Cookies & Privacy

We use cookies to keep the site working, understand how it is used and improve your experience. You can accept all or choose which ones to enable.Cookie Policy.

Back to Insights

Compliance · June 15, 2026

AI Act Readiness: from AI Inventory to Governance and Evidence

Share

AI Act readiness starts with knowing what AI exists, why it is used, what risks it creates and where the evidence sits.

Overview

AI Act readiness is often discussed as a legal project. In practice, it is a governance, data and evidence project. Legal interpretation is essential, but it becomes actionable only when each AI use case is identified, classified, controlled and documented.

The EU AI Act establishes a risk-based framework and creates obligations for developers and deployers of certain AI systems. The European Commission has emphasized that the Act addresses risks to health, safety and fundamental rights while providing clear requirements for specific AI uses. For organizations, readiness means translating those requirements into an internal operating model.

The first deliverable is an AI inventory. Without it, no organization can reliably classify risk, assign accountability, assess data, manage suppliers or prepare documentation.

Step 1: build the AI inventory

An AI inventory should capture more than tool names. It should record business purpose, process, owner, provider, model type, data sources, user group, decision impact, third-party dependencies, deployment status and evidence repository. It should also identify whether a use case involves customer interaction, employee evaluation, credit, fraud, compliance, cybersecurity or other sensitive areas.

The inventory must cover embedded AI in vendor tools as well as internally developed systems and employee-facing generative AI tools. Procurement should therefore be connected to AI governance. New platforms should not enter the organization without an AI impact screening.

Step 2: classify risk and obligations

Risk classification should be repeatable. Each use case should be assessed against intended purpose, impact on individuals, level of automation, data sensitivity, sector rules, user controls and potential harm. The output should be an approved classification with rationale, not an informal judgment.

The classification drives the control model. Lower-risk productivity use cases may require user guidance, access control and data safeguards. High-impact use cases may require stronger documentation, human oversight, performance testing, logging, supplier controls, incident processes and post-deployment monitoring.

Step 3: connect controls to evidence

Controls are useful only if they can be evidenced. For AI systems, evidence may include risk assessments, approvals, data lineage, testing results, monitoring reports, user instructions, logs, human-review procedures, vendor documentation, model cards, change records and incident registers.

Organizations should define a minimum evidence pack for every material AI system. This pack should be accessible to internal audit and governance bodies. It should also be maintained over time as systems change. AI governance is a lifecycle discipline, not a one-time approval.

Step 4: define governance routines

AI governance requires routines: intake reviews for new use cases, periodic inventory refreshes, risk reclassification after material changes, exception management, supplier reviews and management reporting. Governance bodies should include business, IT, risk, compliance, legal, cybersecurity and data management perspectives.

The board or executive committee should receive concise reporting on AI exposure: number of systems, risk distribution, open gaps, incidents, third-party dependencies, high-risk assessments and remediation status. This creates accountability and helps avoid fragmented adoption.

Step 5: prepare for continuous change

AI systems change quickly. Models are updated, use cases expand, vendors modify features and users discover new ways to apply tools. Readiness therefore requires change management. A system that was initially low-risk can become higher impact if it is used in a new context.

The organizations most likely to succeed will treat AI readiness as part of enterprise governance. They will know what AI they use, why they use it, what risks it creates, what controls exist and where the evidence is stored.

Our Approach

  • Inventory Build - Create a structured AI register covering internal, vendor and employee-facing AI use cases.
  • Risk Classification - Apply a repeatable classification model aligned with AI Act risk logic and sector-specific expectations.
  • Evidence Pack Definition - Define mandatory documentation and evidence for each material AI system.
  • Governance Routines - Implement intake, approval, periodic review, exception handling and management reporting.
  • Audit Readiness - Prepare documentation, dashboards and traceability for internal audit, clients and supervisory review.
Share

Talk to us

Discuss this topic with our team

Contact Us