Starting point

The AI Act does not only concern AI vendors. A mid-market company can be the provider of a system embedded in a product, the deployer of an HR tool, the distributor of a solution or the user of a general-purpose model — in ways that change its responsibilities.

1. Build the inventory that is usually missing

The inventory connects the system, its purpose, the people affected, the supplier, the models used, the data, the decisions produced and the company's legal role. It includes the AI functions embedded in SaaS already purchased and the business experiments.

2. Qualify without labelling everything "high risk"

Qualification distinguishes prohibited practices, transparency, general-purpose AI models, high-risk systems and uses that fall outside these categories. The conclusion must be dated, argued and reviewed whenever the purpose, the model or the supplier changes.

ProhibitedStop or exclude the use
High riskReinforced requirements and conformity
TransparencyInform, mark or document
Limited riskProportionate governance

3. Connect legal, data, cyber and business

A workable file covers data quality and governance, documentation, logs, robustness, security, human oversight, information, incidents and monitoring in production. These responsibilities must join the product lifecycle rather than a separate binder.

4. Control suppliers and general-purpose models

Contracts and purchasing processes must make it possible to obtain the useful documentation, the known limits, model changes, the conditions of use, cooperation in case of incident and the elements needed for the company's own role.

5. The output of an AI Act framing

The first deliverable is not a generic declaration of conformity: it is a prioritised register of systems, a role matrix, a risk qualification, the applicable deadlines and a governance plan with expected evidence.

Assess your AI Act situation Frame your AI governance