
The European Union’s AI Act is the world’s first comprehensive framework to regulate artificial intelligence. Adopted in 2024 and set to apply fully by 2025–2026, this landmark regulation aims to ensure AI systems are safe, transparent, and trustworthy across all sectors. It applies broadly to organizations that develop, deploy, or use AI in the EU – not just tech companies or regulated industries. In practice, that means any company leveraging AI (from startups to global enterprises) will need to understand their AI systems’ risks and comply with new rules.
By mid-2026, organizations offering or operating AI in Europe must be able to demonstrate compliance with the AI Act’s requirements. Achieving this is not just about avoiding penalties – it’s about fostering trust in AI solutions, preventing harm, and aligning AI innovations with ethical and legal standards. In short, the AI Act will soon set a common baseline for “trustworthy AI,” and businesses need to prepare now to integrate these requirements into their products and operations.
Key Requirements Under the AI Acts
The AI Act introduces a risk-based approach to AI governance, along with specific obligations that organizations must fulfill. Below is an overview of what your organization will need to do under the AI Act, spanning risk classification, documentation, governance, oversight, transparency, and data safeguards.
- Risk-Based Classification of AI Systems
All AI systems must be evaluated and classified by risk level. The Act defines four tiers: Unacceptable-risk AI (prohibited outright, e.g. exploitative or social scoring systems), High-risk AI (allowed but heavily regulated), Limited-risk AI (lighter rules, mainly transparency), and Minimal-risk AI (freely permitted). In practical terms, this means identifying if any of your AI applications fall under banned practices (such as manipulative AI or certain biometric surveillance) or high-risk use cases. High-risk AI covers areas like safety components in machinery, hiring or credit scoring systems, law enforcement tools, and other applications that can significantly affect people’s safety or rights. These will require strict compliance steps (described below), whereas limited-risk AI (e.g. chatbots, generative AI outputs) mainly requires transparency measures, and minimal-risk AI (the majority of AI like spam filters or AI in video games) has no special obligations. Understanding where each of your AI systems fits in this taxonomy is the first crucial step – it determines which requirements apply. - Technical Documentation and Record keeping
Providers of any high-risk AI system must prepare comprehensive technical documentation and maintain logs to ensure traceability and accountability. The AI Act mandates detailed documentation describing the system’s purpose, design, and performance, sufficient for authorities to assess compliance. This includes information on the model’s algorithms, training data, testing processes, and risk management measures. Organizations will need to establish robust recordkeeping: automatically logging the AI system’s activities and outcomes to enable audits and investigations if something goes wrong. In short, if you deploy a high-risk AI, you must document “what it is and how it works” in depth and keep evidence of its operation. This documentation and logging are not just bureaucratic exercises – they ensure transparency in how decisions are made and provide a paper trail to prove you’ve managed risks properly. - Governance and Human Oversight
The AI Act expects organizations to exercise strong internal governance over AI and not rely on algorithms without control. Concretely, you must implement an AI risk management system and integrate AI oversight into your corporate governance. High-risk AI systems require adequate risk assessment and mitigation processes throughout their lifecycle. Companies will need to update or create policies for AI, assign clear responsibilities (for example, an AI compliance officer or committee), and ensure human oversight of AI decisions. The Act insists on appropriate human oversight measures for high-risk AI – meaning humans should be able to monitor, intervene in, or ultimately control the AI system, especially in sensitive use cases. Your organization should designate qualified staff to review AI outputs and manage any potential issues or biases. In essence, AI can’t be a “black box” running on auto-pilot – you must govern it actively, with humans in the loop and accountable for outcomes. This governance extends to maintaining an internal quality management system for AI (similar to how one would manage product safety or information security) to continuously evaluate and improve the AI’s compliance and performance. - Transparency and User Communication
To maintain trust, the AI Act introduces specific disclosure requirements for certain AI systems. For AI applications that directly interact with people or generate content, organizations must inform users about the AI’s involvement. For example, if a customer is chatting with a bot, they need to be made aware they’re interacting with a machine (not a human). Likewise, AI-generated content (such as deepfake images or AI-written text in a news context) must be clearly labeled as AI-generated. These obligations apply to so-called limited-risk AI systems. Transparency is also relevant for high-risk AI: providers must give clear and understandable information to the users or deployers of those systems about how to properly use the AI, its limitations, and any necessary precautions. In practice, your organization should prepare user notices or summaries that explain the AI system’s nature, and embed transparency (like visible labels or disclaimers) wherever an AI system could be mistaken for human or could significantly influence user decisions. These measures ensure people are not deceived or kept in the dark when AI is impacting them. - Data Quality and Data Governance
