How to prepare an AI project for EU requirements in one day

Brief guide for AI chatbots, assistants, RAG systems, and automations

Home. In one day, you can conduct an initial audit, address obvious gaps, and gather basic evidence of readiness. This does not replace a full assessment of high-risk AI systems or legal advice.

 

As of 2 August 2026, the transparency requirements of Article 50 of the EU AI Act apply. For businesses, this primarily means clear notification of interaction with AI, proper labeling of certain types of content, and the ability to demonstrate how the system is controlled.

First, determine: is this a standard or high-risk project?

Stop the one-day scenario and schedule a separate assessment if AI affects hiring, lending, access to education or essential services, uses biometrics/emotion recognition, or is related to safety and medicine.

  • Standard support chatbot or knowledge base search: most often, start with transparency, GDPR, security, and human oversight.
  • AI agent that sends emails, updates CRM, creates payments, or deletes data: add confirmation for critical actions and a detailed log.
  • High-risk case: deeper classification, risk management, technical documentation and possibly conformity assessment will be required.

Plan for one working day

Time Task Result
09:00–10:00 Inventory Map: AI features, users, data, integrations, actions, and responsible person.
10:00–11:00 Transparency Notification of interaction with AI is shown before or at the beginning of the first contact.
11:00–12:00 AI content Rules for labeling text, images, audio, video, and deepfakes.
12:00–14:00 GDPR Data minimization, legal basis for processing, retention periods, DPA, and privacy notice.
14:00–15:00 Logging Logs of agent actions, errors, human confirmations, and system versions.
15:00–16:00 Security Least privilege, key protection, limits, human approval, and emergency stop.
16:00–17:00 Documentation System passport, data schema, roles, risks, changes, and incident procedures.
17:00–18:00 Testing and fixing Screenshots, test cases, a sample log, and a signed decision on readiness/further development.

What exactly to do: a short instruction

1. Inform the person that they are communicating with AI

Show the message from the start of the first interaction. It should be clear, noticeable, and accessible. Do not hide the information only in the user agreement.

Ready text: “You are chatting with an AI assistant. It may make mistakes. For important or contentious issues, request to speak with an employee”.

 

2. Set rules for labeling AI content

Situation What to do
AI chatbot / agent Disclose AI interaction at the start of the conversation.
Deepfake: realistic image, audio, or video Add a clear visible label no later than the first display.
Text on a socially significant topic Label if it was created/substantially altered by AI and has not undergone meaningful human review.
Editorial content after real testing A separate label is usually not required if a person can modify/reject the text and bears editorial responsibility.
Your own generative AI service Check machine-readable labeling and discoverability of output content.

3. Minimize the use of personal data

  • Do not send names, phone numbers, documents, or correspondence to the model if the task can be solved without them.
  • Document the purpose and legal basis for processing, update the privacy notice, and review contracts/DPAs with vendors.
  • Set retention periods for conversations and logs; restrict access and account for data transfers outside the EEA.
  • If the processing is likely to pose a high risk to individuals, separately assess whether a DPIA is required.

4. Enable AI agent activity logging

For high-risk AI, automatic logging is a direct requirement. For a regular agent, it is a practical measure: without logs, it is difficult to investigate an error and prove that a human confirmed a critical action.

Block What to record
Minimum Time; operation ID; workflow/model version; tool or action; result/error; human confirmation.
Do not store unnecessarily Full passwords, API keys, payment details, unnecessary personal data, and the full prompt.
Control Retention period, access rights, protection against changes, and clear incident search.

5. Limit permissions and keep people in control

  • Grant the agent only the necessary permissions; store keys in secure storage, not in the prompt or code.
  • Require confirmation before sending messages, publishing, making payments, deleting, or changing important data.
  • Add rate limits, an action allowlist, a fallback scenario, a stop button, and an error notification.
  • Check for prompt injection, data leakage, incorrect tool, repeated action, and model unavailability.

6. Gather the minimum required documents

Document Contents
AI system passport Purpose, users, owner, model, suppliers, integrations, and usage boundaries.
Data schema What data is included, where it is transferred, where and for how long it is stored.
Risk Register Error, impact, likelihood, control, owner and residual risk.
Human oversight Which decisions are reviewed by a human and how to stop/cancel an action
Change & incident log Versions, changes, tests, failures, actions taken, and responsible parties.

Final readiness checklist

Mark an item only when there is evidence: a screenshot, setting, document excerpt, test, or log entry.

Check Proof
An AI project owner and incident manager have been assigned. Name and role
The purpose, users, model, providers, and integrations are described. System passport
Checked whether the scenario involves high-risk or prohibited practices. Classification result
The user sees an AI notification from the start of the first interaction. Screenshot
There is a clear way to reach an agent for complex and disputed cases. Dialogue test
Cases of visible and machine-readable content labeling have been defined. Publication rule
Substantive review and editorial responsibility have been assigned to socially significant texts. Editor / order
Only necessary personal data is collected. Field list
Privacy notice, legal basis for processing, DPA, retention periods, and cross-border transfer have been reviewed. GDPR check
Logs record the action, version, result, error, and human approval. Sample log
Secrets never end up in the prompt, logs, or repository. Secrets check
The agent has minimal permissions; dangerous actions require confirmation. Access matrix
Limits, emergency shutdown, and a fallback scenario are configured. Failure test
Errors, prompt injection, repeated actions, and data leaks have been tested. Test report
Procedures for changes, retesting, and incident logging have been defined. Change/incident log
Employees working with the system have received AI training. Training record

What should be ready by the end of the day

  • user notification and content labeling rules;
  • system passport, data schema, risk register, and human oversight procedures;
  • sample log, access matrix, test results, and a list of improvements with priorities.

Important. The AI Act does not exist separately from GDPR, cybersecurity, consumer and sector-specific legislation. This checklist is an initial technical review, not universal proof of compliance.

 

How CenterAI can help

CenterAI conducts a practical AI audit: reviews workflows, data and access, identifies obvious risks, and recommends transparency settings, logging, human approval and a minimal documentation package. After the audit, the necessary improvements can be implemented separately.

Discuss an AI project and book a consultation: https://centerai.eu/

Leave a Reply

Your email address will not be published. Required fields are marked *