Chapter 11 of 11
Your AI Act Roadmap: From Gap Analysis to Implementation Plan
Bring everything together by drafting a tailored AI Act compliance roadmap for your organization, prioritizing actions by risk, deadlines, and business impact.
Step 1 – Anchor Your Roadmap in the AI Act Timeline and Scope
Why Start With Timeline and Scope?
Your AI Act roadmap must be tied to what the law covers and when duties apply. As of mid-2026, the AI Act is in a phased application period with staggered obligations.
Clarify Your Roles
Ask: Are we a provider, deployer (user), importer, distributor, or a mix? Do we place AI on the EU market or use it in the EU? Do we offer or integrate general-purpose AI?
Understand Risk Categories
The Act distinguishes prohibited AI, high-risk AI (Annex III and safety components), limited-risk with transparency duties, and minimal-risk systems with mostly voluntary codes.
Timeline Buckets
Group your work as immediate (prohibited/high-risk already live), near-term (high-risk and GPAI prep), and ongoing (governance, training, monitoring as guidance evolves).
Outcome of Step 1
By the end of this step you know: which AI systems are in scope, what roles you play for each, and which legal deadlines matter for your planning.
Step 2 – Build and Structure Your AI System Inventory
Why an AI Inventory?
You cannot plan compliance for what you cannot see. A structured inventory lists every AI system, so decisions are based on facts, not guesses.
Core Idea: A Table of Systems
Imagine a table where each row is an AI system and columns capture name, owners, lifecycle status, function, role under the AI Act, risk, and more.
Key Fields to Capture
Include: name/description, business and technical owners, lifecycle status, function and context of use, and your role (provider, deployer, or both).
Risk and Dependencies
Add an initial risk category, note any general-purpose AI models, vendors, and critical data sources. This will matter for later controls and contracts.
Business Criticality
Tag each system as high, medium, or low criticality, based on revenue, safety, or legal impact. This helps you decide what to fix first.
Outcome of Step 2
You end with a living inventory: a spreadsheet or database that becomes the backbone for gap analysis, prioritization, and your roadmap.
Activity – Draft a Mini AI Inventory for a Fictional Company
Apply the concepts by sketching an inventory for a fictional organization.
Scenario:
You are mapping AI systems for EduHire, a mid-sized EU-based recruitment and training platform.
Identify at least 3 AI systems EduHire might use and fill in these fields for each:
- Name and short description
- Business owner
- Technical owner
- Lifecycle status
- Function and context of use
- Role under the AI Act (provider, deployer, both)
- Initial risk category (prohibited, high-risk, limited, minimal)
- Business criticality (high, medium, low)
Your task (write this out in your notes):
- List 3 plausible AI systems at EduHire.
- For each, assign realistic values for all fields.
- Mark any systems where you are uncertain about the risk category with a question mark.
After you finish, compare with this sample answer:
- System 1: "SmartMatch" – algorithm that ranks job candidates for client companies.
- Business owner: B2B Sales
- Technical owner: Data Science
- Status: In production
- Context: Used by recruiters to shortlist candidates for interviews.
- Role: Provider (EduHire sells the tool to clients)
- Risk: Likely high-risk (recruitment is an Annex III area)
- Criticality: High
- System 2: "ChatGuide" – chatbot answering candidate FAQs on the website.
- Business owner: Marketing
- Technical owner: Platform Team
- Status: In production
- Context: Public-facing Q&A, no automated decisions.
- Role: Deployer (uses third-party LLM API)
- Risk: Limited-risk (transparency obligations)
- Criticality: Medium
- System 3: "CourseRecommender" – suggests online courses to logged-in users.
- Business owner: Product
- Technical owner: Data Analytics
- Status: Pilot
- Context: Non-binding suggestions for adult learners.
- Role: Provider (internal development for platform users)
- Risk: Likely minimal, unless used for high-stakes certification or access to essential services
- Criticality: Medium
Reflection prompt: For which system would you feel most pressure to get AI Act compliance right first, and why? Consider both legal risk and business impact.
Step 3 – Classify Risk and Map to AI Act Requirements
From Guess to Confirmed Risk
Use Annex III and the safety-component logic to refine each system’s risk category: prohibited, high-risk, limited-risk, or minimal risk.
Check Annex III and Safety Uses
Ask: Is this use in Annex III (e.g. recruitment, credit scoring) or a safety component of a regulated product? If yes, it is likely high-risk.
