EU AI Act & governance
Compliant by design, not by attachment.
The European AI Regulation is here: staff AI literacy (art. 4), transparency (art. 50) and requirements for high-risk systems apply in stages. We help companies classify their systems, meet the obligations and document — with the same care we put into building them.
In practice
Risk classification
Inventory of AI systems in use or in development and mapping to the Regulation's categories — prohibited practices, high risk, transparency obligations, minimal risk — and to the obligations for general-purpose models. With a registry that stays up to date.
Obligations and documentation
Risk management, data governance, technical documentation, human oversight, logging and transparency towards users: built into the development cycle, not bolted on at the end.
Training (art. 4)
AI literacy proportionate to roles: management, operational teams and developers. Short, concrete, documented paths — because the obligation must be demonstrable.
Continuous governance
AI usage policies, impact assessments coordinated with GDPR (FRIA/DPIA), post-market monitoring and periodic review when systems or rules change.
Regulatory references and standards
- Reg. (EU) 2024/1689 — AI Act
- GDPR · DPIA · FRIA
- ISO/IEC 42001
- NIST AI RMF
- EU Commission guidelines
Project
Our approachThe AI Act inside the projects, not beside them
Every system we deliver — from local RAG to edge AI on STM32 — is born with proportionate risk classification, technical documentation, logging and human oversight. We apply the same method to the systems you already have in-house: inventory, gap analysis, remediation plan and staff training.
- Scope
- AI Act · GDPR
- Output
- registry · gap analysis · plan
- Training
- art. 4, by role
- Integration
- in the development cycle
How we work
Four steps, always the same
- 01
Inventory of AI systems and suppliers involved
- 02
Risk classification and map of obligations
- 03
Gap analysis, remediation plan, documentation
- 04
Training, monitoring and periodic review
Frequently asked questions
Does the AI Act apply to SMBs too?
Yes: obligations depend on the role (provider or deployer) and on the system's risk, not on company size. SMBs get simplifications, not exemptions.
Where do we start?
Inventory of the AI systems in use, a check that none falls under prohibited practices, staff AI literacy (art. 4) and transparency towards users where required; then the assessment of potentially high-risk systems.
Does using a third-party model make me a "provider"?
Usually whoever uses someone else's system is a "deployer", with lighter obligations; but if you substantially modify it or market it under your own brand, the role can change. We check case by case.
Get started
Ready to transform your business?
Contact us for a free consultation and discover how we can help you reach your goals.