SkarpSkarp

Chapter 11 of 11

Your AI Act Roadmap: From Gap Analysis to Implementation Plan

Bring everything together by drafting a tailored AI Act compliance roadmap for your organization, prioritizing actions by risk, deadlines, and business impact.

15 min readen

Step 1 – Anchor Your Roadmap in the AI Act Timeline and Scope

Why Start With Timeline and Scope?

Your AI Act roadmap must be tied to what the law covers and when duties apply. As of mid-2026, the AI Act is in a phased application period with staggered obligations.

Clarify Your Roles

Ask: Are we a provider, deployer (user), importer, distributor, or a mix? Do we place AI on the EU market or use it in the EU? Do we offer or integrate general-purpose AI?

Understand Risk Categories

The Act distinguishes prohibited AI, high-risk AI (Annex III and safety components), limited-risk with transparency duties, and minimal-risk systems with mostly voluntary codes.

Timeline Buckets

Group your work as immediate (prohibited/high-risk already live), near-term (high-risk and GPAI prep), and ongoing (governance, training, monitoring as guidance evolves).

Outcome of Step 1

By the end of this step you know: which AI systems are in scope, what roles you play for each, and which legal deadlines matter for your planning.

Step 2 – Build and Structure Your AI System Inventory

Why an AI Inventory?

You cannot plan compliance for what you cannot see. A structured inventory lists every AI system, so decisions are based on facts, not guesses.

Core Idea: A Table of Systems

Imagine a table where each row is an AI system and columns capture name, owners, lifecycle status, function, role under the AI Act, risk, and more.

Key Fields to Capture

Include: name/description, business and technical owners, lifecycle status, function and context of use, and your role (provider, deployer, or both).

Risk and Dependencies

Add an initial risk category, note any general-purpose AI models, vendors, and critical data sources. This will matter for later controls and contracts.

Business Criticality

Tag each system as high, medium, or low criticality, based on revenue, safety, or legal impact. This helps you decide what to fix first.

Outcome of Step 2

You end with a living inventory: a spreadsheet or database that becomes the backbone for gap analysis, prioritization, and your roadmap.

Activity – Draft a Mini AI Inventory for a Fictional Company

Apply the concepts by sketching an inventory for a fictional organization.

Scenario:

You are mapping AI systems for EduHire, a mid-sized EU-based recruitment and training platform.

Identify at least 3 AI systems EduHire might use and fill in these fields for each:

  • Name and short description
  • Business owner
  • Technical owner
  • Lifecycle status
  • Function and context of use
  • Role under the AI Act (provider, deployer, both)
  • Initial risk category (prohibited, high-risk, limited, minimal)
  • Business criticality (high, medium, low)

Your task (write this out in your notes):

  1. List 3 plausible AI systems at EduHire.
  2. For each, assign realistic values for all fields.
  3. Mark any systems where you are uncertain about the risk category with a question mark.

After you finish, compare with this sample answer:

  • System 1: "SmartMatch" – algorithm that ranks job candidates for client companies.
  • Business owner: B2B Sales
  • Technical owner: Data Science
  • Status: In production
  • Context: Used by recruiters to shortlist candidates for interviews.
  • Role: Provider (EduHire sells the tool to clients)
  • Risk: Likely high-risk (recruitment is an Annex III area)
  • Criticality: High
  • System 2: "ChatGuide" – chatbot answering candidate FAQs on the website.
  • Business owner: Marketing
  • Technical owner: Platform Team
  • Status: In production
  • Context: Public-facing Q&A, no automated decisions.
  • Role: Deployer (uses third-party LLM API)
  • Risk: Limited-risk (transparency obligations)
  • Criticality: Medium
  • System 3: "CourseRecommender" – suggests online courses to logged-in users.
  • Business owner: Product
  • Technical owner: Data Analytics
  • Status: Pilot
  • Context: Non-binding suggestions for adult learners.
  • Role: Provider (internal development for platform users)
  • Risk: Likely minimal, unless used for high-stakes certification or access to essential services
  • Criticality: Medium

Reflection prompt: For which system would you feel most pressure to get AI Act compliance right first, and why? Consider both legal risk and business impact.

Step 3 – Classify Risk and Map to AI Act Requirements

From Guess to Confirmed Risk

Use Annex III and the safety-component logic to refine each system’s risk category: prohibited, high-risk, limited-risk, or minimal risk.

Check Annex III and Safety Uses

Ask: Is this use in Annex III (e.g. recruitment, credit scoring) or a safety component of a regulated product? If yes, it is likely high-risk.

