The EU AI Act: what's worth preparing now

Enforcement is still ahead, but the documentation it will demand gets written during the project or never gets written.
The EU AI Act is coming, enforcement is still years away, but the documentation it will demand gets written now or never written. You cannot reconstruct the rationale for decisions once the team moves on. You cannot replicate an experiment after the data is archived.
Training data records, evaluations, known limitations and human oversight are all cheap if you write them as you build. A paragraph after every significant decision costs almost nothing. Writing that same paragraph in a rush before an audit is miserable.
Reconstructing them two years later, with the original team scattered, is a project in itself. The engineer who made the choice has moved on. The dataset is on an old backup. The decision that seemed obvious at the time is now just a comment in the code.
High-risk systems — hiring, credit, benefit eligibility — will need explicit governance. Documentation isn't enough. You need records of human review and a process for complaints. Building that into the initial design is easier than grafting it on later.
We add a system card to every AI delivery. It runs two pages and has already prevented two awkward audits. Known limitations, training data summary, the evaluation methodology, and who reviewed the output before it went live. Nothing elaborate, just enough to explain the work.
The audit season is coming. The cheap time to prepare is now.