This text is for general information only. It does not constitute legal advice or a recommendation for any specific factual situation.
From risk classification to operational responsibility
The AI Act is not only a legal-team regulation. In practice, it affects product, procurement, security, data, technical documentation and customer communication. The first step is to determine what the system is, which party acts as provider, deployer, importer or distributor, and whether the solution may fall into the high-risk category.
What to check before deployment
- the purpose of the system and actual use,
- data sources and dependency on external models or suppliers,
- documentation, information and oversight requirements,
- contractual allocation of responsibility,
- post-deployment monitoring procedures.
A proper assessment should not stop at labelling something as “AI”. It should identify concrete actions required before purchase, implementation, customer deployment or internal use.
Sources
Regulation (EU) 2024/1689: EUR-Lex.