EU AI Act: Your Top 3 Pre-Project Priorities
Originally published on LinkedIn, May 2024.
The EU AI Act clock is ticking. Most of the advice circulating right now tells you to launch immediately: identify your AI systems, conduct gap analyses, establish governance boards. All of that work is necessary. But there are three things you need to do first that will determine whether your EU AI Act programme succeeds or stalls before it gets started.

These three priorities are visualised in a one-page pre-project game plan that can be presented to senior leadership in under fifteen minutes.
Priority 1: Get Leadership Attention and Secure Initial Funding #
Before you walk into any room with senior leadership, do your homework.
Review your company’s business strategy — specifically its existing and planned use of AI systems. Identify the senior colleagues responsible for executing that strategy and who have the most at stake in how AI is deployed. Understand your company’s role under the Act: are you a provider, a deployer, a product manufacturer, or some combination?
Then build a brief education pack for those senior stakeholders. The critical point here is framing. Lead with value creation and business strategy execution, not with the Act’s penalty tiers of 7%, 3%, and 1% of global turnover. Mention the penalties — they are real — but do not use them as a scaremongering device. Include narratives and analogies that connect directly to your company’s strategic objectives. The goal is to position this work as a business enabler, not a compliance burden.
Keep the initial engagement to a maximum of fifteen minutes. These conversations are critical — not just for immediate awareness, but because the goodwill you build here will matter when you need to discuss funding.

Your ask at this stage is focused and specific: request sufficient funding, through your company’s RFA (Request for Approval) process or equivalent, to conduct a feasibility study. By scoping the request tightly, you set a realistic expectation for the initial investment while signalling that a significantly larger programme investment will follow. This stage is also about repositioning compliance work away from the “necessary evil” perception that persists in many organisations.
Priority 2: Feasibility Study and Business Case #
This step is as much about stakeholder engagement as it is about analysis. You need to frame the work in terms that are relatable to each part of the business you involve — not in terms of Act articles and recitals.
A feasibility study examines the technical, financial, and operational viability of the proposed programme. The business case then focuses on financial justification: is this programme viable and worth doing? These are distinct but sequential pieces of work.
If your background is primarily in data protection or legal, consider bringing in a Business Analyst (BA). A good BA has a working understanding of how the organisation operates, how technology underpins business objectives, and a toolkit of techniques for eliciting requirements and insights from the right people. They will help you identify which parts of the business are affected, who needs to be involved, and how to structure the analysis.

Together, you and your BA should:
- Determine information needs by business area — HR has different EU AI Act exposures than Product Development, and your education packs should reflect that
- Engage colleagues with a contextual introduction to the work (fifteen minutes maximum) and use those conversations to build the benefits case
- Identify and assess organisational impacts through interviews and workshops, using a structured technique such as POTI (People, Organisation, Technology, Information) or a similar enabler framework
- Use this analysis to identify existing inventories of AI systems, and where they do not exist, create a tactical inventory capturing the information needed to assess Act applicability
- Classify systems according to the Act’s risk tiers, with initial prioritisation on suspected prohibited and high-risk AI systems
Your findings feed directly into the business case. This does not need to be a large document — less is more. A well-structured business case should include:
- Problem statement: the impact of the EU AI Act on your business and the key compliance obligations it creates
- Options and recommendation: the proposed project or programme scope, framed against your business strategy rather than regulatory obligation alone
- Alignment with business objectives: EU AI Act impacts mapped against relevant elements of your company’s strategy — framing the work as a business enabler rather than a matter of pure compliance
- Risk assessment: project and programme risks, clearly differentiated from regulatory risk
- Cost/benefit analysis: realistic quantification of costs and benefits, a benefit realisation plan, and clear accountability for harvesting those benefits. Where possible, include a funding model that reflects the contributions of the different parts of the organisation that will benefit from the work
- Timeline: a first-cut roadmap covering one to three years, with specific detail on next steps in the coming three months. Do not attempt a detailed schedule from start to finish at this stage — it is not possible and will not be credible
Once the business case is watertight, you are ready for the final pre-project step.
Priority 3: Presentation to Senior Leadership and Approval #
The time you are allocated will vary. You may get fifteen minutes on an existing agenda. You may have an hour or two. A full day is rare but possible — and if it happens, use it well.
Plan for fifteen minutes. If you get more, the additional structure is already there.

For a fifteen-minute slot, prepare as follows:
- In the meeting invitation, state clearly: the purpose (to review and approve the business case), what you are seeking (the green light to initiate the programme), that pre-read is required, and your envisaged next steps
- Produce a one-page summary of your business case and circulate it alongside the full version before the meeting. Consider using risktelling — a structured narrative technique that frames risk in terms of business consequence rather than probability scores — in the one-page version
- Produce a one-page visual game plan for the programme and present it alongside the business case summary
You are presenting two pages or slides: the one-page business case and the one-page game plan. Both must have a business focus. Avoid quoting articles and recitals from the Act itself.
Bring your Business Analyst to the meeting if you can — they will be valuable when the harder questions come.
After the meeting, follow up immediately with brief notes and actions that confirm, in writing, the approval you were seeking.
Frequently Asked Questions #
Why start with leadership buy-in rather than launching the technical work immediately? Because without secured funding and genuine leadership engagement, the technical work — identifying AI systems, conducting gap analyses, classifying risk tiers — will stall when it hits resourcing constraints or competing priorities. The pre-project priorities described here create the conditions for that work to succeed. Jumping straight to the technical work without them is one of the most common reasons EU AI Act programmes fail to get traction.
What is a feasibility study and how is it different from a business case? A feasibility study examines whether the proposed programme is technically, financially, and operationally viable. It asks: can this be done? A business case then addresses whether it should be done, and on what terms: what will it cost, what are the benefits, what are the risks, and how will success be measured? The feasibility study feeds the business case. Both are necessary, and neither can be properly completed without meaningful stakeholder engagement across the organisation.
How do I make an EU AI Act business case compelling to a leadership team that does not see compliance as a priority? Lead with strategy, not regulation. Map the Act’s obligations against the parts of your company’s business strategy that are most dependent on AI systems. Show how non-compliance creates risk to those strategic objectives — not just to the regulatory position. Frame the investment as enabling responsible AI deployment rather than managing a legal obligation. The penalty tiers are worth mentioning, but they should not be the headline argument.
If you found this useful, the Purpose and Means newsletter covers GDPR, data governance, and privacy strategy — fortnightly, in plain language.
Purpose and Means works with organisations on data protection strategy, governance, and compliance - going beyond the legal text to focus on how things actually get done. If you’d like to discuss what this means for your organisation, book a call or explore our services.





