How to navigate the AI Act: Back to the Basics
Does your organisation work with AI systems, or technologies that function like them? If so, you may be navigating a web of compliance obligations under the AI Act. These obligations can vary depending on your role and the type of risk classification your AI system falls under.
This blog mainly focuses on the first step towards AI compliance, defining your system. AI is used to describe various levels of automation, but not all cases of automation qualify as AI under the AI Act. After defining your system, this blog will introduce the next steps: risk classification, role determination and compliance obligations.
Step 1: Defining your System
Article 3(1) of the AI Act contains seven elements that must be present at some point of the AI’s lifecycle for it to be seen as an AI system under the Act.
An AI system is understood as the following in article 3(1) of the AI Act:
When talking about what counts as an AI system under the AI Act, the definition spans two stages: the pre-deployment (building) phase and the post-deployment (use) phase of the system. Some parts of the definition only need to be in place during the build phase, while others might only appear once the system is in operation. This makes a periodic evaluation of the AI system as a whole a necessary step.
Further steps:
Step 2: Risk Classification:
The second step to AI Act compliance is to determine what risk classification your AI system falls under. The AI act prescribes a tiered classification of prohibited (e.g. credit scoring), high-risk (e.g. product/sectoral or certain use-case categories), low risk (e.g. some chatbots) or minimal risk (e.g. some spam filters). To be able to classify each AI correctly, companies need to have a thorough understanding of their AI and its application.
Step 3: Role Designation
The third step to AI Act compliance is knowing your role in relation to the AI system, as this determines which obligations apply. You will need to identify whether you are a provider, deployer, importer, distributor or manufacturer and be aware that your role can change over time. One example is a company that buys an AI system (deployer) and becomes the provider if it places its own trademark on it. The AI Act allows for importers, distributors and manufacturers to become providers in certain cases.
Step 4: Compliance Obligations
After establishing that your system is an AI system, which risk classification it falls under and which role you have, then comes the fourth step, compliance obligations. The AI Act is complex in the sense that different obligations apply to different risk classification and different roles. Most obligations pertain to providers of high-risk AI systems. These can be found in Section 2 of the Act and vary from simple record-keeping obligations to more intricate quality management systems and post-market monitoring.
Conclusion
This blog details four steps in order to be on the road towards AI Act compliance. However, there are more steps in the pipeline of compliance. Implementing, monitoring, evaluating are just some of them.
If you are doubtful about whether your system might be an AI system or already know that you have an AI system but need guidance for the other steps, Considerati is equipped with the knowledge to advise and guide you towards AI Act compliance!
Our services ContactRecente blogs
18-07-2025 – The European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) recently issued a Joint Opinion on the European Commission’s…