EU AI Act Deployer Guide: Your 90-Day Action Plan
Almost everything written about the EU AI Act is written for companies that build AI. Model providers. Foundation model labs. Conformity assessment bodies.
That is not you.
You buy AI, configure it, and put it to work. HR screening tools. Customer chatbots. Fraud detection. Admissions support. That makes you a deployer under the Act, and the deployer’s chapter (Article 26) is the one most likely to get you fined. The provider content flooding your inbox is aimed at someone else.
I run cybersecurity and AI governance at a university with 11,500 students and 3,000 staff. We do not train foundation models. We deploy other people’s AI in dozens of places: admissions, HR, the helpdesk, exam proctoring, research computing. When the transparency obligations went live on August 2, 2026, I was the person who had to answer the question: where is all of it, and are we compliant?
This is the 90-day plan I wish someone had handed me. It is written from the deployer seat, not the law firm conference room.
The uncomfortable numbers
A February 2026 industry report found that 78% of enterprises have taken no meaningful EU AI Act compliance steps, and 83% lack a systematic AI inventory. Read that second number twice. You cannot classify, govern, or evidence the compliance of systems you cannot see.
The fines are not theoretical anymore. Transparency violations can reach 15 million euros or 3% of global turnover. Prohibited practices go to 35 million euros or 7%. The AI Office can already open investigations and issue documentation requests.
And here is the part nobody puts in the headline: only about 8 to 10 of the 27 EU member states have designated their AI Act enforcement contacts. Enforcement will be uneven and patchy at first. That is not a reason to relax. It is a reason to get your house in order while the inspectors are still finding their desks.
The two-speed timeline: what is live now vs. what comes later
The Digital Omnibus created a split timeline, and you need to understand both speeds.
Live now (enforceable today):
- Article 50 transparency: chatbots and AI assistants must disclose they are AI. Deepfakes and AI-generated content must be labeled. AI-generated public-interest text needs machine-readable marking (C2PA or equivalent).
- Article 4 AI literacy: staff using AI need training proportional to their role. In force since February 2025.
- Prohibited practices: social scoring, manipulative AI, real-time biometric surveillance. Banned since February 2025.
- GPAI duties: general-purpose model obligations since August 2025. Mostly your vendors’ problem, but you should know they exist.
December 2, 2026: content-marking obligations extend to AI systems placed on the market before August 2026. Your existing chatbot fleet is not grandfathered forever.
December 2, 2027: full high-risk deployer obligations for standalone Annex III systems (hiring, credit, education access, insurance pricing), delayed from August 2026 by the Omnibus. Product-embedded systems follow in August 2028.
My read, as a practitioner: the delay is runway, not a holiday. The obligations did not shrink. The clock just got longer. Every CISO treating December 2027 as “later” is making the same mistake companies made with GDPR in 2016.
The 90-day plan
Days 1-30: See your AI footprint
Everything downstream depends on the inventory. In my framework (AIGF), this is Domain 1, and I put it first for a reason: every control you build later points at this list.
Week 1: pull the cheap signals. SSO and OAuth grant logs (which AI tools hold grants to your Google Workspace or Microsoft 365?), CASB or secure web gateway discovery, expense and procurement records for AI subscriptions. One afternoon of log work usually surfaces 60 to 70% of the footprint.
Week 2: run a one-week amnesty. Ask every department what AI tools they actually use to get work done. State in writing that nobody gets in trouble. You will learn more in a week of amnesty than in a quarter of top-down discovery, because people hide tools they think will be taken away.
Weeks 3-4: normalize and record. For each system capture five fields: what it is, who owns it, what data it touches, whether it decides or merely assists, and which vendor provides it. That distinction (decide vs. assist) is the single most important classification input you have.
Output: a living register, not a spreadsheet that dies in a shared drive. Review it monthly. AI footprints decay fast.
Days 31-60: Classify and assign
Sort the inventory into the Act’s risk tiers:
- Prohibited: if you find social scoring or manipulative systems, shut them down. This should be a short list, ideally empty.
- High-risk (Annex III): hiring and HR screening, credit and insurance pricing, education admissions, biometric identification, critical infrastructure. These carry the Article 26 deployer duties.
- Transparency tier: customer-facing chatbots, AI-generated content, emotion recognition. Article 50 applies now.
- Minimal risk: spam filters, internal recommenders. Document and move on.