Requirement Clusters for High-Risk
High-risk systems must meet clusters of duties: risk management, data governance, documentation, transparency, human oversight, accuracy, cybersecurity, and monitoring.
Limited-Risk Focus
Limited-risk systems mainly face transparency duties, such as telling users they are interacting with AI or that content is AI-generated.
Add Mapping Columns
Extend your inventory with: confirmed risk category, Annex III reference, and which requirement clusters apply. This prepares you for gap analysis.
Worked Example – Risk Classification and Requirement Mapping
SmartMatch Overview
SmartMatch ranks job candidates for client companies. EduHire develops and sells it, so it is the provider; clients are deployers.
Classifying the Risk
Recruitment and candidate evaluation appear in Annex III. Therefore, SmartMatch is classified as a high-risk AI system.
Provider Obligations
As provider, EduHire must implement risk management, data governance, technical documentation, record-keeping, transparency, human oversight, and security measures.
Post-Market Monitoring
EduHire must monitor SmartMatch in real use, track incidents and performance, and update risk assessments and controls over time.
Inventory Mapping Snapshot
In the inventory, SmartMatch is tagged as high-risk, with an Annex III employment reference and all key requirement clusters checked as applicable.
Step 4 – Perform a Focused Gap Analysis
What is a Gap Analysis?
Gap analysis compares your current controls to AI Act requirements for each system, highlighting where you fall short and where you are already strong.
Use a Simple Rating Scale
Rate each requirement cluster 0–3: not started, partial, largely in place, or fully compliant and documented.
Questions to Ask
Do we have risk management, data governance, documentation, human oversight, and aligned vendor contracts for this system? If not, that is a gap.
Write Concrete Gaps
Avoid vague notes. Write specific items like: no bias assessment on training data, or vendor LLM contract lacks AI Act cooperation clauses.
Outcome: Gap Register
You end with a gap register: a list of missing or weak controls per system, each tied to a requirement cluster and a rating.
Quick Check – Gap Analysis Logic
Test your understanding of how to structure an AI Act gap analysis.
You are assessing a high-risk recruitment AI. You find that there is a bias check done once, but no ongoing monitoring or written procedure. How should you rate the 'risk management system' cluster and describe the gap?
- Rate it 3 (fully compliant); note that monitoring is informal but acceptable.
- Rate it 1 (partial); gap: no documented, ongoing risk management process or monitoring plan.
- Rate it 0 (not started); gap: no risk management activity at all.
Show Answer
Answer: B) Rate it 1 (partial); gap: no documented, ongoing risk management process or monitoring plan.
A one-off bias check shows some activity, so 0 (not started) is too harsh. But without an ongoing, documented process, it is only partial (1), not fully compliant (3). The gap should highlight the missing ongoing and documented risk management.
Step 5 – Prioritize Actions by Risk, Deadlines, and Business Impact
Why Prioritize?
You cannot fix all gaps at once. Prioritization ensures that the most critical legal and business risks are addressed first.
Key Dimensions
Score each gap by regulatory risk, business impact, implementation effort, and timing or dependencies with other tasks.
Three Tiers of Priority
Tier 1: must-do now; Tier 2: plan next; Tier 3: later or nice-to-have. Use this to group remediation actions.
Example: SmartMatch vs ChatGuide
For SmartMatch, risk management and bias checks are Tier 1. For ChatGuide, adding an AI disclosure banner is Tier 1, while extra monitoring might be Tier 2.
Risk Appetite Matters
Organizations with low risk appetite will treat more items as Tier 1, especially where fundamental rights or vulnerable people are involved.
Step 6 – Design a Phased Implementation Plan
From Gaps to Plan
A phased implementation plan sequences your remediation work over time, matching AI Act deadlines and your organization’s capacity.
Example Phases
Phase 0: immediate fixes; Phase 1: governance and templates; Phase 2: full high-risk readiness; Phase 3: optimization and culture.
Define Concrete Projects
For each priority gap, define a project with an objective, scope, owner, milestones, and dependencies.
Visualize with a Timeline
Use a simple Gantt-style chart: rows as projects, columns as months or quarters, with bars showing when work happens.
Outcome of Step 6
You end with a phased, time-bound roadmap that shows what will be done, by whom, and in what order.
Step 7 – Set Up Internal Governance, KPIs, and Training
Why Governance and KPIs?
Projects alone are not enough. You need clear roles, decision structures, and metrics to keep AI Act compliance on track over time.
Core Governance Roles
Set up an AI Governance Committee, assign system owners, and appoint an AI risk or compliance lead to coordinate activities.
