EU AI Act: what do you need to arrange now and how do you take the first step?

What do you need to do to comply with the EU AI Act in the near future? We are hearing this question more and more often. The law is final and will apply from June 2025. Active enforcement is expected starting June 2026. Therefore, organizations have less than a year to ensure that their AI systems comply with the new guidelines for risk, transparency, and supervision.
The law classifies every AI system into four risk levels and associates concrete obligations with them. Think of data quality, explainability, human control, and incident logging. For many teams, this means: first inventory, then adapt and document.
The challenge is not small. Models, data pipelines, and interfaces must be mapped out. Processes must be adapted without stagnating the business. This is precisely where experience makes the difference. At Koodin, we work with senior professionals who combine technology, governance, and team dynamics. They help you start today and be compliant tomorrow, without taking the momentum out of the product.
What exactly does the EU AI Act require?
The law divides all AI systems into four risk levels. Each level has its own requirements and corresponding controls:
Risk Level | Examples | Core Obligations |
Unacceptable | Social scoring, biometric surveillance in public spaces | Prohibited within the EU |
High | Health diagnosis, credit scoring, critical infrastructure | Data quality, risk assessment, CE marking, human supervision, incident logging |
Limited | Chatbots, AI customer support | Transparency: the user must know they are talking to an AI |
Minimal | Spell checkers, recommendation algorithms for newsfeeds | No extra obligations beyond existing legislation |
Fines can reach up to 35 million euros or 7% of global turnover in case of non-compliance. The higher the risk, the stricter the requirements. Since implementation takes 6 to 12 months on average, it is wise to start preparations now.
Where is the biggest impact on your stack?
The AI Act affects multiple layers of your product. Four areas stand out:
Data ingestion: Origin and bias must be demonstrably recorded. Start by mapping out data sources and access rights.
Model development: Every model version must be traceable, including training data and parameters. Add version control and audit trails to your MLOps flow.
UX & transparency: The user must know they are interacting with AI and why the advice is given. Integrate disclaimers and explanations into the interface.
CI/CD & monitoring: Incident logging, drift detection, and rollback scenarios are required for high risk. Build a model registry and real-time monitoring into your pipeline.
What is a feasible roadmap?
Every organization is different, but the approach usually takes place in three phases:
Inventory & risk classification
Map out all AI systems and label them according to the EU categories. This takes an average of 4 to 6 weeks and is guided by consultants and product owners.Proof-of-concept compliance pipeline
Set up a test environment with data validation, model registry, and transparency layer. This way, teams can see what is changing. Time: 6 to 8 weeks.Phased rollout & team training
Policies go live step by step. At the same time, we train the team so they can manage the new standards. Duration: 3 to 6 months.
How does Koodin help?
We do not deliver isolated experts, but teams that understand both technology and process. For AI Act trajectories, we often deploy these roles:
Role | Contribution |
Senior developers | Build traceability and logging into code and pipelines |
DevOps engineers | Set up model registry, CI/CD policies, and monitoring |
UX designers | Design transparency layers and explainability screens |
Consultants & product owners | Classify systems, prioritize actions, guide teams |
We build along with you, document, hand over, and ensure that you can continue independently.
Want to know more?
The AI Act is clear: waiting is not an option. Do you want to know what this means for your product or team? Drop by at B. Amsterdam or get in touch. We would love to show you how you can start today and be compliant tomorrow.
Frequently asked questions about the EU AI Act
How do I determine the risk level of my AI system?
Identify the goal, target group, and impact of errors. Link this to the four levels via the EU guidelines.
Can open-source models be compliant?
Yes, provided that the origin of the data, training, and modifications are traceable, and that appropriate licenses are in place.
How long does a full migration take?
For one high-risk system: approximately 3 months. For multiple systems, this can take up to 12 months.
When do I need to be ready?
When do I need to be ready? The law applies from June 2025. Enforcement becomes active from June 2026. Most processes take 6 to 12 months, so delay brings risks.
What if you start too late?
Fines can reach up to 35 million euros. More importantly, systems that do not comply cannot remain in production.












