The EU AI Act is not a future obligation — it is in force, and its requirements touch the majority of mid-sized and large companies using AI in customer-facing or HR processes. Most companies are still at a governance maturity level where requirements are unknown, no AI registry exists, and high-risk systems have not been identified.
The first stage is a central AI registry: a list of all systems, processes and models using AI that are in production or pilot. This is the foundational requirement for almost everything else. For most companies the registry is a surprise: the assessment produces 30–80 separate systems, even when leadership expected "a few". This is good news — now what has to be managed is visible.
Each system in the registry receives a risk classification per the EU AI Act: prohibited, high-risk, limited-risk, minimal-risk or general-purpose AI (GPAI). This classification determines the documentation, controls and monitoring the system needs. A good risk classification is applied automatically to new use cases at portfolio-scoring time, not only at production deployment.
For high-risk systems the EU AI Act mandates technical documentation covering model purpose, training data, performance metrics, risk assessment, usage limits and possible harms. In practice this is a 10–30 page model card. AI-Koutsi provides ready model-card templates pre-populated from use-case metadata — instead of writing each section by hand.
Systems processing personal data require a Data Protection Impact Assessment (DPIA). High-risk systems often require human oversight (HITL — human in the loop), meaning critical decisions pause for a human review. In production, monitoring is mandatory: bias detection, model performance drift, breaches of usage limits. This monitoring has to be logged and retained.
Governance does not work without an organization. A typical structure includes an AI Officer (or equivalent), a risk committee or broader AI steering body, and for every high-risk system a named business owner and a named technical owner. The decision process has to be documented: who approves a new high-risk system into production, who decides on shutdown if a control fails, who reports incidents to the authority.