EU AI Act: what do you need to arrange now and how do you take the first step?

What do you need to arrange for the EU AI Act?

What do you need to do to comply with the EU AI Act in the near future? We are hearing this question more and more often. The law is final and will apply from June 2025. Active enforcement is expected starting June 2026. Therefore, organizations have less than a year to ensure that their AI systems comply with the new guidelines for risk, transparency, and supervision.

The law classifies every AI system into four risk levels and associates concrete obligations with them. Think of data quality, explainability, human control, and incident logging. For many teams, this means: first inventory, then adapt and document.

The challenge is not small. Models, data pipelines, and interfaces must be mapped out. Processes must be adapted without stagnating the business. This is precisely where experience makes the difference. At Koodin, we work with senior professionals who combine technology, governance, and team dynamics. They help you start today and be compliant tomorrow, without taking the momentum out of the product.

What exactly does the EU AI Act require?

The law divides all AI systems into four risk levels. Each level has its own requirements and corresponding controls:

Risk Level

Examples

Core Obligations

Unacceptable

Social scoring, biometric surveillance in public spaces

Prohibited within the EU

High

Health diagnosis, credit scoring, critical infrastructure

Data quality, risk assessment, CE marking, human supervision, incident logging

Limited

Chatbots, AI customer support

Transparency: the user must know they are talking to an AI

Minimal

Spell checkers, recommendation algorithms for newsfeeds

No extra obligations beyond existing legislation

Fines can reach up to 35 million euros or 7% of global turnover in case of non-compliance. The higher the risk, the stricter the requirements. Since implementation takes 6 to 12 months on average, it is wise to start preparations now.

Where is the biggest impact on your stack?

The AI Act affects multiple layers of your product. Four areas stand out:

  • Data ingestion: Origin and bias must be demonstrably recorded. Start by mapping out data sources and access rights.

  • Model development: Every model version must be traceable, including training data and parameters. Add version control and audit trails to your MLOps flow.

  • UX & transparency: The user must know they are interacting with AI and why the advice is given. Integrate disclaimers and explanations into the interface.

  • CI/CD & monitoring: Incident logging, drift detection, and rollback scenarios are required for high risk. Build a model registry and real-time monitoring into your pipeline.

What is a feasible roadmap?

Every organization is different, but the approach usually takes place in three phases:

  1. Inventory & risk classification
    Map out all AI systems and label them according to the EU categories. This takes an average of 4 to 6 weeks and is guided by consultants and product owners.

  2. Proof-of-concept compliance pipeline
    Set up a test environment with data validation, model registry, and transparency layer. This way, teams can see what is changing. Time: 6 to 8 weeks.

  3. Phased rollout & team training
    Policies go live step by step. At the same time, we train the team so they can manage the new standards. Duration: 3 to 6 months.

How does Koodin help?

We do not deliver isolated experts, but teams that understand both technology and process. For AI Act trajectories, we often deploy these roles:

Role

Contribution

Senior developers

Build traceability and logging into code and pipelines

DevOps engineers

Set up model registry, CI/CD policies, and monitoring

UX designers

Design transparency layers and explainability screens

Consultants & product owners

Classify systems, prioritize actions, guide teams

We build along with you, document, hand over, and ensure that you can continue independently.

Want to know more?

The AI Act is clear: waiting is not an option. Do you want to know what this means for your product or team? Drop by at B. Amsterdam or get in touch. We would love to show you how you can start today and be compliant tomorrow.

Frequently asked questions about the EU AI Act

How do I determine the risk level of my AI system?

Identify the goal, target group, and impact of errors. Link this to the four levels via the EU guidelines.

Can open-source models be compliant?

Yes, provided that the origin of the data, training, and modifications are traceable, and that appropriate licenses are in place.

How long does a full migration take?

For one high-risk system: approximately 3 months. For multiple systems, this can take up to 12 months.

When do I need to be ready?

When do I need to be ready? The law applies from June 2025. Enforcement becomes active from June 2026. Most processes take 6 to 12 months, so delay brings risks.

What if you start too late?

Fines can reach up to 35 million euros. More importantly, systems that do not comply cannot remain in production.

B. Amsterdam (B.2)

John M. Keynesplein 12-46

1066 EP Amsterdam

Follow us on LinkedIn for updates

© 2022 - 2026 Koodin

|

|

B. Amsterdam (B.2)

John M. Keynesplein 12-46

1066 EP Amsterdam

Follow us on LinkedIn for updates

© 2022 - 2026 Koodin

|

|

B. Amsterdam (B.2)

John M. Keynesplein 12-46

1066 EP Amsterdam

Follow us on LinkedIn for updates

© 2022 - 2026 Koodin

|

|