aistack
Book consultation →
← All articles
AI Regulation

Getting AI Act ready: a practical implementation plan for companies

Six steps from an AI inventory to human oversight and an audit trail. Concretely what you must do yourself, and where the right infrastructure does half the work for you.

July 2026·13 min read·Milan Janoštík·
AI ActRegulationGovernance
Editorial infographic: source systems on the left, an identity gate with a lock and a human-oversight node in the centre, and an audit ledger on the right whose rows fill in one by one.

In the first part we described what the AI Act asks and who it applies to. Now the question is how to become ready, without waiting for lawyers or for the deferred deadlines to arrive. Readiness breaks down into six steps that even a company with no compliance department can handle. For each step we say plainly what you must do yourself, and where half the work is saved by how your AI is built.

Step 1: Take an inventory of your AI

You cannot govern what you do not know about. The first step is therefore a list of every place where some AI runs in your company. It is not only the tools you deliberately deployed. It is also AI hidden in things you already use: in the CRM, the accounting system, the email client, the recruiting software. And above all it is so-called shadow AI: tools employees switched on themselves, without management knowing, and are feeding company data into.

A hidden trap
Shadow AI is the biggest blind spot
An employee who pastes customer data into a random tool in their browser creates a risk that nobody approved and nobody sees. An inventory that misses shadow AI is incomplete. The surest defence is not a ban, but offering people one approved, governed way to use AI.

Step 2: Classify each system by risk

For each item on the list, answer one question: what is the system used for. Not what it can do, but what you actually let it do. That places it into one of the four risk tiers. For the vast majority of tools the answer is minimal risk and you are done. For a few, transparency or high risk appears, and that is where all your attention goes.

Ask yourselfIf yes, it points toward
Does the system talk directly to a customer, or create content?Transparency under Article 50
Does it decide on hiring, creditworthiness, insurance or access to a service?High risk (Annex III)
Does it profile specific individuals?High risk, always
Does it only help internally, with no effect on people’s rights?Most likely minimal risk
Data flow: company systems → identity gate → human oversight → audit ledger

Step 3: Meet the deployer duties

If you are only a system’s user (deployer) and the system is high-risk, the law asks specific but manageable things of you. These are not a model maker’s duties; they are lighter and can be built into ordinary operation.

  • Use the system according to the provider’s instructions, not outside the scope it was meant for.
  • Ensure that a competent person with the authority to intervene oversees its output.
  • Monitor how the system performs and report serious incidents to the provider and the authority.
  • Keep operating logs for the period the law requires.
  • Inform the people affected by the system’s decisions, and in some cases the employees concerned.

Step 4: Human oversight that is more than a rubber stamp

Human oversight is the heart of the whole regulation, and also where companies most often only pretend. Oversight does not mean a person blindly clicks through whatever the AI suggested. It means a person understands the output, can see what it was based on, and has a real chance to change or reject it. For that to work, a decision has to be stoppable before it becomes a fact, not after it turns out to have been wrong.

In practice that means building processes so the AI prepares and a person approves. Claude can read a contract, flag a risk and draft a reply. Signing it, sending the payment or hiring the candidate has to be a person. Access to data and the right to act are two different things, and a ready company keeps them separate.

Step 5: Transparency and AI literacy

Two duties reach almost every company regardless of risk. Transparency: where a chatbot talks to people, it must be clear that it is a machine, and content made by AI must be labelled. AI literacy: the people working with AI must know what the tool can do, where its limits are and when to verify its output. Both are achievable without large cost, but you have to do them and be able to show that you did.

Step 6: The audit trail and governance

The last step holds all the previous ones together. It must be traceable who asked what, what data they had for it, and what the system answered. Without that you cannot demonstrate either human oversight or use within the rules. And someone in the company has to own it, whether that is one person or a small group. Governance without a clear owner is just a document in a drawer.

AI without governance
  • Data in random tools and personal accounts
  • Nobody knows who asked what
  • No audit trail, no permission boundaries
  • Human oversight only on paper
Governed AI infrastructure
  • Data stays on your infrastructure
  • Every query carries the user’s identity
  • The audit trail is created automatically
  • Human approval is built into the process

Where infrastructure does half the work for you

Now let us bring it together. A large part of the AI Act duties is not about documents but about technical architecture. When AI is built the right way, many requirements are met on their own, because they are baked into how the system works. The table below shows where infrastructure takes work off your plate, and honestly, where it does not.

AI Act dutyHow the right infrastructure eases it
Human oversight of decisionsA person in the loop is built into the process: AI prepares, a person approves
Controlling and evidencing data accessAn MCP server carries the user’s identity: the system sees only what that person can
An audit trail of operationEvery query and answer is logged automatically, one trail for the whole company
Control over data and where it sitsRunning on your cloud, data is not stored in someone else’s cache
Repeatable, evidenced processesA skills library keeps procedures versioned and available under permissions
Risk classification, staff training, informing the affectedHere infrastructure is not enough; this stays with people and process
An honest boundary
Infrastructure removes friction, it does not replace decisions
AI built the right way gives you the audit trail, permission control and human oversight almost for free, because they are part of the architecture. It does not replace classifying systems by risk, training people, or deciding who owns what. Anyone claiming that one tool makes you compliant is overselling.

A special case: the fundamental-rights impact assessment

For some high-risk deployments, typically public bodies and services such as banking or insurance, the law additionally asks for a fundamental-rights impact assessment (FRIA). It is a structured look at who the system might harm and how, and how to prevent it. If your deployment does not fall into this category, this step does not apply to you. If it does, it is better prepared ahead of time than under deadline pressure.

Common pitfalls you can avoid

  • Relying on high risk being deferred and doing nothing. Preparation takes months, not days.
  • Forgetting AI literacy and transparency, because they apply regardless of risk and already now.
  • Leaving human oversight only on paper while a person merely clicks approve.
  • Re-labelling someone else’s system with your name or changing it substantially, without realising you became a provider.
  • Treating the AI Act as a one-off task. It is ongoing operation, not a stamp.

How we help with it

Our role is clearly bounded and honest. We do not cast ourselves as a law firm. We build the technical foundation readiness stands on, and we help you map where you are and what you are missing.

  • We build AI infrastructure on your cloud, with data under your control and one audit trail.
  • We connect AI to your systems through MCP servers that carry a specific user’s identity and permissions.
  • We set processes so a person keeps the final word on sensitive decisions.
  • We go through the inventory and risk classification with you and say where you are ready and where you are not.
The offer
A readiness mapping, plus the foundation it stands on
A short piece of joint work, at the end of which you know which of your systems fall where, what you already have and what you are missing. Plus infrastructure that meets the larger part of the technical requirements through how it is built. Compliance stays yours; we remove the friction.

In the third part you will find a finished readiness checklist and answers to the questions companies most often ask us about the AI Act. If you want to talk through what implementation would look like in your case, write to us. We start from where you stand today, not from general advice.