The quality of data that feeds your AI systems is a major focus of the AI Act. Training, validation, and testing datasets must be high-quality, meaning they should be relevant, representative, and free from errors or biases as much as possible. This is critical for high-risk AI, where poor data can lead to discrimination or unsafe outcomes. Organizations will need to put in place data governance practices for AI, such as procedures for dataset selection, bias detection and mitigation, and data provenance tracking. The Act explicitly requires steps to minimize the risk of biased or discriminatory results – for instance, if you develop an AI for screening job applicants, you must guard against training data that skews results unfairly against certain groups. Ensuring data integrity also means keeping data secure and up-to-date. Many companies find this challenging because it demands interdisciplinary effort: data scientists, domain experts, and compliance officers must work together to curate datasets and document their attributes. Nonetheless, under the AI Act, demonstrating robust data management and validation is mandatory – it’s how you prove your AI is reliable and respects fundamental rights. In summary, organizations should treat data as a regulated ingredient of AI, with quality controls similar to those in product manufacturing or clinical trials.
Common Challenges in AI Act Compliance
Adapting to the AI Act can be challenging – not only because the law is new, but also because it spans technical, ethical, and organizational domains. Companies of all sizes may face hurdles such as.
- Interpreting New and Complex Requirements
The AI Act’s provisions are detailed and sometimes technical, which can make them difficult to translate into practice. Terms like “bias monitoring”, “traceability”, or “appropriate human oversight” require careful interpretation. Many organizations are unsure how to determine if an AI system is “high-risk”, or what exactly needs to be in a technical document. Unlike familiar regulations (e.g. financial or data protection rules), these AI-specific obligations are novel. This complexity means there’s a risk of either over-engineering a solution or missing critical requirements. Companies often need multidisciplinary understanding (legal, IT, AI modeling) to fully grasp the Act. Without expert guidance, simply figuring out what needs to be done – from categorizing an AI use case to applying the right standards – can be daunting. - Data and Bias Mitigation Difficulties
Ensuring data quality and algorithmic fairness is easier said than done. Many organizations struggle with identifying and removing biases in training data, or even obtaining sufficient data that is representative and free of errors. It can be technically complex to test an AI system for discrimination or to explain why a model made a certain decision. Moreover, addressing bias often requires significant changes – like retraining models or improving data collection – which can be resource-intensive. Smaller companies might lack the tools and expertise for robust data curation and testing. The Act, however, demands these issues be addressed, which means businesses must invest in new processes (e.g. bias audits, data annotation, model validation). Failing to do so not only risks non-compliance but can also harm a company’s reputation if an AI system produces unfair or harmful outcomes. - Resource and Expertise Constraints
Complying with the AI Act isn’t just a legal exercise, it’s an operational one – requiring skills and resources that some organizations have in short supply. For instance, implementing continuous monitoring, logging, and security for AI systems may require new infrastructure and talent (such as ML engineers or AI ethicists). Firms that are not already in highly regulated environments may find the conformity assessment and quality management aspects challenging – they might not have existing compliance teams versed in AI. There is also the cost factor: conducting rigorous testing (like stress-testing an AI model’s resilience or having independent experts review it) can be expensive. These constraints can be especially acute for startups or SMEs using AI. The risk is that organizations might try to cut corners, but under AI Act scrutiny, lack of preparation or under-investment in compliance could lead to project delays or enforcement actions. Building up the necessary capabilities (whether internally or with external support) is a common pain point. - Integrating AI Compliance into Existing Programs
