There is a particular kind of paralysis around the AI Act in mid-size companies. The text is long, the penalties are quoted in headlines, and nobody internally can say with authority whether a given project is allowed. So projects stall, and meanwhile staff keep using whatever tools they found themselves.
In almost every case we are called into, the resolution is the same and it is undramatic: the company is a deployer, not a provider; almost nothing it runs is high risk; and the obligations that do apply take about a month to satisfy.
Here is that month.
Days 1–5: inventory, including the parts nobody approved
You cannot classify what you have not listed. The inventory has three sources, and skipping the third is the most common mistake.
The first is the project list: what the business has formally proposed or built. The second is the vendor list: the AI features inside software you already buy — the assistant in your CRM, the summarisation in your helpdesk, the scoring in your recruitment tool. These are the ones that surprise people, because nobody decided to adopt AI; it arrived in a release note.
The third is shadow AI. Ask, without blame, what people are actually using. Expect the answer to include at least one general-purpose assistant that has seen company documents. Finding this out during the inventory is much cheaper than finding it out during an incident.
For each system, record: what it does, who uses it, what data goes in, whether output affects a person, and who supplied it.
Days 6–10: role and risk, system by system
Two questions settle most of the work.
Are you a provider or a deployer? You are a deployer if you use an AI system under your own authority. You become a provider — with a much heavier obligation set — if you put your name on it, or if you substantially modify a high-risk system, or if you repurpose a general-purpose model into a high-risk use under your own brand. Fine-tuning a model for internal use does not usually make you a provider. Shipping that model to customers as a feature can.
What risk class is it? Prohibited practices are narrow and mostly obvious once read: social scoring, certain biometric categorisation, emotion inference in the workplace and in education, untargeted facial image scraping. Read the list once against your inventory and be done with it.
High risk is defined by use, not by technology. The cases that catch ordinary companies are in employment — CV screening, task allocation, promotion or termination decisions — and in access to essential services such as credit scoring. An assistant that drafts emails is not high risk because it is clever; a simple rules-based tool that screens job applicants may be.
Everything else is limited risk, where the obligation is transparency, or minimal risk, where there is effectively nothing to do beyond good practice.
Record the reasoning, not just the conclusion. The decision record is the deliverable.
Days 11–15: the obligations that actually apply to you
For a deployer of a high-risk system, the core duties are: use the system in accordance with the provider's instructions; assign human oversight to people with the competence and authority to exercise it; ensure input data is relevant for the intended purpose to the extent you control it; monitor operation and inform the provider and the authority of serious incidents; keep the automatically generated logs; and inform affected workers before putting the system into service in the workplace. Certain deployers — public bodies and private entities providing public services, plus credit and insurance use cases — must also carry out a fundamental rights impact assessment.
For limited-risk systems, the duty is disclosure: people must know when they are interacting with an AI system, and synthetic content must be marked as such.
For every deployer, Article 4 requires AI literacy: staff who deal with these systems must have a sufficient level of understanding. This applies regardless of risk class, it applied from February 2025, and it is the obligation most companies have not noticed.
Days 16–22: the three documents
Governance does not have to be heavy, and heavy governance is how projects die. Three artefacts are enough for a company of this size.
An AI register. One row per system: name, owner, purpose, role, risk class, data used, review date. Kept where people will actually update it.
An acceptable-use policy. Short. Which tools are approved, what may and may not be pasted into them, what must be checked before output is used externally, and who to ask. Written to be read in three minutes.
An approval route. A lightweight form and a named reviewer for new use cases, with a service level — two working days, not two weeks. If approval is slow, teams will route around it, and you will be back to shadow AI with better paperwork.
Days 23–27: literacy, delivered
Two sessions: one for staff who use these tools daily, one for the people who decide whether to buy them. Content that is specific to your systems, not generic. What these models do well, how they fail, what must never go into a prompt, and what "human oversight" means in your context.
Record attendance. That record is your Article 4 evidence.
Days 28–30: the security work you now know you need
The inventory will have surfaced at least one thing that is a security issue rather than a compliance one. It is almost always the same thing: an assistant connected to a document store that inherits every over-broad permission ever granted.
Scope that work, even if you cannot do it this month. An AI system that can read everything one of your employees can read is a compliance question only after it is an access-control question.
What you have at the end
A list of every AI system in the company, a defensible classification for each with the reasoning recorded, three short governance documents, a trained staff with the attendance to prove it, and a security backlog item that was invisible thirty days ago.
That is the whole of the AI Act for most mid-size deployers. It is a month, not a programme, and the companies that do it stop being blocked — which is the actual benefit.