Compliance 12 min read

30 Days Left: The Final-Sprint Triage Plan for High-Risk AI Compliance

With 30 days to August 2, full compliance may no longer be achievable for every system. This ruthless triage framework tells you what must be done by the deadline, what to document as best-efforts, what to defer — and how to build a minimum defensible position.

By Sarah Jenkins · Published

When Full Compliance Is No Longer on the Table

At 30 days out, some organizations face an uncomfortable reality: not every high-risk AI system will be fully compliant with the EU AI Act by August 2, 2026. The instinct is to spread effort thinly across everything. That is the wrong move. The final month calls for ruthless triage — concentrating scarce resources where legal exposure is highest and building a defensible position everywhere else.

The Three-Bucket Triage Framework

Bucket 1 — Must do by Aug 2: anything touching prohibited practices (Article 5); human oversight (Article 14); logging (Article 12); and shutting down or restricting systems that cannot be made safe. Bucket 2 — Document best-efforts: Annex IV technical documentation, risk management (Article 9), and data governance (Article 10) — complete what you can and log the gaps with remediation dates. Bucket 3 — Defer with a plan: nice-to-have refinements, non-high-risk systems, and optimisation of already-adequate controls.

The Minimum Defensible Position

For everything that can't reach full compliance, the goal is a minimum defensible position — the evidence set that shows a market surveillance authority you acted in good faith. It has four components: an honest gap register with dated remediation plans; substantially complete draft technical documentation; operational controls (oversight and logging) live in production; and governance evidence such as board sign-off, budget, and named owners. Authorities weigh good-faith effort heavily; the difference between a warning and a fine is often the difference between a documented gap register and a shrug.

The Day-by-Day Final Month

Day 30–27: run the triage and sort every high-risk system into buckets with legal sign-off. Day 26–20: close all Bucket 1 items and restrict or withdraw anything unsafe. Day 19–12: complete Bucket 2 documentation to best-efforts and build the gap register. Day 11–6: run an internal mock audit, assemble per-system evidence packs, and prepare registrations. Day 5–1: executive sign-off, issue declarations of conformity where ready, and brief incident response.

The Bottom Line

Triage is not surrender — it is strategy. By concentrating the final 30 days on non-negotiables and building a minimum defensible position everywhere else, you convert an impossible "comply with everything" into an achievable "be honestly, demonstrably diligent." That is what withstands scrutiny after August 2.

Need an experienced pair of hands for the final sprint? Browse our directory of AI Act consultants who specialise in rapid remediation.