GovCompass

First steps: EU AI Act compliance for deployers

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

The first steps to EU AI Act compliance for deployers are: build an AI inventory, classify each system against Art. 6, request the provider documentation, start AI-literacy training under Art. 4, and assign ownership. These steps create the foundation for the Art. 26 obligations.

Updated: June 2026

Introduction: starting from zero

Most Dutch organizations are somewhere on the spectrum between "we haven't started" and "we have a basic inventory." Very few have achieved the level of systematic compliance that the EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → ultimately requires. The good news: you do not need to achieve full compliance immediately. The regulation's phased deadlines, and the proportionalityproportionalityMatching the weight of governance to the risk of the use case (heavy gates for high stakes, a light touch for low stakes), which keeps controls credible and followed.Open full entry → principleprincipleOne of the seven responsible-AI values a governed system should live up to (fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, human oversight). A principle is abstract: it states an outcome, not a lever you can pull. It becomes governable by naming the harm that would breach it, assessing the risk that harm carries, and placing controls against that risk. Held this way, a principle becomes a pillar. See pillar, harm, risk.Open full entry → built into the law, allow for a structured approach.

This article identifies the five most important first steps for deployersdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry →, prioritized by legal urgency and practical impact.

Step 1: build your AI inventory

You cannot comply with obligations you do not know about. The first step is a systematic inventory of every AI systemAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → your organization uses, not just the ones IT knows about, but the SaaS tools that business units procure independently, the AI features embedded in enterprise software, and the AI-enabled workflows in your operations.

A useful inventory structure:

  • System name and vendor
  • Business function (HR, finance, operations, etc.)
  • Primary use case
  • Affected categories of individuals
  • Preliminary riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → classification (to be confirmed in Step 2)
  • Operational status (in use / planned / under review)

Assign this exercise to a cross-functional team that includes IT, legal, HR, and business unit representatives. The AI inventoryAI inventoryA register of all AI systems an organization builds, buys or embeds, with owners and risk tiers. It is the prerequisite for governing any of them.Open full entry → often surfaces surprise discoveries, business units using AI tools that IT is unaware of, vendor features that have enabled AI without explicit organizational decision.

Step 2: classify your AI systems

For each system in your inventory, determine its risk classification under Art. 6:

  • Prohibited (Art. 5): Immediately assess against the eight prohibitions
  • High-risk (Annex I or III): Full Art. 26 compliance obligations apply
  • GPAI systems (Art. 52–55): TransparencytransparencyOpenness about the fact that AI is used and how it operates in general: disclosures, documentation, notices. Pairs with explainability, which addresses individual outcomes.Open full entry → obligations
  • Minimal risk: No mandatory EU AI Act obligations (though voluntary codes of practicecodes of practiceVoluntary guidance under the AI Act, notably for general-purpose AI, that helps providers show compliance until harmonized standards exist.Open full entry → apply)

For systems where classification is uncertain: apply the conservative default. Classify as high-risk until you can substantiate a lower classification. Document your reasoning.

Step 3: set up AI governance

Compliance requires accountabilityaccountabilityThe principle that a named human or organization answers for an AI system's outcomes, through ownership, documentation, audit trails and redress; never the system itself. The EU AI Act attaches obligations to the role rather than the technology, with provider duties in Article 16 and deployer duties in Article 26, supported by technical documentation (Article 11) and record-keeping (Article 12). See provider, deployer, record-keeping, responsible AI.Open full entry → structures. At minimum:

  • Appoint an AI Officer (or assign the function to an existing role like the DPO or CTO)
  • Define the AI Officer's responsibilities: maintaining the inventory, overseeing classification, approving risk downgrades, liaising with supervisory authorities
  • Establish a governancegovernanceThe system through which an organization steers itself: corporate governance, risk management, compliance, lines of accountability, risk appetite, and the operating model. It exists across everything the organization does, before and beyond AI. AI governance is this same system extended for AI. See AI governance, governance design, execution level.Open full entry → process for new AI system procurement: no new high-risk AI without classification, DPIADPIAData Protection Impact Assessment: required before likely-high-risk processing (systematic profiling with significant effects, large-scale special categories, public monitoring); AI development triggers it constantly.Open full entry →/FRIAFRIAFundamental Rights Impact Assessment: required of public bodies and certain private deployers before using some high-risk AI systems under the EU AI Act.Open full entry → assessment, and sign-off
  • Create a policy document that sets out your organization's AI governance framework

Step 4: prioritize high-risk systems

Not all compliance work has equal urgency. Focus first on your high-risk AI systemshigh-risk AI systemAn AI system that falls under the EU AI Act's strictest requirements, following Article 6. There are two routes in: a system that is a product or safety component covered by the Union harmonization legislation in Annex I and subject to third-party conformity assessment, or a system used in one of the areas listed in Annex III, such as employment, education, or access to essential services. Article 6(3) contains a filter: an Annex III system is not high-risk if it does not pose a significant risk of harm to health, safety, or fundamental rights, although a system that profiles natural persons is always high-risk. See EU AI Act, Annex III, conformity assessment.Open full entry → in the categories that took effect earliest:

