Part 2 — The 4-Step Compliance Pathway: The Fastest Way to Understand Your AI Act Obligations
Most people who read about the EU AI Act walk away feeling more confused, not less. There are annexes, risk categories, provider vs…
AI Act Explained (Part #2 )— The 4-Step Compliance Pathway: The Fastest Way to Understand Your AI Act Obligations

Most people who read about the EU AI Act walk away feeling more confused, not less. There are annexes, risk categories, provider vs. deployer obligations, conformity assessments, technical documentation, oversight rules… and none of it feels intuitive.
So where do you even start?
Here’s what hardly anyone tells you:
AI Act compliance has a specific order of operations. If you follow it, everything becomes clearer. If you don’t, you’ll waste weeks analysing systems that aren’t even AI or applying requirements that don’t apply to you.
The good news: there is a simple pathway through all of this. Four steps. Always the same order. Works for any organisation, any use case, any industry.
At **ExplorAI**, we use this framework every day to help organisations make sense of their obligations under the AI Act. And once you start thinking in this sequence, compliance becomes dramatically easier.
Why You Need a Framework

Most organisations approach the AI Act in the wrong direction.
One team starts worrying about high-risk systems. Another starts asking vendors for documentation. Someone else is stuck wondering whether their tools even count as “AI.”
The issue isn’t lack of effort — it’s lack of structure.
Without a sequence, you might:
- Over-analyse systems that aren’t even covered by the Act
- Apply obligations that don’t apply to your role
- Miss key requirements because you jumped ahead too soon
A structured pathway prevents that confusion.
The 4-Step Compliance Pathway

Here’s the method that cuts through the noise:
- Classify the Risk
- Confirm It’s Actually “AI”
- Determine Your Role (Provider or Deployer)
- Apply the Correct Obligations
Let’s break each one down.
STEP 1 — Classify the Risk
Is the system:
- Unacceptable risk (banned)?
- High-risk?
- Limited risk?
- Minimal risk?
This single classification determines almost everything else.
High-risk systems trigger extensive requirements. Minimal-risk systems require almost nothing.
This is why classification comes first: it defines the stakes.
STEP 2 — Confirm It’s Actually “AI”
A surprising number of tools that look like AI… simply aren’t.
Article 3(1) defines AI as systems that generate predictions, recommendations, or decisions using inference from data.
If a system is rules-based, deterministic, or pure automation, it may not be AI under the Act.
This step eliminates a massive number of false alarms.
STEP 3 — Determine Your Role
The AI Act treats different actors differently.
Are you a:
- Provider — developing, supplying, or placing the AI system on the market?
- Deployer — using the AI system in your organisation?
- Both ?— common with internally developed tools
Your obligations depend entirely on this classification.
Providers must perform conformity assessments, prepare technical documentation, and ensure CE marking. Deployers must ensure oversight, maintain logs, monitor performance, train users, and inform affected individuals.
Get this wrong, and you’ll implement the wrong requirements.
STEP 4 — Apply the Right Obligations
Only after completing steps 1–3 can you identify which requirements apply.
High-risk + Provider = the most extensive obligations High-risk + Deployer = oversight, documentation, monitoring Limited risk = transparency Minimal risk = nothing special
This sequence is the difference between efficient compliance and chaos.
Why This Sequence Matters
You might wonder: Why not start by checking if something is AI? Why not determine your role first?
Because:
- Risk comes first → It tells you how deep the analysis must go
- AI definition comes second → Even high-risk use cases don’t matter if the system isn’t AI
- Role comes third → Your obligations differ dramatically
- Obligations come last → Only meaningful once you know all the above
Skipping ahead leads to wasted time and misguided work.
A Real Example: HR Screening Tool

Let’s run a common system through the 4 steps.
The System
Software that screens CVs, ranks candidates, and sends top results to recruiters.
STEP 1: Risk Classification
Use case: employment decisions. Annex III, category 4: recruitment and worker management systems → high-risk.
✔ High-risk system.
STEP 2: Is It AI?
Uses ML models trained on historical data to generate suitability predictions.
✔ Yes, it meets the AI definition.
STEP 3: What’s Your Role?
Purchased from a vendor. You’re not developing or supplying it.
✔ You are the Deployer, not the Provider.
STEP 4: Apply the Right Obligations
Your obligations as a deployer include:
- Human oversight
- Logging
- Monitoring for bias
- Training of staff
- Informing candidates that AI is used
- Obtaining documentation from the provider
You do not need to:
- Perform conformity assessments
- Prepare technical documentation
- Affix CE marking
Those belong to the provider.
See how the framework removes uncertainty?
How to Use This Framework

Take the AI inventory you created in Part 1. Choose 2–3 systems and run them through the four steps:
- What’s the use case → What risk level might it fall into?
- Does it actually perform inference or machine learning?
- Are you the developer, deployer, or both?
- Based on that, which obligations apply?
You don’t need perfect answers yet. You’re building disciplined thinking that prevents mistakes later.
What to Do This Week
If you already have an inventory: 👉 Pick a few systems and practice the 4-step classification.
If you don’t have an inventory yet: 👉 Go back to Part 1. You must know what systems you have before you can classify them.
The AI Act is complex — but your approach doesn’t have to be.
A structured method is the key to navigating the Act with confidence.
Next Up
In Part 3, we dive into Step 1: Risk Classification — the foundation of everything that follows. We’ll show you exactly how to classify systems correctly and avoid common mistakes that organisations make.
ExplorAI also offers practical EU AI Act training for organisations working with high-risk AI systems. Learn more: explorai.eu/eu-ai-act-training
Resources
🔗 ExplorAI — AI Audit & Compliance Services https://explorai.eu Independent AI system assessments, high-risk evaluations, and readiness checks for the EU AI Act.
🔗 LinkedIn https://www.linkedin.com/company/exploraieu Follow for practical compliance insights and updates on the AI Act.
References
[1] Article 5 — Prohibited AI Practices https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-5
[2] Article 6 — Classification Rules for High-Risk AI Systems https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-6
[3] Article 3(1) — Definition of AI System https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-3
[4] Article 3(3) and Article 3(4) — Definitions of Provider and Deployer https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-3
[5] Article 16 — Obligations of Providers of High-Risk AI Systems https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-16
[6] Article 26 — Obligations of Deployers of High-Risk AI Systems https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-26
[7] Annex III — High-Risk AI Systems https://ai-act-service-desk.ec.europa.eu/en/ai-act/annex-3
This is the second in a 10-part series on practical AI Act compliance for real-world organisations. Next: Step 1 in detail — How to classify AI risk.
메타데이터
- post_id
- 42bc8558a8b6
- slug
- part-2-the-4-step-compliance-pathway-the-fastest-way-to-understand-your-ai-act-obligations-42bc8558a8b6
- url
- https://medium.com/@explor_ai/part-2-the-4-step-compliance-pathway-the-fastest-way-to-understand-your-ai-act-obligations-42bc8558a8b6
- canonical_url
- https://medium.com/@explor_ai/part-2-the-4-step-compliance-pathway-the-fastest-way-to-understand-your-ai-act-obligations-42bc8558a8b6
- author_url
- https://medium.com/@explor_ai
- status
- ok
- fetched_at
- 2026-07-27 19:47:14