How to Audit Your AI Systems Before the EU AI Act Deadline
AI Audit

How to Audit Your AI Systems Before the EU AI Act Deadline

The EU AI Act changes what “compliant” means for software companies. It raises the bar for organizations developing and deploying AI systems, particularly those operating in high-risk categories. Before key obligations apply, companies need a structured way to examine their systems, identify gaps, and prioritize what needs to be fixed. That is where an AI audit comes in.

Start with scope: which systems are high-risk?

Your audit must begin with classification. It should identify which AI systems fall into the high-risk category and are therefore subject to the strictest obligations.

Under the AI Act, high-risk AI systems mainly include:

  • AI used as a safety component of products or as products themselves covered by EU sectoral legislation in Annex I (e.g., certain medical devices, industrial machinery) that require third-party conformity assessment
  • AI used in sensitive Annex III use cases, such as employment, credit scoring, access to essential services, law enforcement, education, migration, or biometric identification, especially when decisions may significantly impact health, safety, or fundamental rights.

The Commission has published practical guidelines and examples to help organizations classify whether an AI system is high-risk or not. For some Annex III systems that do not pose significant risk, providers can document why they consider them non-high-risk, though this still triggers registration and oversight requirements.

Clarify your role: provider, deployer, or both?

The AI Act distinguishes between providers and deployers, and your obligations and audit checklist depend on which role you play.

  • Providers develop and place high-risk AI systems on the EU market or put them into service, including non-EU entities whose AI outputs are used within the EU. They are responsible for design-time compliance (risk management, data governance, documentation, robustness), conformity assessment, and registration in the EU database.
  • Deployers use high-risk AI systems in their operations, for example, HR teams using AI CV screening tools, or banks using AI credit scoring engines. They must ensure appropriate use, assign human oversight, manage input data quality, keep logs, inform affected workers and individuals, and in some scenarios perform fundamental rights impact assessments.

In practice, a single company can be both provider and deployer, for instance, a SaaS vendor building an AI hiring tool (provider) and its own HR team using that tool for internal recruitment (deployer).

Audit step: For each AI system, document whether your organization is acting as provider, deployer, or both. This determines which legal obligations and internal controls apply, and where you can rely on vendors versus building your own governance.

Establish or stress-test your AI risk management system

For high-risk AI, a risk management system across the entire lifecycle is a core legal requirement.

A compliant risk management system should:

  • Identify reasonably foreseeable risks to health, safety, and fundamental rights when the AI is used as intended, as well as foreseeable misuse scenarios.
  • Define structured mitigation measures (technical controls, process safeguards, human oversight, escalation paths) and link them to specific risks.
  • Incorporate post-market monitoring data (incident reports, complaints, performance anomalies) to update risk assessments iteratively over time.

Your audit should review risk registers, incident logs, governance policies, and escalation procedures to confirm they cover prohibited practices, bias and discrimination risks, cybersecurity threats, and misuse scenarios, with clear ownership assigned for monitoring and remediation.

Audit step: Create or refine a central AI risk register, link it to your incident management tooling, and ensure each high-risk system has explicit risk entries and mitigation measures.

Audit data governance and input data quality

The AI Act places specific obligations on data governance, both for training data (providers) and for input data used during operation (deployers).

For providers, the audit should check whether:

  • Training, validation, and testing datasets are relevant, sufficiently representative, and as free as possible from errors and biases for the system’s intended purpose.
  • There is detailed documentation of data sources, preprocessing steps, and measures to detect, prevent, and mitigate bias, including demographic and socio-economic bias.

For deployers who control input data, auditors must ensure:

  • Input data is relevant and sufficiently representative, and that there are controls to detect anomalies or drift that could undermine system performance or fairness.
  • All data processing complies with GDPR, ePrivacy, and sector-specific rules, including data protection impact assessments where required (for large-scale profiling, sensitive data, etc.).

Audit step: For each high-risk AI system, verify that training data documentation and input-data quality checks exist, are documented, and are reviewed at defined intervals.

Check transparency, human oversight, and user information

Transparency and meaningful human oversight are central pillars of the AI Act; both providers and deployers have duties here.

Providers must:

  • Supply clear instructions for use, describing system capabilities, limitations, and performance characteristics.
  • Design high-risk systems so that human operators can understand outputs, override decisions, or halt the system when necessary.

Deployers must:

  • Assign trained, competent individuals to exercise human oversight and provide them with guidance on when to intervene or suspend system use
  • Inform workers when a high-risk AI system is used in the workplace, and inform individuals when decisions affecting them are made or assisted by such systems, in line with Article 50 transparency requirements.

Audit step: Review training records, governance charters, and communication templates, and confirm that every high-risk system has assigned oversight owners and clear user-information mechanisms.

Review logging, recordkeeping, and documentation

The AI Act demands robust logging and technical documentation to enable traceability and regulatory supervision.

For providers, your audit should confirm that:

  • Technical documentation meets the AI Act’s minimum content requirements: system description, architecture, development process, risk management, data governance, performance metrics, and human-oversight design.
  • Systems automatically record events relevant to risk and substantial modifications, with logs retained for an appropriate period (often years) to support investigations and audits.

For deployers, auditors should check that:

  • Logs under their control are kept for at least six months, or longer if required by other EU or national laws.
  • Operational documentation on use cases, incidents, and corrective actions is maintained and can be shared with providers and authorities on request.

Align your audit roadmap to the AI Act timeline

Finally, your AI audit strategy must be grounded in the implementation timeline. The core rules for Annex III high-risk systems and transparency obligations start applying from 2 August 2026, while some Annex I product-integrated systems and proposed AI Digital Omnibus changes introduce later backstop dates, such as 2 December 2027 and 2 August 2028.

This implies that organizations should:

  • Prioritize auditing and remediating Annex III high-risk use cases already live or planned before 2026, particularly in HR, credit scoring, biometrics, and public-service contexts.
  • Build an AI governance framework that can scale to general-purpose AI (GPAI) and lower-risk systems, which face earlier obligations around transparency and training-data documentation.

By systematically addressing classification, roles, risk management, data governance, transparency, oversight, documentation, conformity assessment, registration, and incident response, you can move from reactive compliance to a proactive, trust-building AI strategy well ahead of the EU AI Act deadline.

Conclusion

The EU AI Act raises the standard for how AI systems are built and managed. Companies that begin auditing now will have a clearer path to compliance and fewer surprises as the remaining obligations come into force over the next two years.

Agiliway is an AI-augmented software development company that holds ISO/IEC 42001:2023 certification for AI management systems, reflecting the kind of structured risk management, data governance, and oversight processes the EU AI Act now requires of high-risk AI providers and deployers.