The EU AI Act: What Enterprise IT Teams Need to Do Now

Most US companies with EU operations are going to fail their first EU AI Act audit — not because their AI is dangerous, but because they have no documentation proving it isn’t.

The EU AI Act entered into force in August 2024. Prohibitions on unacceptable-risk AI apply from February 2025. High-risk obligations — the ones that will hit most enterprise use cases — apply from August 2026. That sounds like enough runway. It isn’t, because the documentation and governance infrastructure required doesn’t get built in a quarter.

This is a practical guide for IT directors and CISOs who need to understand what the law actually requires, which systems are in scope, and what has to change before your legal team starts getting letters from EU supervisory authorities.

Which AI Use Cases Are Actually High-Risk

The Act defines high-risk AI by reference to specific deployment contexts, not by technical characteristics. The list is more expansive than most organizations realize when they first read it.

High-risk categories include: AI used in employment decisions (CV screening, performance evaluation, promotion recommendations), AI in credit and insurance underwriting, AI in access to essential services, AI in educational admissions, AI in law enforcement and border control, and AI in administration of justice. If your organization operates in HR tech, financial services, insurance, or public sector services and you have EU employees or customers, you almost certainly have high-risk AI systems in scope.

Two things catch enterprises off guard. First, the classification applies based on intended use and deployment context — not on how sophisticated the model is. A rules-based automated screening tool for job applications is high-risk under the Act. Second, the obligations fall on both providers (organizations that develop or substantially modify AI systems) and deployers (organizations that put AI systems into use). If you’re a US company buying an AI-powered HR platform and deploying it to your EU workforce, you are a deployer under the Act and you carry compliance obligations — your vendor’s compliance doesn’t transfer to you automatically.

What Documentation the Law Actually Requires

For high-risk AI systems, the EU AI Act enterprise compliance framework is built around four documentation pillars: technical documentation, a conformity assessment, registration in the EU database, and an ongoing post-market monitoring system.

Technical documentation must cover the system’s intended purpose, the development process including training data governance, the performance metrics and known limitations, the cybersecurity measures, and the human oversight procedures. This isn’t a one-time write-up — it has to be kept current and must be available to supervisory authorities on request. The required retention period is ten years after the system is placed on the market or put into service.

Deployers carry specific obligations beyond passive use: they must conduct a fundamental rights impact assessment before deploying high-risk systems, implement the human oversight measures specified by the provider, monitor system performance in their specific context, and report serious incidents. If you’re running AI in HR or lending decisions, you need documented processes showing a human is genuinely reviewing AI outputs before consequential decisions are made — not a checkbox, an actual procedure with evidence it runs.

The conformity assessment requirements depend on the risk category. Most high-risk AI can self-certify if it follows harmonized standards, but certain categories — including AI in biometrics and critical infrastructure — require third-party conformity assessment. Even for self-certification, you need to have actually run the assessment and hold the documentation.

What Changes in Procurement

The single biggest operational shift for EU AI Act enterprise compliance isn’t internal — it’s procurement. Most existing AI vendor contracts don’t support the obligations the Act places on deployers, and renegotiating enterprise software agreements takes time.

Before signing or renewing any AI system contract, your procurement process needs to answer five questions. First, does the vendor classify this system under the EU AI Act, and what’s their stated risk classification? Second, does the vendor provide the technical documentation required for your deployer obligations? Third, what logging and audit trail data does the vendor provide, and in what format? Fourth, what are the data residency and processing terms, and do they support your EU obligations? Fifth, what are the incident reporting obligations on both sides, and do they align with the Act’s 15-day serious incident notification requirement?

Vendors who sell into regulated industries are starting to adapt their contracts. Many are not. If a vendor can’t produce a clear answer to whether their system is in scope under the Act and what documentation they provide to support deployer compliance, that’s a procurement risk, not just a compliance gap.

This is where governance infrastructure matters more than people expect. Peridot gives IT and compliance teams a centralized layer for tracking which AI systems are deployed, by whom, for what purpose, and what documentation exists — the exact data structure you need to run a compliant deployer program at scale. Without something that creates a system of record for AI deployment, you’re managing EU AI Act enterprise obligations in spreadsheets and hoping nothing gets audited.

What US Companies With EU Operations Need to Do Now

The Act applies based on where the output of the AI system is used, not where the company is incorporated. A US company whose AI-powered hiring tool screens EU-based job applicants is in scope. There is no extraterritoriality carve-out for non-EU companies.

The practical steps are sequenced. Start with a system inventory: identify every AI system in use across the organization, classify each one by the Act’s risk categories, and document who is the provider and who is the deployer. This alone takes most organizations longer than expected because AI deployment has often happened without centralized tracking.

Next, run a gap assessment against high-risk obligations for systems that land in that category. What documentation exists? What doesn’t? Where are the human oversight procedures, and are they real or nominal? What does the current vendor contract provide?

Then build the governance infrastructure. This is what separates organizations that pass audits from those that produce documentation after the fact. Peridot’s control layer is designed specifically for this: giving organizations the ability to run AI inside their own infrastructure with the audit trail, access controls, and documentation hooks that EU AI Act enterprise compliance requires — not bolted on after deployment but built into how AI runs from the start.

August 2026 is the compliance deadline for most high-risk obligations. Eighteen months isn’t long when it includes a full system inventory, vendor contract reviews, impact assessments, and building documentation processes that have to run continuously. The organizations that treat this as an infrastructure problem to solve now will be ready. The ones waiting for regulatory pressure to force action will be scrambling when it arrives.

Scroll to Top