Skip to main content

EU AI Act & governance

Compliant by design, not by attachment.

The European AI Regulation is here: staff AI literacy (art. 4), transparency (art. 50) and requirements for high-risk systems apply in stages. We help companies classify their systems, meet the obligations and document — with the same care we put into building them.

In practice

Risk classification

Inventory of AI systems in use or in development and mapping to the Regulation's categories — prohibited practices, high risk, transparency obligations, minimal risk — and to the obligations for general-purpose models. With a registry that stays up to date.

Obligations and documentation

Risk management, data governance, technical documentation, human oversight, logging and transparency towards users: built into the development cycle, not bolted on at the end.

Training (art. 4)

AI literacy proportionate to roles: management, operational teams and developers. Short, concrete, documented paths — because the obligation must be demonstrable.

Continuous governance

AI usage policies, impact assessments coordinated with GDPR (FRIA/DPIA), post-market monitoring and periodic review when systems or rules change.

Regulatory references and standards

  • Reg. (EU) 2024/1689 — AI Act
  • GDPR · DPIA · FRIA
  • ISO/IEC 42001
  • NIST AI RMF
  • EU Commission guidelines

Project

Our approach

The AI Act inside the projects, not beside them

Every system we deliver — from local RAG to edge AI on STM32 — is born with proportionate risk classification, technical documentation, logging and human oversight. We apply the same method to the systems you already have in-house: inventory, gap analysis, remediation plan and staff training.

Scope
AI Act · GDPR
Output
registry · gap analysis · plan
Training
art. 4, by role
Integration
in the development cycle

How we work

Four steps, always the same

  1. 01

    Inventory of AI systems and suppliers involved

  2. 02

    Risk classification and map of obligations

  3. 03

    Gap analysis, remediation plan, documentation

  4. 04

    Training, monitoring and periodic review

Frequently asked questions

Does the AI Act apply to SMBs too?

Yes: obligations depend on the role (provider or deployer) and on the system's risk, not on company size. SMBs get simplifications, not exemptions.

Where do we start?

Inventory of the AI systems in use, a check that none falls under prohibited practices, staff AI literacy (art. 4) and transparency towards users where required; then the assessment of potentially high-risk systems.

Does using a third-party model make me a "provider"?

Usually whoever uses someone else's system is a "deployer", with lighter obligations; but if you substantially modify it or market it under your own brand, the role can change. We check case by case.

Get started

Ready to transform your business?

Contact us for a free consultation and discover how we can help you reach your goals.