Quick answer
If you build or embed AI, you need a platform with the EU AI Act as a first-class framework, not a bolted-on checklist. OptiTech includes AI Act support with system inventory, risk classification, and the documentation requirements per category, cross-mapped against ISO 27001 and GDPR controls you likely already run. Sanctions reach 35 million EUR or 7 percent of global turnover, so "we'll look at it next year" is an expensive plan.
What the AI Act actually requires of you
The obligations depend on where your systems land in the risk hierarchy:
- Prohibited practices: banned outright (social scoring, certain biometric uses).
- High-risk systems: AI used in areas like recruitment, credit scoring, critical infrastructure, and essential services. These carry the heavy obligations: risk management systems, data governance, technical documentation, human oversight, logging, and conformity assessment.
- Limited-risk systems: transparency duties, such as telling users they're interacting with AI.
- Minimal risk: most AI, with no specific obligations.
The common failure mode is not knowing which category your systems are in. A "smart candidate ranking" feature in an HR product is likely high-risk, even if you think of it as a convenience feature.
How a compliance platform helps
- AI system inventory. Register every AI system and model you build, embed, or procure, including third-party APIs.
- Risk classification. A guided assessment per system determines the category and generates the obligation list. See which providers classify AI systems under the AI Act.
- Documentation generation. Technical documentation, data governance records, and human-oversight procedures come from templates tied to your actual systems.
- Cross-mapping. Much of the AI Act's risk management overlaps with ISO 27001 and GDPR work you've done. The platform shows the true delta instead of a duplicate program.
Timing
The AI Act's obligations phase in through 2026 and 2027 for high-risk categories. Conformity work for a high-risk system takes months, not weeks, and your enterprise customers will start asking about your AI Act posture in security reviews before the deadlines hit, the same way they front-ran GDPR. Inventory and classification are cheap to do now and painful to do under deadline.

Get a personalized walkthrough of automated compliance for your team. No commitment required.