AI for Business
Where so many get it wrong, and what the EU AI Act now makes you show
A record of making one real business compliant, written while it happened, including the parts that went wrong. Fifteen chapters, ordered by what goes wrong rather than by what the Act lists.
The argument
The compliance work and the good-engineering work are the same work.
Article 26(5) requires that you can suspend a system. That is a kill switch, and every operator wants one; almost none have tested theirs. Article 12 requires records of what the system did. That is observability. Article 26(2) requires a human who can meaningfully intervene. That is a review step you already believed you had.
Work through it and you end up with a list of every AI system you run, a written statement of what each is for, records of what they decided, a way to stop them, and a description of where the data goes. If the regulation were repealed tomorrow you would keep all five. The regulation forced the question. That is genuinely all it did.
What it covers
The limited-risk path, done properly: inventory, roles, classification, Article 50 transparency in each of its forms, logging, oversight, suspension, the AI literacy duty, data-flow mapping, and machine-readable marking.
And what it does not. We ran no high-risk systems, so conformity assessment, technical documentation and fundamental-rights impact assessment are out of scope. The opening says so on the first page. If you operate an Annex III system, this book covers about half of what you need and tells you that before you buy it.
Every figure in it was read off a live system on a stated date. The failures are ours.
- 1You do not know what you are running
- 2You do not know whether you are a provider or a deployer
- 3Your reasoning is not written down
- 4Your records are the wrong records
- 5You cannot show the oversight you actually perform
- 6Your marking is deleted on the way out
- 7The obligation lands where you are not looking
- 8You cannot stop it
- 9Nobody told you this one existed
- 10It is not just you
- 11The fix you bought was not one
- 12What you read was already out of date
- 13It will change again
- 14From a file to a system
- 15What to do first, and why order costs money
The book ships a working artefact
Anyone can generate a compliance scanner in thirty seconds. What cannot be generated is knowing the tool is lying. So the book comes with a free, open test corpus of the cases where the naive verdict is wrong, and twenty-two of the twenty-five are our own tooling failing against our own systems.
Publication date and price to be confirmed. It will be sold as a practitioner title rather than a commodity guide, and the verification suite will stay free either way.