Skip to content
Beyond Prompt AI Studio
The EU AI Act in Practice

The Practical Roadmap: AI Act Compliance in Five Steps

Eight modules, one goal: by the end of this course, you don't end up with a pile of disconnected facts, but a concrete roadmap. This final module bundles everything learned into five steps – from the first check to ongoing upkeep.

Four roadmap stages – worth remembering

Try it yourself: the five-step roadmap

Step 1

Inventory

List every AI system and check it against Art. 5/Annex III – write it down.

The roadmap in five steps

The following five steps build on each other and reference the specific modules in this course where they were covered in detail.

Step 1: Inventory

List every AI system in use and check it against the concrete lists from “The Risk Pyramid in Detail”: prohibited practices, Annex III categories, or “just” a chatbot or minimal risk. Write it down, don't just think it through.

Step 2: Clarify the role

For every system in the inventory, answer the role question from “Provider or Deployer?” – in particular checking whether your own brand, a substantial modification, or a change of purpose triggers an unnoticed provider role.

Step 3: Build competence and oversight

Introduce documented, role-tiered training following the pattern from “The AI Literacy Duty”. For high-risk systems, additionally implement real human oversight and – where applicable – a fundamental rights impact assessment per “Human Oversight and the Fundamental Rights Impact Assessment”. If there's a works council, it belongs at the table from the start, per “What This Means for Employees: Information, Co-Determination, Works Councils”.

Step 4: Implement labelling

Visibly label chatbots, AI-generated content, and deepfakes per “Transparency Obligations for Chatbots, Deepfakes & AI Content (Art. 50)”. Anyone using their own models, or even providing them, should additionally check the vendor or provider obligations from “If You Deploy or Provide Models Yourself: GPAI Obligations”.

Step 5: Stay audit-ready

Document all the results from steps 1–4 so they can be shown on request from the Bundesnetzagentur (see “Who Checks This? Enforcement, Fines, and the Bundesnetzagentur”) – including the six-month minimum retention of automatically generated logs.

Practice section: the roadmap is a living document, not a one-off project

The AI Act itself is still in motion – the high-risk deadlines for Annex III systems (December 2027) and embedded systems (August 2028) are still ahead, and the legal framework keeps being adjusted. So the roadmap doesn't belong in an archive – it belongs on a recurring review list: revisit it with every new AI tool, every substantial change to an existing system, and every new deadline. This classification doesn't replace case-by-case legal advice – for the concrete implementation in your own company, bring in a specialist.

The key points

  • Step 1: check every AI system's inventory against the concrete Art. 5/Annex III lists, and write it down.
  • Step 2: clarify the provider/deployer role for every system, especially the three unnoticed triggers of the provider trap.
  • Step 3: build documented, role-tiered training, real human oversight, a fundamental rights impact assessment where applicable, and early works council involvement.
  • Steps 4–5: implement labelling obligations and document all evidence so a Bundesnetzagentur audit isn't an emergency.
  • The roadmap is an ongoing process, not a one-off project – this classification doesn't replace case-by-case legal advice.

The EU AI Act: what companies really need to know – and what's just panic

Quick check: did it sink in?

1 / 3

According to the roadmap, what's the first step before anything else makes sense?

Want to implement this roadmap in your company with professional support?