Here is the honest situation. Here is the honest situation. The AI Act does not ask how clever your model is. It asks what your system does, to whom, and in what setting, and it assigns duties by the risk that answer implies, which is why the obligations land on product and legal directly and why the hardest ones are decided by design choices made long before launch. Most teams meet the Act as a compliance panic once a launch is already committed, and they misjudge the tier because tier is driven by use and placement, not by how advanced the model is. Misclassify a system and you either overbuild for a tier you are not in or, far worse, ship a high-risk system with none of the controls it required. Doing this well does not mean buying tooling. It means rebuilding the judgement: settle scope and your role, work the risk ladder from the prohibited check down to a written tier, screen features against the banned practices at the concept stage, apply the high-risk regime as real build items, place the transparency disclosures where users meet them, mark AI-generated content both for people and for machines, version the documentation and logging with the system, and run a monitoring loop that keeps the tier honest as the product changes. Where teams fall short is predictable: scope assumed away, tier driven by model capability, prohibited designs caught late, human oversight that is a button no one uses, disclosures buried in a policy, no machine-readable marking, documentation reconstructed under deadline, and a launch classification filed and forgotten.
This Kit removes the guesswork. It is EU AI Act compliance written as adopt-ready controls you personalize in a weekend, with the evidence a product review, a legal sign-off or a conformity assessor examines.
What you get, the moment you buy
Grounded in the EU AI Act's risk-based structure applied to how product and legal teams actually build and ship: scope and provider or deployer roles, the risk tiers from prohibited through high-risk to transparency duties and minimal-risk, the transparency and content-marking obligations, machine-readable provenance, technical documentation and logging, and post-market monitoring. Editable Word and Excel files. This is a practitioner method, not legal advice or a substitute for your own reading of the Act, your regulatory obligations and qualified counsel.
What one control looks like
This is the opening control, where the assessment begins. All 18 are built to this depth.
Why this is not another template pack
- The evidence is the point. A system you cannot evidence as classified, disclosed, documented and monitored is a finding waiting to land. This tells you what a reviewer or a conformity assessor examines and where teams fall short, for every control.
- The Act's specifics built in. Provider and deployer roles, the risk ladder worked from the prohibited check down, meaningful human oversight, machine-readable content marking alongside the human-visible label, versioned documentation and logging, and re-classification triggers are written into the controls, not left generic.
- Built on real practice, not one person's opinion, grounded in how product and legal teams translate a broad regulation into a specific, defensible build and evidence trail.
- It compounds. This work shares its shape with AI management systems, AI risk management and data-protection governance, so it feeds your wider governance and compliance practice.
Who buys this
Product managers, legal counsel and compliance officers responsible for AI systems that serve users in the Union and who own the intended-use definition, the tier determination, the disclosure and marking builds, and the documentation and monitoring, and who have to prove their systems are classified, disclosed and defensible. Whether this is your first pass at the AI Act or a hardening pass on a system already live, you save weeks and walk in with your scope, classification, transparency, marking, documentation and monitoring controls structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Does it cover the whole AI Act compliance problem? Yes. Scope and risk-tier classification, prohibited and high-risk obligations, transparency and disclosure duties, content marking and provenance, technical documentation and records, and post-market monitoring and governance each have their own controls with their own evidence.
Is this tied to one kind of system? No. The controls are principle-level: role and scope, risk classification, prohibited and high-risk duties, transparency, content marking, documentation and monitoring, so they apply across chatbots, generative products, decision-support systems and more, alongside your team rather than replacing it.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com