Written for the person who has to answer for it — not for a legal journal. What the Act asks of you, what you must be able to produce on request, and where most companies are quietly non-compliant.
The EU AI Act is product-safety law applied to software. It does not ask whether your AI is good. It asks whether you can show what it did, who was accountable, and what you did when it was wrong.
That distinction matters more than any technical requirement in it. A company with a mediocre model and a complete evidence trail is in better shape than a company with a brilliant model and none.
It is an operational reading, written by people who had to comply. Use it to ask your counsel better questions, not to replace them.
Almost every company reading this is a deployer: you use an AI system in the course of your business. Providers build and place systems on the market. The duties are different, and deployer duties are the lighter set — but they are not nothing.
If you fine-tune a model on your own data and deploy it for hiring decisions, get advice before assuming you are still just a deployer.
The uncomfortable truth for most mid-market companies: your current AI use is probably minimal or limited risk, and your next use case is where high-risk creeps in. CV screening is the classic example — it feels like productivity and is legally employment.
Applies to everyone, at every risk level. Staff who use AI systems must have sufficient understanding to use them sensibly. This is the obligation companies most often miss, because it does not feel like a compliance task. A record of who was trained, on what, and when, is enough.
High-risk systems must be used under human oversight, by people who are competent to exercise it and empowered to override. “A human clicked approve” is not oversight if that human had no realistic basis to disagree.
Automatically generated logs, retained for an appropriate period — at least six months unless other law says longer. The logs must be sufficient to reconstruct what happened. Prompt-and-response pairs alone rarely are; you also need which model, which jurisdiction, which data, which human.
Monitor operation against instructions for use. Suspend use and inform the provider when you identify a risk. Report serious incidents. Keep the evidence.
Where a high-risk system is used in decisions about individuals, inform them. Where they ask for an explanation of a decision, be able to give one.
GDPR did not go away. Where you run a DPIA, the AI Act obligations sit alongside it rather than replacing it.
Prohibitions and AI literacy came into application first. General-purpose model obligations followed. High-risk obligations are the last major tranche. Check current dates with counsel — the Commission has adjusted timing more than once.
Practically: prohibitions and literacy are live obligations today, not future ones. If you have no training record, that is a present gap.
Ignore the article numbers for a moment. A regulator, a customer’s procurement team, or your own auditor will ask for some version of these six things.
If producing any of these would take you more than a day, that is the gap to close first.
Twelve questions. If you cannot answer one with a document rather than an opinion, it is a gap.
Including the ones bought on someone’s personal card.
And a named owner who agrees they own it.
Enforced at a gateway, not requested in a policy.
Not a vendor dashboard we can only look at.
Prompt and response alone will not reconstruct a decision.
And written into the DPA rather than assumed.
What was changed is more useful evidence than what was approved.
Oversight nobody can act on is not oversight.
Who, what, when, and when it is refreshed.
Before someone asks, not after.
For every model provider in the chain.
Including who calls the provider.