Guide · 1 min read

The EU AI Act in practice: a buyer's checklist for high-risk systems

A practical checklist for organisations deploying or procuring AI systems that may be high-risk under the EU AI Act — inventory, classification, oversight, and evidence.

Dr Amara OkaforPartner, Run Governance

The EU AI Act is now enforceable in stages, and the obligations for high-risk systems are concrete. This checklist is what we use at the start of every governance engagement.

1. Inventory

List every AI system in use or procurement, including embedded features in SaaS products. Record purpose, data, affected people, and owner.

2. Classify

For each system, determine whether it falls into a prohibited, high-risk, limited-risk, or minimal-risk category. Credit scoring, employment decisions, essential-services access, and safety components are the common high-risk triggers.

3. Assign obligations

Deployers and providers have different duties. If you customise or materially change a system, you may become a provider.

4. Design oversight

Human oversight must be meaningful: someone with the authority, information, and time to intervene. Design it into the workflow.

5. Log and document

Technical documentation, logging, and record-keeping are explicit requirements. Start the evidence pack before go-live.

6. Monitor

Post-market monitoring is an obligation. Continuous evaluation and incident handling are the operational answer.

Get two articles a month and one report a quarter. No hype.

Dr Amara Okafor

Partner, Run

Amara leads Governance, Risk & Operations. She holds a PhD in machine learning robustness, advised the drafting of sector guidance under the EU AI Act, and runs our AI red-teaming programme.

LinkedIn

Find out where AI will pay off first.

A 30-minute discovery call, or the 5-minute readiness assessment. Either way you leave with a next step.