[blog]

A deployer's checklist for the EU AI Act

Practical steps for organisations deploying AI in Europe as the regulation phases in.

MinimalLimitedHigh

Published 24 February 2026 · LoxiLabs

Know your classification

Most business systems are limited or minimal risk. Credit decisions, employment, access to essential services, and some public-sector uses can be high risk. Classification is a legal question we answer with the client's counsel, but engineering needs the answer early because it changes what must be built.

Document as you build

What the system does, what data it uses, how it was evaluated, how humans oversee it, how incidents are handled. Written at the end this is a project; written as part of delivery it is a template filled in weekly.

Separate provider and deployer duties

Building on OpenAI, Anthropic, or Google models means some obligations sit with the provider and some with you. Procurement should ask the provider for what they cover; engineering should design for what remains.

Inherit controls from the platform

A portfolio-level governance framework gives each new system evaluation harnesses, monitoring, and documentation templates on day one. Compliance becomes a property of the platform rather than a per-project cost.

Remember sector regulators

Financial, telecom, and public-sector rules still apply. We design to the stricter requirement.

This article is general information for practitioners, not legal advice.

[related]

[share]

Copy the address bar link, or send this article to a colleague who owns the metric.

Ready to move from pilots to P&L?

Tell us about the decision or workflow you want to change. We'll come back with an honest view on whether it's worth proving, and what it would take.

Start a conversation