Our EU AI Act compliance services
From AI system inventory and risk classification to human oversight, transparency, and audit-ready documentation — everything you need to deploy AI confidently in the EU.
System Inventory & Risk Classification
Full mapping of your AI tools. Accurate classification as high-risk, limited, minimal, or GPAI. Identify obligations and gaps early.
Vendor & Third-Party Compliance
Due diligence on suppliers: verify CE marking, conformity assessments, technical documentation, and clauses for bias mitigation, accuracy, and robustness.
Data Governance
Assess datasets for relevance, accuracy, bias detection/mitigation, and traceability. Update policies for collection, retention, and transparency.
Human Oversight & Governance Design
Implement effective human-in-the-loop processes: define oversight rules, train staff to monitor/challenge outputs, establish escalation protocols, and prevent over-reliance.
Transparency & Individual Rights
Develop clear notifications for clients/employees on AI usage, decision logic, and impacts. Set up explanations, appeal mechanisms, and compliance with deployer transparency duties.
Risk Management & Monitoring
Build continuous monitoring programs: regular risk assessments, performance/bias tracking, incident detection/logging (≥6 months retention), and corrective actions.
Documentation & Incident Reporting
Create comprehensive technical/organizational documentation, define roles, maintain logs, and prepare for audits, serious incident reporting (Art. 73), and authority cooperation.
Strategic Compliance & Brand Positioning
Transform obligations into strengths: craft “Human-First AI” narratives, client-facing statements, internal training, and integrate compliance messaging into sales processes for trust and differentiation.
August 2026 brings the first transparency obligations — and December 2027 the high-risk AI deadline. Start your compliance journey now.
EU AI Act roadmap
Unacceptable AI practices banned
AI systems classified as “unacceptable risk” are prohibited and AI literacy obligations start applying to organisations.
GPAI & governance in force
General-purpose AI (GPAI) rules, central governance structures, the AI Office, and the penalties framework begin to apply across the EU AI value chain.
Transparency obligations (Art. 50)
Transparency rules for chatbots and AI-generated content become enforceable. Member States must establish AI regulatory sandboxes.
Synthetic content marking
Mandatory labelling of AI-generated synthetic content and prohibition of non-consensual intimate imagery (“nudifier”) applications.
High-risk AI obligations (Annex III)
Core requirements for high-risk AI systems become enforceable: recruitment, credit scoring, law enforcement, biometrics, education, critical infrastructure. Deferred from Aug 2026 by the AI Omnibus.
High-risk AI in regulated products (Annex I)
Full compliance required for high-risk AI embedded in regulated products: medical devices, machinery, vehicles, aviation, and other product safety legislation.
August 2026 is the next critical milestone — transparency obligations for all organisations. High-risk AI deadlines follow in December 2027 and August 2028.
Our tiered EU AI Act compliance packages
Select the package that matches your urgency and ambition. From quick diagnostics to turning compliance into a competitive edge.
Tier 1: Readiness Check
- AI tools inventory & risk classification
- Gap assessment vs EU AI Act
- Diagnostic report & heat-map
- Actionable compliance roadmap
Tier 2: Compliance Playbook
- All Tier 1 deliverables
- Ready-to-use Compliance Playbook
- Training modules for teams
- Leadership alignment workshop
Tier 3: Competitive Edge
- All Tiers 1 & 2 deliverables
- Brand narrative & messaging
- Monitoring playbook & framework
- Priority 1-year support
Add-ons available: Quarterly AI Risk Monitoring • Leadership Roundtables • Vendor & Third-Party Audits.
Frequently asked questions
What is the EU AI Act?+
The EU AI Act (Regulation 2024/1689) is the world's first comprehensive legal framework for artificial intelligence. It entered into force on 1 August 2024 and applies to any organisation that places AI systems on the EU market or whose AI systems affect people in the EU, regardless of where the company is based.
When do EU AI Act obligations start?+
Key deadlines: 2 February 2025 — bans on unacceptable AI practices (e.g. social scoring, real-time biometric surveillance). 2 August 2025 — rules for general-purpose AI (GPAI) and governance structures. 2 August 2026 — transparency obligations under Article 50 (e.g. disclosing AI-generated content, chatbot labelling). 2 December 2027 — full obligations for high-risk AI systems listed in Annex III (recruitment, credit scoring, education, law enforcement, critical infrastructure). 2 August 2028 — high-risk AI embedded in regulated products (Annex I, e.g. medical devices, machinery).
Which AI systems are considered high-risk under the EU AI Act?+
High-risk AI systems are listed in Annex III of the EU AI Act and include: AI used in recruitment and HR decisions, credit scoring and access to financial services, educational assessment, law enforcement and justice, border management, critical infrastructure management, and real-time biometric identification. These systems must meet strict requirements for documentation, human oversight, risk management, data governance, and transparency before being deployed.
Does the EU AI Act apply to SMEs?+
Yes — the EU AI Act applies to any organisation (including SMEs and startups) that develops, deploys, or uses AI systems affecting people in the EU. However, the Act includes some proportionate provisions for SMEs: reduced documentation requirements for certain systems, access to regulatory sandboxes, and lighter obligations for low-risk AI. That said, if your AI system qualifies as high-risk, full compliance obligations apply regardless of company size.
What happens if a company does not comply with the EU AI Act?+
Non-compliance with the EU AI Act can result in significant fines: up to €35 million or 7% of global annual turnover for violations related to prohibited AI practices; up to €15 million or 3% of turnover for other violations such as failing to meet high-risk AI requirements; up to €7.5 million or 1.5% of turnover for providing incorrect information to authorities.
Where do I start with EU AI Act compliance?+
The first step is building an inventory of all AI systems your organisation uses or develops, then classifying each one by risk level (unacceptable, high, limited, or minimal risk). From there, high-risk systems require a full compliance programme covering risk management, data governance, human oversight, technical documentation, and incident logging. Our free assessment tool at app.euai-compliance.com can help you get started in minutes.
From Our Blog
Practical EU AI Act guides and deadline updates
EU AI Act Enforcement Began August 2026 — And It Wasn't About High-Risk Systems
The Act's first live enforcement date targeted chatbot and deepfake disclosure, not risk classification. Here's why that catches most compliance plans off guard.
Read article →EU AI Act High-Risk AI Systems: The Complete Annex III Guide
Every Annex III category explained with real-world examples and the obligations that apply.
Read article →EU AI Act Compliance Checklist for SMEs: 7 Steps to Get Ready
A practical step-by-step checklist to assess your exposure and build a compliance plan.
Read article →EU AI Act August 2026: What the Transparency Obligations Mean for Your Business
Article 50 is closer than most companies think. Here's exactly what it requires and how to prepare.
Read article →Ready to get compliant?
Book a free Compliance Readiness Assessment and discover how to turn AI compliance into a competitive edge.
Whether you have a defined project or just a sense that the EU AI Act should be on your agenda — a first conversation costs nothing and usually clarifies a lot.