Most organizations lack the tools to verify EU AI Act compliance – researchers say LLM agents could help

With the EU AI Act now in force, organizations that develop or deploy AI systems face a thicket of new legal obligations covering transparency, risk management, documentation, and human oversight. A new academic survey suggests most of them are not ready to meet those requirements – and that the gap between legal text and verifiable evidence is wide enough to need automated tools.

The study, published as a preprint on arXiv and led by researchers from Fraunhofer IAIS and Pontificia Universidad Catolica de Valparaiso, conducted expert interviews and an online survey with 25 participants spanning requirements engineering, data science, development, and compliance roles. The results paint a picture of an industry that recognizes the AI Act’s importance but has not built the systematic processes needed to translate its obligations into testable specifications.

The core challenge is one of translation. The AI Act’s articles impose high-level duties – conduct a risk assessment, maintain technical documentation, enable human oversight, ensure data governance – but offer limited guidance on how to verify that these duties have been fulfilled. A requirements engineer reading Article 9’s mandate for a risk management system has little in the way of concrete, auditable checklists to implement. The researchers found that structured mechanisms to capture regulatory obligations, propagate updates into active projects, and maintain lifecycle-wide traceability are “often missing” across the organizations surveyed.

The paper proposes that LLM-based agentic validation tools could bridge this gap. The idea is to use large language models to map regulatory text to specific requirements, assess coverage against existing documentation, and organize evidence into audit-ready packages. Survey participants viewed this approach as promising but expressed strong reservations about full automation, emphasizing that human oversight and safeguards remain essential.

If you found this article useful, please consider helping us keep 1ban.news independent.

Make a difference

The study arrives alongside related work on the same problem. A separate paper published in December 2025 and updated in April 2026 presents a structured mapping from the AI Act’s high-level requirements to specific verification activities across the AI lifecycle, decomposing legal obligations into operational sub-requirements grounded in existing standards. Together, the two papers illustrate a growing realization that the AI Act’s success depends on practical tooling as much as legislative intent.

For organizations subject to the AI Act, the window to build compliance infrastructure is narrowing. The Act’s provisions are phasing in through 2026 and 2027, with prohibitions on unacceptable-risk practices already in effect and obligations for high-risk systems following close behind. The tools to verify compliance, the research suggests, are still largely hypothetical.

Sources: From Obligation to Specification: A Survey on Validating EU AI Act Requirements in RE (arXiv:2607.21608, May 2026); Assessing High-Risk AI Systems under the EU AI Act: From Legal Requirements to Technical Verification (arXiv:2512.13907, December 2025 / April 2026); EU AI Act: first regulation on artificial intelligence (European Parliament, 2026)

Scroll to Top