EU AI Act Readiness
The EU AI Act uses a risk-based framework and assigns different responsibilities to providers, deployers, importers, distributors, and other actors. Classification depends on the actual use case and role, not on the product name or model alone.
This page is an operational starting point, not legal advice. The implementation timeline and supporting rules continue to evolve. Confirm the current position with legal counsel and the official EU sources before relying on a classification or deadline.
Use-Case Review
For every production use case, record:
- Intended purpose, users, affected people, and business process.
- Whether Siesta AI, the customer, or another party is acting as provider or deployer for the use case.
- Whether the use falls into a prohibited, high-risk, transparency, or minimal-risk area.
- Which model, data, tools, decisions, and human oversight are involved.
- Which records demonstrate risk management, testing, logging, instructions, and monitoring.
- Who owns ongoing review and serious-incident escalation.
Operational Evidence
High-impact use cases commonly need stronger evidence around:
- risk assessment and mitigation,
- data quality and governance,
- technical and user documentation,
- logging and traceability,
- human oversight,
- accuracy, robustness, and cybersecurity,
- post-deployment monitoring and incident handling.
Transparency duties may also require users to know they are interacting with AI or that content was generated or manipulated by AI. Implement disclosure in the actual interface and workflow, not only in a policy document.