π€ AI Summary
This study addresses the absence of concrete mapping mechanisms for implementing the EU AI Act within agile teams. Employing a Design Science Research methodology, this work proposes a novel framework that translates abstract regulatory requirements into actionable agile compliance guidelines. Through a traffic light taxonomy and expert interviews, an action catalog comprising twelve practices covering roles and risk management was constructed. The results demonstrate that these guidelines are both comprehensible and relevant, establishing that compliance should be integrated into existing agile activities rather than treated as a parallel process. Ultimately, this research bridges the gap in regulatory operationalization, providing a reusable methodological foundation that enables agile teams to achieve compliance without compromising iterative efficiency.
π Abstract
Context: The EU AI Act requires providers and deployers of Artificial Intelligence (AI) systems to implement documentation, risk management, and human oversight. Agile teams that ship AI features in short iterations lack specific artifacts to discharge these duties, since the regulation's abstract provisions do not map onto the Definition of Done, Sprint Reviews, or working agreements. Objective: We provide agile teams with an actionable compliance instrument: an evaluated guideline that operationalizes EU AI Act obligations as activities integrable into existing agile practice. We further document the translation method behind it so that the approach can be reused for adjacent regulations. Method: Following Design Science Research, we assessed each EU AI Act article along three dimensions. We subsequently classified the articles using a traffic-light scheme and mapped those deemed highly relevant to previously documented pain points of agile teams working with AI. We validated the resulting catalog with practitioners through a survey and 11 additional semi-structured expert interviews, analyzed via qualitative content analysis. Results: The guideline comprises 12 items covering roles and responsibilities, risk and quality management, transparency and traceability, monitoring, and regulatory sandboxes. Practitioners rated the catalog as understandable and relevant; feasibility varied with organizational maturity. Effective adoption towards EU AI Act compliance requires collective ownership across roles and integration into existing agile events rather than parallel compliance processes. Conclusions: The catalog gives agile teams a starting point to transform their delivery practices towards an EU AI Act compliance without dismantling agile practices.