EU AI Act

EU AI Act readiness for organisations reaching the European market

Classification, documentation and controls prepared before the obligations bite — with the reasoning written down and the evidence organised.

What does the EU AI Act require from organisations?

The EU AI Act applies obligations according to the role an organisation plays and the risk tier of each AI system. Practices deemed unacceptable are prohibited outright. High-risk systems require a risk management system, data governance, technical documentation, logging, transparency to deployers, human oversight, accuracy and robustness measures, and conformity assessment. Certain systems carry transparency duties towards affected people, and general-purpose AI models carry their own documentation and, above a capability threshold, systemic-risk obligations.

What we do

Role determination

Establish whether you act as provider, deployer, importer or distributor for each system — the answer changes every obligation that follows.

Risk classification

Assess each use case against prohibited practices, high-risk annexes and transparency categories, with documented reasoning.

Technical file

Build the documentation set expected for high-risk systems: purpose, data, design, testing, metrics, oversight and lifecycle.

Deployer controls

Human oversight arrangements, instructions-for-use compliance, monitoring, logging and staff AI literacy.

Frequently asked questions

We only use third-party AI tools. Are we still in scope?

Very likely yes, as a deployer. Deployer obligations include using systems according to instructions, assigning competent human oversight, monitoring operation, keeping logs where applicable and informing affected people in certain contexts. Substantially modifying or rebranding a system can also shift you into provider obligations.

How do the AI Act and ISO/IEC 42001 fit together?

The AI Act sets legal obligations; ISO/IEC 42001 provides a management system to meet them repeatably. Implementing the standard produces much of the governance, risk and documentation machinery the regulation expects, though the standard alone does not establish legal conformity.

Check your EU AI Act position

A system-level classification and gap review, with the documentation plan that follows.