AI Compliance & Regulation

Regulatory obligations translated into controls and evidence

We turn AI regulation into something operational: which obligations apply to which system, what must be documented, who signs it and what evidence survives an inspection.

How do you know which AI regulations apply to your company?

Applicability is determined by three questions: what role the organisation plays for each AI system (provider, deployer, importer or distributor), which markets and users the system reaches, and which risk tier the use case falls into. From those answers, obligations under the EU AI Act, sector regulation and data protection law can be mapped per system rather than assumed for the company as a whole.

Frameworks we work with

EU AI Act

Role and risk-tier classification, prohibited practices review, transparency obligations, technical documentation and GPAI considerations.

NIST AI RMF

Govern, Map, Measure and Manage functions operationalised into a repeatable risk process with owners and artefacts.

ISO/IEC 42001 & 23894

Management system and AI risk guidance used as the structural backbone of the compliance programme.

GDPR and data protection

Lawful basis, DPIA interaction with AI impact assessment, data minimisation and international transfer questions for AI processing.

Compliance workflow

  1. 01

    Inventory

    Identify every AI system in use or in development, with role, purpose, data and geography.

  2. 02

    Classify

    Assign regulatory role and risk tier per system, with documented reasoning.

  3. 03

    Map obligations

    Derive the concrete obligations, deadlines and documentation duties that follow from the classification.

  4. 04

    Close gaps

    Implement missing controls, documentation, transparency notices and oversight mechanisms.

  5. 05

    Maintain

    Keep classification and documentation current as systems, models and regulation change.

Frequently asked questions

Does the EU AI Act apply to companies outside the European Union?

It can. The regulation reaches providers placing AI systems on the EU market and deployers established outside the EU where the output of the system is used within the EU. Extraterritorial reach is assessed system by system, based on market placement and where the output lands.

Do you guarantee regulatory compliance?

No consultancy can guarantee compliance, and we do not make that claim. We deliver preventive alignment: documented classification, controls, evidence and a defensible position, so the organisation can demonstrate diligence to regulators, clients and auditors.

Is an AI impact assessment the same as a DPIA?

No. A DPIA addresses risks to personal data and data subjects. An AI impact assessment addresses a wider set of risks, including fairness, robustness, transparency, human oversight and societal effects. They overlap and should be linked, but one does not replace the other.

Map your AI regulatory exposure

Get a system-by-system view of applicable obligations, documentation gaps and priority actions.