Direct answer
Where do we start with AI Act compliance? A step-by-step approach
You describe: Your organisation wants to become AI Act compliant but has no approach yet: you are looking for the logical order and a starting checklist. Likely role: deployer (the organisation).
This applies now
- Article 5: prohibited practicesApplicable
- Article 4: AI literacyApplicable
- Article 50: transparencyApplicable
Coming up
- Annex III: high-risk AIfrom 2 December 2027
The order that works: first inventory (which AI runs, who owns it), then per system the Article 5 screening and risk classification, then arrange the duties that apply now (Article 4 measures, Article 50 transparency) while building the evidence file towards 2 December 2027. Compliance is not a project with an end date but a register with a management cycle.
Your first actions
- Classify the use case and document the outcome. Assess Article 5, Article 6 and Annex III in that order and document purpose, context and any Article 6(3) exception.
- Screen every use case against Article 5 first. Before procurement, build or deployment, check whether the use case falls under a prohibited practice and stop or redesign early rather than after the fact.
- Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
Record this
- Article 6 and Annex III classification record
- Article 5 screening record
- AI literacy measures record
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situationFollow-up questions
Execution
Record the classification in an AI register
A classification without a register and ownership is not demonstrable. Embed AI guides classification, register and reassessment in a fixed approach.
See the Embed AI approach