Operationalizing the EU AI Act in Agile Software Development: A Guideline-Based Approach
2026-08-17 • Software Engineering
Software Engineering
AI summaryⓘ
The authors created a practical guideline to help agile software teams follow the rules of the EU AI Act without disrupting their typical work style. They analyzed the law to find parts most relevant to agile teams and mapped them to common challenges these teams face. After checking with experts, they developed 12 key items related to roles, risk management, and transparency that can be included in regular agile activities. The authors found that success depends on shared responsibility across team members and embedding compliance into existing workflows rather than adding separate processes.
EU AI ActAgile teamsRisk managementHuman oversightTransparencyDesign Science ResearchSprint ReviewsRegulatory complianceAI systems documentation
Authors
Dennis Schrader, Eva-Maria Schön, Henning Fritzemeier, Michael Neumann
Abstract
Context: The EU AI Act requires providers and deployers of Artificial Intelligence (AI) systems to implement documentation, risk management, and human oversight. Agile teams that ship AI features in short iterations lack specific artifacts to discharge these duties, since the regulation's abstract provisions do not map onto the Definition of Done, Sprint Reviews, or working agreements. Objective: We provide agile teams with an actionable compliance instrument: an evaluated guideline that operationalizes EU AI Act obligations as activities integrable into existing agile practice. We further document the translation method behind it so that the approach can be reused for adjacent regulations. Method: Following Design Science Research, we assessed each EU AI Act article along three dimensions. We subsequently classified the articles using a traffic-light scheme and mapped those deemed highly relevant to previously documented pain points of agile teams working with AI. We validated the resulting catalog with practitioners through a survey and 11 additional semi-structured expert interviews, analyzed via qualitative content analysis. Results: The guideline comprises 12 items covering roles and responsibilities, risk and quality management, transparency and traceability, monitoring, and regulatory sandboxes. Practitioners rated the catalog as understandable and relevant; feasibility varied with organizational maturity. Effective adoption towards EU AI Act compliance requires collective ownership across roles and integration into existing agile events rather than parallel compliance processes. Conclusions: The catalog gives agile teams a starting point to transform their delivery practices towards an EU AI Act compliance without dismantling agile practices.