Compliance readiness is not a model badge or a one-time document. It is the ability to identify the system and role, map applicable duties, operate controls, and produce current evidence. This guide is implementation guidance, not legal advice.
Decision summary
- Date-stamp every EU AI Act plan: the July 2026 changes moved major high-risk application dates.
- Classify the system, intended purpose, affected people, supply-chain role, and jurisdiction before selecting controls.
- Separate legal obligations from voluntary risk-management practices and contract requirements.
- Use NIST AI RMF as a tailored operating framework, not a certification or checklist.
- Maintain evidence through change: inventory, decisions, tests, logs, oversight, incidents, providers, and versions.
Decision summary
Begin with facts about the system, not a generic compliance checklist. Record the intended purpose, users, affected people, decisions influenced, data and model providers, geography, deployment context, level of autonomy, and consequence of error. Then identify the organization's role for each relevant regime or contract.
A readiness program should distinguish three things: binding obligations determined with qualified counsel, voluntary risk-management practices, and internal or customer commitments. The controls can overlap, but the claims must not. NIST AI RMF alignment, for example, does not by itself establish EU AI Act compliance.
SOURCES: [1] European Commission · [3] National Institute of Standards and Technology · [4] National Institute of Standards and Technology
The EU AI Act timeline as of July 30, 2026
The European Commission states that the AI Act entered into force on August 1, 2024. AI-literacy duties and prohibited practices 1–8 began applying on February 2, 2025; a ninth prohibition covering systems that generate non-consensual sexually explicit or intimate content or child sexual abuse material takes effect in December 2026. Governance rules and general-purpose AI obligations began applying on August 2, 2025. Transparency rules apply from August 2026.
The July 2026 changes moved major high-risk dates. The Commission now lists December 2, 2027 for Annex III high-risk systems in specified sensitive areas and August 2, 2028 for high-risk systems embedded in regulated products covered by Annex I. Content that still says all high-risk obligations begin in August 2026 is outdated.
Timelines and applicability can change, and a summarized Commission page is not a substitute for the enacted legal text or advice on a specific system. Recheck the Commission and obtain qualified legal analysis before relying on a launch date or classification.
SOURCES: [1] European Commission · [2] European Commission
Classify the system and organizational role
Classification is an operating exercise. Map every materially different intended purpose and deployment rather than assigning one label to a model or product family. The same underlying model can sit inside systems with very different users, effects, oversight, and legal treatment.
Identify whether the organization is acting as provider, deployer, importer, distributor, product manufacturer, or a provider of a general-purpose model, as applicable. Record upstream provider dependencies and downstream customer responsibilities. A contract should make evidence, incident, change, and information obligations flow across that chain.
- Intended purpose, prohibited uses, and material modifications
- Users, affected people, and decisions or actions influenced
- Jurisdictions and market placement
- Provider, deployer, GPAI, and other supply-chain roles
- Data categories, sources, retention, and transfers
- Autonomy, human oversight, and consequence of error
SOURCES: [1] European Commission · [2] European Commission
Security, compliance, and the evidence system
The Commission's overview identifies high-risk themes including risk management, data quality, logging and traceability, documentation, information for deployers, human oversight, robustness, cybersecurity, and accuracy. A delivery team should translate each applicable requirement into an owner, control, implementation artifact, test, record, review cadence, and exception process.
Evidence should be versioned with the system. A risk assessment for model A, prompt version 12, retrieval policy B, and permission set C may not support a materially changed deployment. Link inventory entries, architecture decisions, evaluations, security tests, approvals, monitoring, incidents, and provider documents to the released configuration.
SOURCES: [1] European Commission
Use NIST AI RMF as an operating backbone
NIST AI RMF 1.0 is voluntary and context-sensitive. Its four functions—Govern, Map, Measure, and Manage—provide a useful way to organize ownership, context, assessment, and action without pretending every AI system needs identical controls. NIST is revising AI RMF 1.0, so organizations should track the revision rather than freeze the 2023 publication as permanent doctrine.
The NIST Playbook explicitly says it is not a checklist and does not prescribe a fixed order. Tailor it to the use case. The NIST Generative AI Profile adds a GenAI-specific view, including confabulation, data privacy, information integrity and security, bias, and human-AI configuration among its risk areas.
- Govern: accountability, policy, roles, culture, third parties, and risk tolerance
- Map: purpose, context, people, impact, data, dependencies, and assumptions
- Measure: evaluations, security tests, monitoring, uncertainty, and residual risk
- Manage: prioritize, treat, accept, communicate, monitor, and retire risk
SOURCES: [3] National Institute of Standards and Technology · [4] National Institute of Standards and Technology · [5] National Institute of Standards and Technology
Failure modes and limits
Common readiness failures include starting with a control catalog before classification, treating provider documentation as proof of the deployed system, confusing an evaluation score with acceptable risk, and generating documents that no operating process maintains. Another failure is making public claims such as “fully compliant” when the actual conclusion is narrower or still conditional.
Legal analysis remains jurisdiction- and fact-specific. Voluntary frameworks help organize risk but do not resolve legal applicability. Technical controls cannot replace required notice, governance, labor, sector, product-safety, privacy, or contractual analysis where those issues apply.
SOURCES: [2] European Commission · [3] National Institute of Standards and Technology · [4] National Institute of Standards and Technology
Implementation checklist
A practical first release of the compliance-readiness system should include the following artifacts.
- Inventory of systems, intended purposes, owners, users, affected people, and versions
- Documented role and classification analysis with legal questions separated
- Applicable-obligation, voluntary-framework, and contract-requirement register
- Risk, threat, data, provider, and human-oversight assessments
- Representative evaluations for accuracy, robustness, security, and safe failure
- Logging, traceability, documentation, and retention design
- Provider evidence and material-change notification process
- Incident, complaint, correction, escalation, and shutdown procedures
- Release approval and periodic review tied to the actual deployed configuration
- Public-claim review that prohibits unsupported certification or compliance language
SOURCES: [1] European Commission · [3] National Institute of Standards and Technology · [5] National Institute of Standards and Technology
How Nautilus can help
Nautilus can build the technical and operational evidence layer: inventory, architecture records, evaluation and security controls, traceability, provider register, oversight workflows, and release evidence. We work with the client's legal and compliance advisers on applicability and do not present implementation work as legal advice or certification.
Primary sources
Product capabilities, terms, timelines, and guidance change. These are the primary materials technically reviewed for this edition; implementation decisions should recheck the current source at the time of work.
- AI Act regulatory framework
European Commission · Updated 2026-07
Current application timeline, risk categories, and high-risk obligation themes. - Navigating the AI Act: questions and answers
European Commission · Updated 2026-07-27
Current Commission explanations of scope, roles, and timing. - AI Risk Management Framework
National Institute of Standards and Technology · AI RMF 1.0 published 2023-01-26
Voluntary, context-sensitive Govern, Map, Measure, and Manage framework and revision status. - NIST AI RMF Playbook
National Institute of Standards and Technology · NIST page updated 2026-06-10
Tailorable suggested actions; explicitly not a checklist or fixed sequence. - Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile
National Institute of Standards and Technology · 2024-07-26
Generative-AI-specific risks and suggested risk-management actions.