Skip to content

Answers you can put in writing

We classify the systems you run and close the gaps against the rules that bind you. We leave documentation that reads as evidence rather than as intent.

The problem is specificity, not ignorance

Most teams we meet have read the Act. What they cannot do is say, for one named system, which risk tier it sits in, which role they hold, which obligations follow, and where the evidence for each of those answers lives. A readiness deck does not survive that question and a maturity score does not either. The work runs system by system, and what it produces is evidence.

What the work involves

Where an item carries a clause reference, it points at the operative legal text and you can read it yourself. Where it carries none, it is good practice rather than a codified duty. We mark the difference because it changes how you should rank it.

  1. 01

    Classification and role

    Every system you run, checked against the prohibited practices, the Annex III high-risk categories and the Article 50 transparency triggers. Then your role for each one: provider, deployer, importer or distributor. The role determines the obligation, so it comes first.

    Arts. 5, 6, 50 · Annex III
  2. 02

    General-purpose model posture

    Fine-tuning, hosting or substantially modifying a general-purpose model can make you a provider without anyone intending it. We establish whether it has, and what documentation and copyright-policy duties came with it.

    Arts. 53 to 55
  3. 03

    DPDP Act readiness

    Notice and consent architecture, purpose limitation, retention and erasure, data principal rights including nomination, grievance redressal, breach reporting, and the further duties that follow if you are notified as a Significant Data Fiduciary.

    DPDP Act 2023 · DPDP Rules 2025
  4. 04

    Impact assessments

    Data protection impact assessments, and fundamental rights impact assessments where Article 27 applies. Written to inform a decision rather than to record one already taken.

    Art. 27 · GDPR Art. 35
  5. 05

    Controls and human oversight

    Risk management, data governance, logging, accuracy and robustness targets, and oversight a real person can exercise under real workload. Oversight that exists only on an org chart fails at first inspection.

    Arts. 9 to 15
  6. 06

    Documentation and board reporting

    Technical documentation, a risk register someone maintains, and a standing board pack covering what changed, what is outstanding and what closing it would cost. Directors have to discharge their own oversight duty from it.

    Art. 11 · Annex IV
  7. 07

    Alignment with ISO 42001 and NIST AI RMF

    The same evidence base serves all three. We structure it once so a later certification project starts from something rather than from nothing.

How this usually runs

What moves the price is how many systems need classifying and how far the gaps run once they are. The diagnostic is fixed price and produces the graded gap report that scopes everything after it, so remediation is quoted against known findings rather than an estimate.

  • Diagnostic, 2 to 4 weeks

    Fixed price. Inventory, classification, a graded gap report and a prioritised remediation plan. Some clients stop here and remediate themselves.

  • Remediation, 2 to 6 months

    We work the plan with your team: policies, controls, assessments, documentation. Scoped against the gap report, so you are buying a known quantity.

  • Standing advisory, monthly

    A retained governance function for organisations that ship continuously. Monthly review, triage on new systems, and someone to call when procurement asks a question nobody can answer.

What you get

  • System inventory with per-system risk classification and role determination
  • Graded gap report against each applicable framework, with evidence cited
  • Prioritised remediation roadmap with effort and sequencing
  • Policy set covering acceptable use, model lifecycle, incident response and third-party AI
  • Risk register, plus the operating rhythm that keeps it current
  • Impact assessments where they are owed
  • Technical documentation pack aligned to Annex IV
  • Board summary in language a non-specialist director can act on

A good fit if

  • Companies serving customers in the EU or the UK
  • Product teams shipping AI features into Europe
  • Financial services, healthcare, recruitment and education
  • Organisations asked for a governance answer by a customer, an investor or a board

Before you ask

We are not in the EU. Why would the AI Act apply to us?

Article 2 extends the Regulation to providers and deployers established outside the Union where the output of the system is used in the Union. An Indian company with European customers can be in scope with no EU entity and no EU staff. In practice the trigger is commercial before it is legal: a European customer asks for evidence before they will sign.

How is this different from an ISO 42001 project?

ISO/IEC 42001 certifies that you run a management system. The AI Act asks whether one named system meets specific obligations. They share evidence and complement each other, but a certificate answers neither a classification question nor an auditor asking for the file. We build the evidence base so it serves both.

Can you work alongside our existing counsel?

Yes, and where the legal exposure is real we would rather you had counsel involved. We do the technical and evidentiary work and give your lawyers something concrete to opine on.

What if the diagnostic finds we are in decent shape?

Then the report says so and you have documented proof of it for the next customer who asks. We would rather hand over a short remediation list than manufacture a long one.

The high-risk deadline moved to December 2027. Can we wait?

You can wait on the Annex III conformity work. The rest is already live: prohibited practices and the Article 4 literacy duty since February 2025, general-purpose model obligations since August 2025, and Article 50 transparency since 2 August 2026. Most organisations find the deferral buys them under a quarter of real slack once conformity assessment and notified-body scheduling absorb the rest.

Start with a scoping call

Thirty minutes. Tell us what you run and where it is going wrong, and we will tell you what we would look at first.