Companies often already have governance frameworks for IT security, data protection (GDPR), or quality management – but plugging AI Act requirements into these frameworks can be complex. Overlaps and gaps need to be reconciled. For example, ensuring AI transparency and aligning it with GDPR’s transparency and fairness principles requires coordination between the AI team and the privacy/legal team. Many businesses risk treating AI compliance as a siloed effort, when in fact it should dovetail with broader risk management. Overlooking cross-framework alignment is a common pitfall, processes and controls for AI need to mesh with cybersecurity (like NIS2 requirements for critical systems) and with sector-specific rules if applicable. Achieving this integration can be organizationally difficult; it means updating multiple policies and getting different departments (IT, R&D, compliance, HR, etc.) to collaborate. Without a harmonized approach, companies might duplicate efforts or create inconsistent policies. A key challenge is thus to embed AI Act compliance into the “business-as-usual” governance structure, rather than handling it as an ad-hoc project. - Sustaining Compliance as a Continuous Process
Similar to other major regulations, the AI Act expects ongoing adherence, not a one-time checkbox exercise. This is challenging because it requires a cultural shift. Organizations will need to continuously monitor their AI systems post-deployment, keep documentation up to date as models evolve, and retrain or adjust systems as new risks or data issues are discovered. Treating compliance as a living, continuous process (rather than a one-off certification) is essential, but many companies struggle with maintaining that momentum. It’s easy to focus on getting compliant by the effective date, only to let practices lapse afterward. Regulators, however, will want to see that you have permanent routines – like periodic audits, incident reporting procedures, and a plan for updating AI systems or even withdrawing them if they no longer comply. Building this kind of proactive compliance culture is no small task, especially in the fast-moving AI field where systems can change through updates or new data. Organizations must plan for the long haul: compliance should be ingrained in model development life cycles and product management, with clear ownership and accountability at the executive level.
Frequently asked questions
What does the AI Act mean for organisations using AI?
The AI Act is the EU risk-based framework for artificial intelligence. A practical first step is to map AI use cases, clarify the organisation role, and identify requirements for governance, documentation, transparency and risk management.
Which AI systems may require additional control?
AI systems may require additional control when they are used in contexts that can affect safety, rights, employment, education, critical infrastructure or other regulated activities. The assessment should consider the use case, risk level and organisational role.
Do we need an AI policy?
An AI policy is often a useful starting point. It should define acceptable use, responsibilities, risk assessment, information security, data protection, supplier requirements and how AI systems are monitored over time.
How does the AI Act relate to GDPR and information security?
AI systems may process personal data and introduce risks to confidentiality, accuracy and traceability. AI governance should therefore be aligned with data protection, information security, risk management and supplier governance.
How should we start preparing for the AI Act?
Start with an AI inventory, classify use cases, assign ownership and assess risk. Policies, controls, training and monitoring can then be adapted to the AI systems actually used by the organisation.
Helping you to comply
Kristensson i Skåne AB is an independent consulting partner specializing in information security, IT governance, and regulatory compliance. Just as we have helped clients navigate other complex regulations (from financial ICT rules to data protection), we assist organizations across all sectors in becoming AI Act ready and building long-term compliance into their operations. Our support model addresses the challenges above through a structured yet flexible approach. We integrate AI Act compliance efforts into your broader risk, security, and compliance programs, ensuring that meeting the new requirements also strengthens your overall governance. Key elements of our AI Act compliance services include:
- AI Act Readiness Assessments & Risk Classification
We start by evaluating your current and planned AI systems against the AI Act’s criteria. This includes identifying which of your AI use cases fall into each risk category (unacceptable, high, limited, or minimal) and performing an impact assessment for high-risk systems. Our experts conduct a detailed gap analysis to see where you already meet the obligations and where there are shortfalls. You’ll receive a clear, prioritized roadmap of what needs to be done for each AI system – from technical measures to policy updates. This readiness assessment takes the guesswork out of compliance: we translate the legal requirements into concrete actions specific to your organization. By classifying your AI and pinpointing compliance gaps up front, you can focus your efforts on the areas of highest risk and importance. - Documentation, Technical Controls & Policy Implementation
