The EU AI Act changes what an AI pilot may do, and what it must do in production. A sprint that ignores the Act delivers a prototype that is legally unusable. We take the Act into account from phase one, not as a barrier but as a design constraint.
In phase 01 we draw up a provisional risk classification based on the problem framing. In phase 03, when the model pattern and data become concrete, we sharpen that classification, because the precise shape of a use case can tip between limited and high risk. For a high-risk classification the scope shifts: articles 9 to 15 require a risk management system, data governance, technical documentation, logging, transparency towards users, human oversight and robustness, and we factor those requirements directly into the feasibility assessment.
We also work out the link with the GDPR, the need for a DPIA and, for financial institutions, DORA. For sector-specific regimes (NEN 7510 in healthcare, the assessment framework for public bodies), we bring in the relevant references. The report includes a section you can pass directly to your legal or compliance officer; for a deeper treatment, this ties into our AI development approach.
What the sprint does not do is produce a formal DPIA or audit report: that belongs to implementation, not validation. What it does do is prevent you from building on an assumption that, legally speaking, already ruled out the application in that form. A lot of wasted effort sits in the gap between "we heard it was allowed" and "it should have been built the way the Act prescribes".