Blog
AI Governancebluebill.io — Mirco Francioni

EU AI Act readiness for scaleups: a practical checklist

You probably do not need a compliance department. You do need an inventory, a risk classification and evidence you can show.

EU AI Act readiness for scaleups: a practical checklist

Start with an inventory

You cannot classify what you cannot see. List every AI system in use: products you ship, vendor features you have switched on, and internal tools. For each one record the purpose, the model or vendor, the data it touches and the owner.

Classify by risk, honestly

Most scaleup use cases are limited or minimal risk: support drafting, content generation, internal search. Some are not. Anything touching hiring, credit, education or biometrics sits in a stricter bracket and needs documentation, human oversight and logging.

Transparency obligations are the easy win

Tell users when they are interacting with an AI system, and label synthetic content. This is cheap to implement and it is the obligation most often missed in a review.

Evidence beats intent

Auditors ask for artefacts, not policies. Keep: the inventory, the risk classification with reasoning, model and prompt version history, evaluation results, incident records, and logs of who accessed what.

Where a gateway helps

Routing model traffic through a single gateway gives you logging, redaction and per-team policy in one place. It turns most of the evidence requirements into a byproduct of how the system already works, rather than a quarterly scramble.