# EU AI Act Global Compliance Roadmap and Vendor Questionnaire

The strategic question for a non-EU company: apply EU AI Act standards everywhere, or only to EU-facing systems. A global-vs-tiered decision framework, a vendor EU AI Act questionnaire, and a high-risk compliance roadmap.

**Who this is for:** The compliance leader at a global company deciding how far the EU AI Act reaches into non-EU operations.

Source playbook: https://aigovernance.com/playbook/eu-ai-act-global-operations

---

## Global vs. tiered compliance decision framework

_A structured way to decide whether to hold one global standard or segment by market._

### Template

| Factor | Points toward one global standard | Points toward tiered by market |
|---|---|---|
| Share of systems or revenue touching the EU | High | Low and stable |
| Cost of maintaining two system variants | High (shared codebase, hard to fork) | Low (already region-segmented) |
| Other jurisdictions trending toward EU-like rules | Yes | No |
| Customer expectation / competitive positioning | EU-grade is a selling point | Price-sensitive, no demand |
| Internal capacity to run parallel compliance regimes | Limited | Ample |
| **Decision:** | | |
| **Systems in scope for EU-grade treatment:** | | |
| **Review date for this decision:** | | |

### Worked example

| Factor | Assessment |
|---|---|
| EU exposure | ~30% of enterprise revenue; growing |
| Cost of two variants | High: single codebase, forking oversight logic is expensive |
| Other jurisdictions | Several US states and the UK trending toward risk-based rules |
| Customer expectation | EU-grade governance is used in enterprise sales globally |
| Internal capacity | One compliance team; cannot run two regimes well |
| **Decision** | One global standard at EU-AI-Act high-risk level for all Annex-III-equivalent systems |
| **In scope** | Resume Screener, Fraud Scoring, any future consequential-decision system |
| **Review date** | 2027-06-01 |

### Acceptance criteria

- The decision is made deliberately with the factors documented, not by default.
- It names exactly which systems get EU-grade treatment.
- It has a review date, since exposure and the regulatory landscape shift.

---

## Vendor EU AI Act compliance questionnaire

_What to ask an AI vendor whose product is part of an EU high-risk system._

### Template

| Question | Vendor response | Evidence | Gap |
|---|---|---|---|
| What is your role under the EU AI Act for this product (provider, GPAI provider, other)? | | | |
| For GPAI: do you provide the Article 53 technical documentation and the training-content summary? | | | |
| Do you supply the information a downstream provider needs to meet Annex IV and Article 13? | | | |
| Do you support our conformity assessment with test results, model cards, and data governance evidence? | | | |
| Will you notify us of changes that could affect our compliance, and in what window? | | | |
| Do you have an authorised representative in the EU (if established outside)? | | | |

### Worked example

| Question | Vendor response | Evidence | Gap |
|---|---|---|---|
| Role under the Act | GPAI model provider | vendor legal statement | none |
| Article 53 docs + training summary | Yes, under NDA | doc portal access | none |
| Downstream provider info for Annex IV / Art. 13 | Partial | model card + eval summary | need input-data specs and known-limitation detail |
| Support for our conformity assessment | Yes | test result pack | none |
| Change notification | Changelog only | public changelog | need contractual notice window; redline sent |
| EU authorised representative | Yes | name + address provided | none |

### Acceptance criteria

- The vendor's role under the Act is established and recorded.
- Gaps in the information you need for your own conformity assessment are tracked to closure.
- A change-notification commitment is secured in the contract.

---

## High-risk system compliance roadmap

_The plan to get one system from where it is to conformity, with dates._

### Template

| Workstream | Current state | Target | Owner | Due | Dependencies |
|---|---|---|---|---|---|
| Risk management system | | Art. 9 process operating | | | |
| Data governance | | Art. 10 evidence complete | | | |
| Technical documentation | | Annex IV current | | | |
| Logging | | Art. 12 in production | | | |
| Human oversight | | Art. 14 designed and verified | | | |
| Accuracy / robustness / security | | Art. 15 evidence | | | |
| FRIA | | completed | | | |
| Conformity assessment + declaration | | signed | | | |
| EU database registration | | registered | | | |

### Worked example

| Workstream | Current | Target | Owner | Due | Dependencies |
|---|---|---|---|---|---|
| Human oversight | override exists; no low-score review | review step for bottom quartile | Talent | 2026-10-10 | UI change |
| FRIA | not started | completed | Legal | 2026-10-31 | oversight design final |
| Technical documentation | drafted | Annex IV current | Compliance | 2026-11-15 | eval refresh |
| Conformity assessment | 6 of 9 requirements met | declaration signed | Compliance | 2027-06-01 | above three |
| EU database registration | not started | registered | Compliance | before 2027-12-02 | conformity done |

### Acceptance criteria

- Every Chapter III workstream has an owner, a due date, and its dependencies.
- Dates chain back from the applicability deadline, not forward from today.
- The roadmap is reviewed on the same cadence as the compliance calendar.

---

## Governance controls this kit produces evidence for

- **CMP-007**: The roadmap and vendor questionnaire drive the EU AI Act conformity assessment for global systems.
- **CMP-001**: The global-vs-tiered decision is a multi-jurisdiction compliance strategy artifact.
- **PRC-002**: The vendor questionnaire feeds EU-AI-Act-specific clauses into vendor contracts.
- **HOC-001**: Scoping which systems get EU-grade treatment depends on risk classification.
- **MGV-003**: The high-risk roadmap is a governance-program milestone plan.
