Strategic answer
Conformity assessment questions should follow high-risk triage.
Conformity assessment is not the first operational step for every AI project. A company should first determine whether the system is in scope, whether high-risk logic may apply, and whether the current evidence base can support deeper review.
Start with the EU AI Act Diagnostic, turn findings into an implementation plan, and see how the diagnostic works as a reference app on M13.
Exposure focus
What needs to be clear first
- The intended purpose and operational setting of the AI system.
- Whether the use case falls into a sensitive or regulated area.
- Whether the company acts as provider or has provider-like responsibility.
- Whether documentation, testing, oversight and monitoring evidence exists.
First action
What to do first
- 01Confirm role and intended use.
- 02Run high-risk triage against the actual workflow.
- 03Map missing technical and governance evidence.
- 04Escalate formal assessment work only for systems that need it.
This page provides operational information for AI governance readiness. It is not legal advice.