  • Art. 5 prohibited practicesprohibited practicesAI uses banned outright under the AI Act, such as social scoring, manipulative techniques and untargeted scraping of facial images.Open full entry →: compliance required since 2 February 2025
  • Art. 4 AI literacyAI literacySufficient understanding of AI's workings, capabilities and risks for one's role, an explicit expectation for provider and deployer staff under the EU AI Act.Open full entry →: required since 2 February 2025
  • High-risk AI in regulated products (Annex I): deadline 2 August 2028
  • Stand-alone high-risk AI (Annex IIIAnnex IIIThe EU AI Act's list of high-risk use-case areas: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice.Open full entry →): deadline 2 December 2027

For Annex III high-risk systems: build your compliance dossier now. The 2027 deadline appears distant but the work is substantial: FRIA, DPIA, human oversighthuman oversightDesigned-in human ability to monitor, intervene in, override or shut down an AI system. It is meaningful only when the human has authority, information and time to act. One of the seven pillars of responsible AI, and under the EU AI Act a requirement for high-risk AI systems: Article 14 requires that those systems are designed so natural persons can effectively oversee them. Oversight that exists on paper but amounts to confirming in practice does not meet that bar. See override rate, automation bias, high-risk AI system, fairness, safety and reliability, privacy, security and robustness, transparency and explainability, accountability, responsible AI. In the IAPP AIGP body of knowledge, this principle appears as human-centricity, with human oversight as one of its elements.Open full entry → arrangements, training documentation, log retention systems.

Step 5: establish supplier relationships

For every high-risk AI system you procure: engage your supplier. Request:

  • The providerproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry →'s technical documentationtechnical documentationRecords a provider must compile and keep for a high-risk AI system to demonstrate conformity, covering its design, data, testing, risk management and monitoring.Open full entry → (summary)
  • The EU declaration of conformitydeclaration of conformityThe provider's signed statement that a high-risk AI system meets the AI Act's requirements, drawn up before the system is placed on the market.Open full entry → (or conformity assessmentconformity assessmentThe pre-market process demonstrating a high-risk AI system meets the EU AI Act's requirements, leading to CE marking and registration.Open full entry → status)
  • The instructions for use
  • The EU database registration number
  • Contractual commitments on incident notification, performance monitoring, and documentation updates

Suppliers who cannot or will not provide this information present a compliance risk. Document your requests and their responses.

Compliance checklist

  1. Is there a complete AI inventory for your organization?
  2. Has every AI system been classified against Art. 5 and Art. 6?
  3. Is there an appointed AI Officer with defined responsibilities?
  4. Is there a governance process for new AI procurement?
  5. Have you engaged suppliers of high-risk AI systems and requested compliance documentation?
  6. Is there a documented compliance roadmap for high-risk AI systems with deadlines assigned?

For whoever takes ownership of this new governance role, the AIGP certification is the recognized way to demonstrate the capability.

Legal referencesArt. 26Art. 4Art. 6
Share Share on LinkedIn

More on Accountability

Agentic AI and governance: why autonomy sharpens the control question

Analysis

Agentic AI does not need a new kind of governance. Autonomy widens the gap between what a system does and who is accountable for it, which makes the existing governance chain, control tracing to risk and forward to evidence, more important, not less. The actions are real and sometimes irreversible, so the stakes on each control rise.

Agentic AI risk assessment: from architecture decisions to control objectives

Analysis

Assessing the risk of an AI agent does not need a separate method. The steps stay the same: recognize the risk, assess how likely and how severe it is for your system, and control it. What changes is the input. An agent runs the process through recorded architecture decisions, about the model, the instruction, retrieved knowledge, tools, orchestration, memory, and autonomy, and each of those decisions, alone or in combination, creates the possibility of harm. The output of the assessment is a set of risk scenarios with a control objective for each.

AI certification: what exists and what it proves

Analysis

AI certification is not one category. Three different objects are assessed, each by a different kind of assessor: a person, an organization's AI management system, and an AI system placed on the EU market. The first two can be certified. The third is subject to a legal conformity assessment, which produces a certificate on one of its two routes and none on the other. Identifying which object a credential covers is the first step to judging what it is worth.

AI governance and enterprise risk management: where they meet

Analysis

AI governance is not a parallel structure that sits beside enterprise risk management. It belongs inside it. The seven pillars of responsible AI are the control structure the organization uses to govern each AI system; enterprise risk management is the machine that carries the residual risk those controls leave behind into the board's risk appetite, the risk register, and the assurance plan. The practical question is not whether to build AI governance or ERM, but how to slot the first into the second so that one accountable structure, not two competing ones, owns AI risk.