For every high-risk system, do three things:
First, read the provider’s instructions for use. This sounds obvious. Almost nobody does it. Operating outside the documented intended purpose can transfer liability from the provider to you. Get the instructions, archive them, and check your actual use against them.
Second, name a human overseer. Not a committee. A person, with the competence, training, and actual authority to intervene, override, or shut the system down. Article 26(2) requires this explicitly, and “the team watches it” will not survive an audit.
Third, check your data. If you control the input data, it must be relevant and representative for the purpose. Biased inputs plus a high-risk system equals a fundamental rights problem, which is exactly what the Act was written to punish.
Days 61-90: Build the evidence file
Compliance without evidence is a story you tell yourself. Regulators ask for artifacts.
Logging: high-risk systems must keep automatically generated logs for at least six months. Verify the logs exist, are accessible, and are retained. Coordinate with your GDPR retention schedules so the two regimes do not fight each other.
Fundamental rights impact assessment (FRIA): required before first use for public bodies, private providers of public services, and deployers of credit scoring or life and health insurance pricing systems (Article 27). If this is you, start now. It cannot be backdated credibly.
Worker notices: inform employees and their representatives before deploying workplace AI that affects them. Do this before go-live, not after someone files a complaint.
Incident path: define what counts as a serious incident, who decides, and who notifies the provider and the market surveillance authority. A decision made for the first time during an incident is a decision made badly.
Board reporting: your board needs one page: how many AI systems, how many high-risk, what is the exposure, what did we spend. I report 12 decision-ready metrics to my board every quarter, and AI governance is now one of them (CISO board report guide).
The deployer checklist
| Article 26 duty | What to actually do | Evidence to keep |
|---|---|---|
| Use per provider instructions (26(1)) | Archive instructions; check real use vs. intended purpose | Instruction documents, use-case register |
| Human oversight (26(2)) | Name an overseer per high-risk system; give them override authority | Oversight assignments, training records |
| Input data quality (26(4)) | Define relevance criteria; run periodic checks | Data quality records |
| Monitoring and reporting (26(5)) | Monitoring protocol; incident thresholds; suspension mechanism | Monitoring logs, provider notifications |
| Log retention (26(6)) | 6-month minimum retention, secure storage | Retention policy, log samples |
| Worker information (26(7)) | Notify workers and reps before deployment | Dated notices, consultation records |
| Affected-person information (26(11)) | Tell people when AI influenced a decision about them | Notice templates, delivery logs |
| FRIA (Art. 27, where required) | Complete before first use | Assessment document, authority notification |
Five mistakes I see CISOs making right now
- “Our vendor is compliant, so we are fine.” Your vendor’s conformity assessment covers their obligations, not yours. Deployers carry independent liability. “Our vendor is compliant” is not a defense for deployer failures. Read that twice too.
- Treating the Omnibus delay as a pause. The work did not shrink. The standards, guidelines, and conformity procedures are still being finalized, which means early movers get to shape their program instead of bolting it on under deadline pressure.
- Letting legal own it alone. Legal interprets the Act. But inventory, logging, oversight staffing, and monitoring are operating-model problems. If your AI governance program lives entirely in the legal department, you have a memo, not a program.
- Assuming chatbots are “minimal risk.” A customer-facing chatbot is not minimal risk under this Act. It sits in the transparency tier, and those obligations are live now. I have seen three chatbot deployments this year where nobody had checked the disclosure requirement.
- Skipping AI literacy. Article 4 has been in force since February 2025, and workforce AI literacy scores are dismal across every benchmark I have seen. Literacy is the cheapest control in this entire regulation. There is no excuse for not having it.
Where this fits: the AIGF connection
This 90-day plan is the deployer-flavored execution of two domains of the Ozkaya AI Governance Framework: Domain 1 (AI Inventory and Classification) and Domain 4 (Regulatory Compliance). The framework gives you the standing operating model; this plan gives you the first 90 days of motion inside it. For the bigger picture, start with the AI governance hub, and grab the free controls checklist in the CISO toolkit.
The bottom line
You are almost certainly a deployer. The deployer obligations are concrete, they are already partially live, and 78% of your peers have done nothing. That is not a comforting statistic. It is an opportunity. The CISOs who build the inventory, name the overseers, and file the evidence now will spend 2027 answering board questions with confidence while everyone else scrambles.
Start with the inventory. Everything else follows.
Enjoyed this? The Ozkaya Brief is my weekly newsletter for CISOs: one AI governance lesson, one breach breakdown, zero fluff. Join 5,000+ security leaders.