Requirement Clusters for High-Risk

High-risk systems must meet clusters of duties: risk management, data governance, documentation, transparency, human oversight, accuracy, cybersecurity, and monitoring.

Limited-Risk Focus

Limited-risk systems mainly face transparency duties, such as telling users they are interacting with AI or that content is AI-generated.

Add Mapping Columns

Extend your inventory with: confirmed risk category, Annex III reference, and which requirement clusters apply. This prepares you for gap analysis.

Worked Example – Risk Classification and Requirement Mapping

SmartMatch Overview

SmartMatch ranks job candidates for client companies. EduHire develops and sells it, so it is the provider; clients are deployers.

Classifying the Risk

Recruitment and candidate evaluation appear in Annex III. Therefore, SmartMatch is classified as a high-risk AI system.

Provider Obligations

As provider, EduHire must implement risk management, data governance, technical documentation, record-keeping, transparency, human oversight, and security measures.

Post-Market Monitoring

EduHire must monitor SmartMatch in real use, track incidents and performance, and update risk assessments and controls over time.

Inventory Mapping Snapshot

In the inventory, SmartMatch is tagged as high-risk, with an Annex III employment reference and all key requirement clusters checked as applicable.

Step 4 – Perform a Focused Gap Analysis

What is a Gap Analysis?

Gap analysis compares your current controls to AI Act requirements for each system, highlighting where you fall short and where you are already strong.

Use a Simple Rating Scale

Rate each requirement cluster 0–3: not started, partial, largely in place, or fully compliant and documented.

Questions to Ask

Do we have risk management, data governance, documentation, human oversight, and aligned vendor contracts for this system? If not, that is a gap.

Write Concrete Gaps

Avoid vague notes. Write specific items like: no bias assessment on training data, or vendor LLM contract lacks AI Act cooperation clauses.

Outcome: Gap Register

You end with a gap register: a list of missing or weak controls per system, each tied to a requirement cluster and a rating.

Quick Check – Gap Analysis Logic

Test your understanding of how to structure an AI Act gap analysis.

You are assessing a high-risk recruitment AI. You find that there is a bias check done once, but no ongoing monitoring or written procedure. How should you rate the 'risk management system' cluster and describe the gap?

  1. Rate it 3 (fully compliant); note that monitoring is informal but acceptable.
  2. Rate it 1 (partial); gap: no documented, ongoing risk management process or monitoring plan.
  3. Rate it 0 (not started); gap: no risk management activity at all.
Show Answer

Answer: B) Rate it 1 (partial); gap: no documented, ongoing risk management process or monitoring plan.

A one-off bias check shows some activity, so 0 (not started) is too harsh. But without an ongoing, documented process, it is only partial (1), not fully compliant (3). The gap should highlight the missing ongoing and documented risk management.

Step 5 – Prioritize Actions by Risk, Deadlines, and Business Impact

Why Prioritize?

You cannot fix all gaps at once. Prioritization ensures that the most critical legal and business risks are addressed first.

Key Dimensions

Score each gap by regulatory risk, business impact, implementation effort, and timing or dependencies with other tasks.

Three Tiers of Priority

Tier 1: must-do now; Tier 2: plan next; Tier 3: later or nice-to-have. Use this to group remediation actions.

Example: SmartMatch vs ChatGuide

For SmartMatch, risk management and bias checks are Tier 1. For ChatGuide, adding an AI disclosure banner is Tier 1, while extra monitoring might be Tier 2.

Risk Appetite Matters

Organizations with low risk appetite will treat more items as Tier 1, especially where fundamental rights or vulnerable people are involved.

Step 6 – Design a Phased Implementation Plan

From Gaps to Plan

A phased implementation plan sequences your remediation work over time, matching AI Act deadlines and your organization’s capacity.

Example Phases

Phase 0: immediate fixes; Phase 1: governance and templates; Phase 2: full high-risk readiness; Phase 3: optimization and culture.

Define Concrete Projects

For each priority gap, define a project with an objective, scope, owner, milestones, and dependencies.

Visualize with a Timeline

Use a simple Gantt-style chart: rows as projects, columns as months or quarters, with bars showing when work happens.

Outcome of Step 6

You end with a phased, time-bound roadmap that shows what will be done, by whom, and in what order.

Step 7 – Set Up Internal Governance, KPIs, and Training

Why Governance and KPIs?

Projects alone are not enough. You need clear roles, decision structures, and metrics to keep AI Act compliance on track over time.

