- Risk classification → teams need a defensible view of where their system sits
- Annex IV documentation → high-risk systems require structured technical documentation
- Human oversight and controls → not just policy language, but clear operational ownership
- Post-market monitoring → ongoing responsibility after deployment
- Unclear system boundaries → what exactly is “the AI system”?
- No clear classification stance → uncertainty between limited vs high-risk
- Fragmented ownership → product, legal, and engineering are not aligned
- Documentation gaps → nothing structured enough for procurement review
- Reactive approach → starting documentation only when buyers ask