Choosing KPIs
Track indicators like: share of systems inventoried, high-risk systems with full documentation, AI incidents, and staff training coverage.
Role-Based Training
Develop tailored training for developers, product managers, HR/sales/support, and executives, using your own AI systems as examples.
Continuous Improvement
Review KPIs and incidents regularly, update the roadmap with new guidance, and refine templates and processes based on experience.
Key Term Review – AI Act Roadmapping
Use these flashcards to reinforce key concepts from the module.
- AI system inventory
- A structured list of all AI systems in an organization, capturing attributes like owners, function, lifecycle status, risk category, dependencies, and business criticality.
- Risk category (AI Act)
- Classification of AI systems as prohibited, high-risk, limited-risk (with transparency duties), or minimal risk, based on their use and impact.
- Gap analysis
- A systematic comparison between current practices and AI Act requirements for each system, identifying missing or weak controls.
- Priority tier
- A label (for example, Tier 1, 2, 3) showing how urgently a remediation action should be done, considering regulatory risk, business impact, and effort.
- Phased implementation plan
- A time-bound roadmap divided into stages (e.g. immediate, foundation, high-risk readiness, optimization) that sequences compliance projects.
- AI Governance Committee
- A cross-functional group that oversees AI use cases, approves high-risk deployments, monitors compliance KPIs, and updates the AI roadmap.
- Key Performance Indicator (KPI)
- A measurable value (e.g. % of high-risk systems with completed risk management) used to track progress toward AI Act compliance goals.
- Deployer vs provider
- A provider develops and places an AI system on the market; a deployer uses an AI system under its authority. One organization can be both for different systems.
Final Activity – Draft Your Own Mini AI Act Roadmap
Bring everything together by drafting a mini AI Act roadmap for a context you know (your university, a part-time job, or a fictional company).
1. Choose an organization
Pick one:
- Your university (e.g. admissions, learning platforms).
- A small online shop.
- A fictional startup (e.g. health app, fintech, edtech).
2. Identify 2–3 AI systems
For each system, note:
- Name and brief description.
- Role (provider, deployer, both).
- Risk category (prohibited, high-risk, limited, minimal).
3. List at least 3 gaps total
Examples:
- No AI inventory exists.
- No transparency notice for a chatbot.
- No risk management documentation for a high-risk use.
- Vendor contract does not mention AI Act cooperation.
4. Prioritize and phase
Assign each gap a priority tier (1–3) and a phase (0–3), similar to the module:
- Phase 0: immediate
- Phase 1: foundation
- Phase 2: high-risk readiness
- Phase 3: optimization
5. Write a 5–6 line roadmap summary
In your notes, describe:
- The top 2–3 projects you would start with.
- Who should own them.
- When you would aim to complete them.
Reflection prompt: Which part of the roadmap felt hardest (inventory, risk classification, gap analysis, prioritization, or governance), and what information would you need to make it easier in a real organization?
Key Terms
- Deployer
- An organization or person that uses an AI system under its authority in the course of its activities, sometimes called the user of the AI system.
- Provider
- An organization or person that develops an AI system or has it developed and places it on the EU market or puts it into service under its own name or trademark.
- Gap analysis
- A method to compare current practices and controls against legal or standard requirements, identifying where an organization falls short and what needs to be improved.
- AI system inventory
- A structured register of all AI systems used, developed, or acquired by an organization, including key attributes such as owners, purpose, lifecycle stage, risk category, and dependencies.
- High-risk AI system
- An AI system that falls into categories listed in Annex III of the AI Act or acts as a safety component of regulated products, subject to strict requirements on risk management, data, documentation, oversight, and monitoring.
- Risk category (AI Act)
- The classification of AI systems into prohibited, high-risk, limited-risk (with specific transparency or other duties), and minimal risk, depending on their use case and potential impact on safety and fundamental rights.
- AI Governance Committee
- A cross-functional internal body responsible for overseeing AI use, approving high-risk deployments, monitoring compliance KPIs, and updating policies and roadmaps.
- General-purpose AI (GPAI)
- AI models that are intended to be used in many different applications and contexts, often including large language models, which have their own set of obligations under the AI Act when provided or integrated.
- Phased implementation plan
- A roadmap that sequences compliance work into distinct time periods or phases, aligning with regulatory deadlines and organizational capacity.
- KPI (Key Performance Indicator)
- A quantitative measure used to track progress toward a specific objective, such as the percentage of high-risk AI systems with completed risk assessments.