Diligence
What does August 2nd ask of your architecture?
The EU AI Act's high-risk obligations begin applying in weeks. Most of the readiness work is architecture, not paperwork. The two-week version.
By TIS Partners · · 1 min
The EU AI Act's obligations arrive on a published schedule, and the next tranche, covering high-risk systems, begins applying August 2nd. The legal analysis is your counsel's department. The part that lands on architecture is ours, and it is larger than most compliance programs have noticed.
Consider what the obligations assume a system can do: demonstrate what data trained or grounded a decision, log operation sufficient to reconstruct an outcome, support human oversight that can actually intervene, and report on accuracy in operation, not just at evaluation time. Every one of those is an architectural property. A system that cannot trace a decision to its inputs does not become traceable by hiring a compliance officer; it becomes traceable by engineering, on engineering timelines.
So the question in the title, put to a review: which of your AI-touching systems could, today, answer for one production decision from last Tuesday? Inputs, model version, prompt or features, confidence, and who could have overridden it. If the answer is a log-diving expedition, the gap is not documentation. It is design, and August is not when to discover that.
The two-week version for teams starting late: inventory the systems where model output affects a person's access to money, work, or services, because that is roughly where the high-risk perimeter falls. For each, test the one-decision reconstruction above and file the result. What reconstructs is a documentation task. What does not is an engineering backlog item with a regulatory date attached, which is the easiest funding argument any architect will make this year.
Whether your systems sit inside the EU's reach is a question for counsel. Whether they can answer for their decisions is a question regardless; the Act merely put a date on it.