Core Governance Roles

Set up an AI Governance Committee, assign system owners, and appoint an AI risk or compliance lead to coordinate activities.

Choosing KPIs

Track indicators like: share of systems inventoried, high-risk systems with full documentation, AI incidents, and staff training coverage.

Role-Based Training

Develop tailored training for developers, product managers, HR/sales/support, and executives, using your own AI systems as examples.

Continuous Improvement

Review KPIs and incidents regularly, update the roadmap with new guidance, and refine templates and processes based on experience.

Key Term Review – AI Act Roadmapping

Use these flashcards to reinforce key concepts from the module.

AI system inventory
A structured list of all AI systems in an organization, capturing attributes like owners, function, lifecycle status, risk category, dependencies, and business criticality.
Risk category (AI Act)
Classification of AI systems as prohibited, high-risk, limited-risk (with transparency duties), or minimal risk, based on their use and impact.
Gap analysis
A systematic comparison between current practices and AI Act requirements for each system, identifying missing or weak controls.
Priority tier
A label (for example, Tier 1, 2, 3) showing how urgently a remediation action should be done, considering regulatory risk, business impact, and effort.
Phased implementation plan
A time-bound roadmap divided into stages (e.g. immediate, foundation, high-risk readiness, optimization) that sequences compliance projects.
AI Governance Committee
A cross-functional group that oversees AI use cases, approves high-risk deployments, monitors compliance KPIs, and updates the AI roadmap.
Key Performance Indicator (KPI)
A measurable value (e.g. % of high-risk systems with completed risk management) used to track progress toward AI Act compliance goals.
Deployer vs provider
A provider develops and places an AI system on the market; a deployer uses an AI system under its authority. One organization can be both for different systems.

Final Activity – Draft Your Own Mini AI Act Roadmap

Bring everything together by drafting a mini AI Act roadmap for a context you know (your university, a part-time job, or a fictional company).

1. Choose an organization

Pick one:

  • Your university (e.g. admissions, learning platforms).
  • A small online shop.
  • A fictional startup (e.g. health app, fintech, edtech).

2. Identify 2–3 AI systems

For each system, note:

  • Name and brief description.
  • Role (provider, deployer, both).
  • Risk category (prohibited, high-risk, limited, minimal).

3. List at least 3 gaps total

Examples:

  • No AI inventory exists.
  • No transparency notice for a chatbot.
  • No risk management documentation for a high-risk use.
  • Vendor contract does not mention AI Act cooperation.

4. Prioritize and phase

Assign each gap a priority tier (1–3) and a phase (0–3), similar to the module:

  • Phase 0: immediate
  • Phase 1: foundation
  • Phase 2: high-risk readiness
  • Phase 3: optimization

5. Write a 5–6 line roadmap summary

In your notes, describe:

  • The top 2–3 projects you would start with.
  • Who should own them.
  • When you would aim to complete them.

Reflection prompt: Which part of the roadmap felt hardest (inventory, risk classification, gap analysis, prioritization, or governance), and what information would you need to make it easier in a real organization?

Key Terms

Deployer
An organization or person that uses an AI system under its authority in the course of its activities, sometimes called the user of the AI system.
Provider
An organization or person that develops an AI system or has it developed and places it on the EU market or puts it into service under its own name or trademark.
Gap analysis
A method to compare current practices and controls against legal or standard requirements, identifying where an organization falls short and what needs to be improved.
AI system inventory
A structured register of all AI systems used, developed, or acquired by an organization, including key attributes such as owners, purpose, lifecycle stage, risk category, and dependencies.
High-risk AI system
An AI system that falls into categories listed in Annex III of the AI Act or acts as a safety component of regulated products, subject to strict requirements on risk management, data, documentation, oversight, and monitoring.
Risk category (AI Act)
The classification of AI systems into prohibited, high-risk, limited-risk (with specific transparency or other duties), and minimal risk, depending on their use case and potential impact on safety and fundamental rights.
AI Governance Committee
A cross-functional internal body responsible for overseeing AI use, approving high-risk deployments, monitoring compliance KPIs, and updating policies and roadmaps.
General-purpose AI (GPAI)
AI models that are intended to be used in many different applications and contexts, often including large language models, which have their own set of obligations under the AI Act when provided or integrated.
Phased implementation plan
A roadmap that sequences compliance work into distinct time periods or phases, aligning with regulatory deadlines and organizational capacity.
KPI (Key Performance Indicator)
A quantitative measure used to track progress toward a specific objective, such as the percentage of high-risk AI systems with completed risk assessments.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself