Where Do You Stand Today?
Take an honest baseline first. Score each item from 0 (absent) to 3 (operational and evidenced). Inventory — do you have a current list of every AI system you build or deploy that touches the EU? Classification — for each, do you know its risk tier under the Act and why? Ownership.
Case Study: When the Fine Is the Smaller Problem
Consider any organization that has quietly embedded a general-purpose model into a customer-facing decision: credit pre-screening, candidate ranking, eligibility triage.
Build Your Scope-and-Role Register
This is the foundational artifact for everything that follows — spend an afternoon, not a fortnight. For every AI system you build, embed, license, or resell, capture one row: system name and one-line function (what it infers and what decision its output shapes), and whether it's in scope under the AI-system definition.
The Regulation as a Machine, Not a Manifesto checklist
- System name and one-line function — what it infers and what decision its output shapes.
- With a one-sentence reason.).
- EU nexus — Is it placed on the EU market, put into service there, or do its outputs reach EU users? Name the factor.
- Your role(s) — provider, deployer, importer, distributor, or more than one.
- Re-casting risk — Do you rename, rebrand, retrain, or repurpose it in a way that could make you a provider?
- Owner — the named person accountable, carried forward from the another chapter scorecard.
Case Study: One Tool, Four Different Compliance Bills
Consider a single high-risk creditworthiness model — a category Annex III covers for systems used to evaluate creditworthiness or establish credit scores — and how the same software generates four different obligation sets depending on who is holding it.