) and other legislation, such as privacy and security laws. 


      The need for trusted AI


      The EU’s goal for the AI Act is to ensure that AI systems are “safe, transparent, traceable, non-discriminatory and environmentally friendly.” Those priorities are shared by the KPMG Trusted AI framework. 

      This ten-pillar guide is KPMG’s strategic framework to help design, build, deploy and use AI solutions in a responsible and ethical manner while also accelerating value. Through our Trusted AI framework, we assist clients in strategically integrating responsible AI practices, from initial assessments and benchmarking to designing AI governance processes that will align with the provisions of the EU AI Act. 

      With the race to AI adoption heating up, it's crucial for businesses to not only comply with the EU AI Act but also to build a robust AI framework that enables optimal performance. At KPMG, we recognise this and provide a one-stop-shop solution with our expertise across all aspects of AI, backed by our service lines and competency groups in Forensic, Legal, Compliance, NextGen Operations, and Digital Risk. Our unique approach provides businesses with comprehensive solutions and cutting-edge insights to create the ultimate AI framework. 

      Whether you require end-to-end advisory and implementation support, regulatory compliance, or tech integration, we've got you covered.  Contact us, so we can talk more about how we can assist you. 

      Learn more about Trusted AI and the KPMG approach here.


      Read more insights here

      We change the way organizations work through AI & data.

      From deployment to value realization: Translating AI adoption into measurable business value

      Get insight into the new requirements and what it means for your company.

      Contact us

      Please reach out if you would like to hear more about how we can help your company.

      Jens Krenk

      Nordic AI Lead & Partner, Advisory

      KPMG in Denmark

      Jesper Kaasgaard

      Director, Advisory

      KPMG in Denmark

      Subscribe to our KPMG insights newsletter

      Turn insight into opportunity with perspectives and actionable insights on the issues shaping the future of business - from technology and transformation to transactions and financial services.