The Week in One Line

EU AI Act compliance is not a one-time audit exercise. It is an ongoing operational process built around visibility, ownership, oversight, and documented accountability.

What the Act Actually Says

For deployers of high-risk AI systems, the obligations under Article 26 are continuous operational requirements.

They apply throughout the entire lifecycle of the deployment.

Most compliance failures will not come from intentionally harmful AI deployments. They will come from organisations lacking:

• documented ownership • escalation processes • monitoring visibility • operational controls • evidence trails

The core operational requirements include:

Use the system according to provider instructions

In practice, this means:

• documented onboarding • defined approved use cases • internal usage controls • records of deployment scope

Assign meaningful human oversight

Article 26(2) requires a named person with:

• authority to intervene • sufficient competence and training • practical ability to override outputs • escalation responsibility

An org chart alone does not satisfy this requirement.

Retain logs for at least six months

Article 26(6) requires retention of automatically generated logs.

Operationally, companies need to know:

• whether logs exist • who can access them • where they are stored • how retention is managed • whether they can be produced during investigation or audit

Monitor the system’s operation

Monitoring is an active obligation.

If a high-risk system behaves unexpectedly or creates risk, deployers are required to suspend usage and notify relevant parties where necessary.

Conduct a Fundamental Rights Impact Assessment where required

Article 27 applies to certain deployers, including some financial, insurance, and public-service contexts.

If applicable, the assessment must be completed before deployment.

Source: artificialintelligenceact.eu – Article 26, Article 27

What This Means for Your Business

The clearest way to evaluate operational readiness is to ask five questions for every high-risk AI system currently deployed:

• Who is the named human overseer, and what authority do they have to intervene?

• Where are the automated logs stored, and can we retain them for six months?

• What monitoring and escalation process exists if the system behaves unexpectedly?

• What documentation records the classification rationale, intended use, and provider restrictions?

• Has a Fundamental Rights Impact Assessment been completed if required?

If those questions can only be answered with assumptions, verbal explanations, or scattered documents, the governance process is probably immature.

Good compliance is not primarily about producing policies.

It is about operational ownership.

Most organisations still do not have:

• complete AI inventories • assigned system owners • central oversight visibility • incident escalation workflows • documented classification rationale

That is where the real implementation work now sits.

This Week’s Action Point

Assign a named owner for every high-risk AI system your company currently deploys.

Not a department. Not a committee. A person.

That owner should be responsible for:

• classification documentation • oversight processes • log retention • monitoring coordination • escalation handling • vendor coordination

Write the ownership structure down in a format a regulator could review.

That single operational step becomes the foundation for almost every other deployer obligation under the Act.

Further Reading

Article 26 – Deployer Obligations: artificialintelligenceact.eu/article/26

Article 27 – Fundamental Rights Impact Assessment: artificialintelligenceact.eu/article/27

Small Business Guide to the EU AI Act: artificialintelligenceact.eu/sme-guide

European Commission AI Framework: digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

This concludes the first six-edition series of EU AI Act for Business.

If the series has been useful, share it with someone inside your organisation responsible for AI, compliance, procurement, HR, governance, or operational risk.

Most companies still have more AI deployed internally than they currently have governance visibility over.

Next Tuesday: The Omnibus Explained: what changed, what did not change, and why the timeline extension is not a reason to pause compliance work.