How do I prepare for the EU AI Act?
Prepare for the EU AI Act by inventorying the AI systems you build or use, classifying each by the Act’s risk tiers, and then meeting the obligations for that tier: avoid prohibited practices, implement the high-risk requirements (risk management, data governance, documentation, human oversight) where they apply, meet transparency duties, and track the staged application dates.
Step by step
- Inventory your AI systems. List the AI systems you build, deploy, or use, and where they are used, so you know what is in scope.
- Classify by risk tier. Sort each system into the Act’s tiers: prohibited, high-risk, transparency, or minimal risk.
- Eliminate prohibited practices. Confirm you do not operate any AI practice the Act prohibits.
- Implement high-risk requirements. Where a system is high-risk, put in place risk management, data governance, technical documentation, human oversight, and accuracy and robustness.
- Meet transparency duties. Where systems interact with people or generate content, provide the required disclosures.
- Track the timelines. Map the staged application dates to your systems so obligations are met on time.
Start with an inventory and classification
The EU AI Act is risk-based, so almost everything depends on which tier each system falls into. Build an inventory of your AI systems and classify each as prohibited, high-risk, transparency, or minimal. Most systems are not high-risk, so this step keeps the work proportionate.
It can reach you from outside the EU
Like the GDPR, the Act has extraterritorial reach: it can apply to providers and deployers outside the EU when their AI is placed on the EU market or used in the EU. If you sell into or operate in the EU, assume it may apply and check.
Where Keel fits
Keel helps you inventory AI systems, hold the documentation and evidence that high-risk obligations require, and reuse that work across ISO 42001 and the NIST AI RMF, so AI Act readiness is part of one governance program rather than a separate scramble.
FAQ
Does the EU AI Act apply to US companies?
It can. The Act has extraterritorial reach and may apply to providers and deployers outside the EU when their AI systems are placed on the EU market or used in the EU, similar to how the GDPR reaches beyond the EU.
Is every AI system high-risk under the Act?
No. The Act is tiered, and most systems are not high-risk. A small set of practices are prohibited, specific uses are high-risk, some carry transparency duties, and the rest are minimal risk. Classification is the key first step.
Get audit-ready with Keel
The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free