Guide · 1 min read
The EU AI Act in practice: a buyer's checklist for high-risk systems
A practical checklist for organisations deploying or procuring AI systems that may be high-risk under the EU AI Act — inventory, classification, oversight, and evidence.
The EU AI Act is now enforceable in stages, and the obligations for high-risk systems are concrete. This checklist is what we use at the start of every governance engagement.
1. Inventory
List every AI system in use or procurement, including embedded features in SaaS products. Record purpose, data, affected people, and owner.
2. Classify
For each system, determine whether it falls into a prohibited, high-risk, limited-risk, or minimal-risk category. Credit scoring, employment decisions, essential-services access, and safety components are the common high-risk triggers.
3. Assign obligations
Deployers and providers have different duties. If you customise or materially change a system, you may become a provider.
4. Design oversight
Human oversight must be meaningful: someone with the authority, information, and time to intervene. Design it into the workflow.
5. Log and document
Technical documentation, logging, and record-keeping are explicit requirements. Start the evidence pack before go-live.
6. Monitor
Post-market monitoring is an obligation. Continuous evaluation and incident handling are the operational answer.
Get two articles a month and one report a quarter. No hype.
Dr Amara Okafor
Partner, Run
Amara leads Governance, Risk & Operations. She holds a PhD in machine learning robustness, advised the drafting of sector guidance under the EU AI Act, and runs our AI red-teaming programme.
LinkedIn