Kristensson provides hands-on support to develop all required documentation and technical safeguards for AI Act compliance. We help you compile the comprehensive technical documentation needed for high-risk AI systems – covering system descriptions, intended uses, algorithms, training data details, risk controls, and more. Our team will also assist in implementing technical measures such as logging and monitoring mechanisms (to record AI system outputs and performance), access controls for AI models and data, and validation/testing protocols to ensure your AI remains within acceptable parameters. In parallel, we work with you to update or create internal policies and procedures governing AI. This can include AI development guidelines, ethical AI principles, data management procedures for AI datasets, and incident response plans specific to AI-related incidents. The goal is to embed AI risk controls into your existing processes. All documentation and controls we help put in place are tailored to your organization and aligned with the Act’s strict requirements – making sure that if regulators examine your AI system, you have a solid paper trail and effective safeguards to show them. We strive to make the burden of documentation as light as possible by using templates and best practices, while still meeting all regulatory expectations. - AI Governance Framework & Alignment with Standards
Compliance is not just about point-in-time fixes, it requires a governance framework that oversees AI on an ongoing basis. We assist in establishing an AI governance structure within your organization, or integrating AI oversight into your existing governance bodies (such as risk committees or IT governance forums). This involves defining clear roles and responsibilities for AI risk management – for example, assigning who reviews and signs off on AI deployments, and how issues are escalated. We ensure your AI governance aligns with and complements other frameworks: whether you already follow ISO/IEC 42001 (the new AI management system standard) or plan to, we help map the AI Act requirements to that structure (ISO 42001 provides a systematic approach to AI risk, which can directly support meeting the Act’s obligations). We also consider intersections with NIS2 (for cybersecurity) and GDPR (for data privacy), so that your controls for AI do not conflict with, but rather enhance, your broader compliance posture. For instance, we’ll check that your AI transparency notices also satisfy GDPR transparency duties, or that your AI incident response ties into your general incident response plan. Our philosophy is that AI Act compliance should reinforce your overall risk and security management – not exist in a vacuum. We guide you in building a unified governance framework where AI risks are managed alongside other operational and IT risks, enabling efficiency and consistency. This often includes updating corporate risk registers to include AI risks, integrating AI compliance checkpoints into project management and procurement, and training your governance teams on AI oversight. The outcome is that AI compliance becomes “business as usual” – baked into decision-making and oversight processes at all levels. - Ongoing Compliance Support & Audit Readiness
Meeting the AI Act requirements is not a one-and-done project, which is why we offer continuous support options to help you stay compliant over time. Regulations evolve, AI technologies change, and new use cases may arise in your business – we can act as a long-term partner to navigate these changes. Our team can provide periodic compliance health checks for your AI systems, help interpret new guidance or regulatory updates from the EU (such as future standards or adjustments to the Act), and ensure you’re prepared for any audits or assessments. If you plan to undergo formal conformity assessments or certification (for example, seeking an AI quality mark or ISO 42001 certification down the line), we will help you gather the necessary evidence and be audit-ready. We can also support in setting up internal audit programs for AI, or even serve as an independent assessor to test your controls. For organizations that prefer an ongoing engagement, we offer services like an “AI Compliance Officer as-a-service” – essentially, a retained advisor who continuously assists your team in managing AI-related compliance tasks and keeps you ahead of regulatory developments. On the other hand, if you just need occasional guidance, we can provide that too. Whether delivered as a defined project (to jump-start your compliance) or as ongoing advisory support, our services are always tailored to your needs. The ultimate goal is to ensure that your compliance effort is sustainable – that you don’t just satisfy the AI Act on paper for one moment in time, but maintain that compliance (and the trust of your customers and regulators) as your AI initiatives grow.
In summary, preparing for the EU AI Act can seem complex and demanding, but with the right approach it becomes an opportunity to strengthen your organization’s innovation and reputation. Kristensson i Skåne AB helps demystify the regulation and turn its requirements into practical steps that enhance your governance and risk management. We integrate AI Act compliance into the bigger picture of your business, covering not just the letter of the law, but the spirit of trustworthy AI. With expert guidance, you can not only meet the AI Act obligations by the 2026 deadline, but leverage them to build better, safer AI systems that benefit your customers and stakeholders.
If your organization is developing or using AI and you want to ensure compliance with the upcoming regulations, we are here to help. Feel free to contact us to discuss a tailored AI Act readiness plan, whether you need a one-time gap assessment, help with implementation, or a long-term partner in managing AI risk. Together, we can navigate the AI Act and help your business thrive in the era of trustworthy and responsible AI.
Selected official sources: European Commission: AI Act; EUR-Lex: Regulation (EU) 2024/1689.
