Back to blog
Compliance
12 min read

How to prepare your organisation for the EU AI Act

The EU AI Act is being progressively enforced. Here are the concrete steps to bring your organisation into compliance before the first penalties.

SP

Steve P.

Research, Hikari Blue · March 1, 2026

The EU AI Act is the world's first comprehensive regulatory framework for artificial intelligence. Effective since August 2024, it imposes increasing obligations based on the risk level of your AI systems.

What changes concretely

For companies deploying AI agents in production, three major obligations are emerging:

1. Risk classification

Each AI system must be classified into one of four categories: minimal, limited, high, or unacceptable risk. Agents that make decisions impacting people (HR, finance, healthcare) typically fall into the "high" category.

2. Mandatory audit trail

From 2027, every high-risk AI system must maintain an immutable audit log tracing every decision. This isn't a nice-to-have, it's a legal obligation with fines up to €35 million.

3. Human oversight

High-risk systems must allow human intervention at any time. This is exactly what a properly implemented Kill Switch enables.

Preparation steps

Phase 1: Inventory (now)

Map all your AI systems in production. For each, identify the risk level and data processed.

Phase 2: Assessment (Q2 2026)

For each high-risk system, conduct a documented conformity assessment.

Phase 3: Implementation (Q3-Q4 2026)

Implement necessary controls: audit trail, human oversight, technical documentation.

Phase 4: Continuous monitoring (2027+)

Compliance isn't a fixed state. It requires permanent monitoring.

Why act now

Companies waiting for the first penalties to comply will face a double cost: the fine itself and the cost of emergency compliance. Those who anticipate turn regulatory constraints into competitive advantage.

Ready to structure your AI governance?

Talk to our team