The EU AI Act has direct consequences for the architecture of an AI system, not just for the paperwork around it. Organisations that only encounter the Act during an audit often find the architecture has to be redone. A workshop that ignores the Act delivers a blueprint that cannot legally be built.
In the data and compliance block we determine the risk classification. We explicitly check whether the use case falls under Annex III (HR decisions, credit decisions, education allocation, critical infrastructure, law enforcement, migration and asylum, administration of justice, democratic processes) or under a prohibited practice from Article 5. For a high-risk classification, we work out the initial mapping against Articles 9 to 15: the risk management system, data and data governance requirements, technical documentation, logging, transparency, human oversight and robustness. That mapping feeds directly into a different logging layer, a different oversight flow and a different model card discipline.
We also work out the link with the GDPR, the need for a DPIA and, for financial institutions, DORA. For sector-specific regimes we bring in the relevant references: NEN 7510 in healthcare, the algorithm assessment framework for public bodies, and sector guidelines in financial services. The workshop does not replace a formal DPIA or audit; those belong to implementation. However, the mapping in the blueprint is complete enough for you to build your AI development approach on, and for your legal or compliance officer to form an initial view. For sectors where that distinction is critical (healthcare, financial, public), a compliance specialist with sector expertise joins the table.