Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Part of Compliance13 services in this practice area

Get Ready for AI Regulation

EU AI Act Readiness and AI Regulation Compliance

The EU AI Act is Europe's risk-based law for artificial intelligence, and it reaches Indian companies whose AI is placed on or used in the EU market. We help you classify your systems, meet the duties for their risk level, and plan for the dates that now apply.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

The EU AI Act, Regulation (EU) 2024/1689, regulates AI by risk. It bans a small set of practices, places substantial duties on high-risk systems, sets transparency rules for others, and adds obligations for general-purpose AI models. It reaches providers and deployers outside the EU whose systems are placed on the EU market or whose output is used there, so Indian product and services companies are frequently in scope. The timetable changed in 2026: the Digital Omnibus on AI, Regulation (EU) 2026/1744 of 8 July 2026, moved the high-risk deadlines back. We help you inventory and classify your AI, work out whether you are a provider or a deployer for each system, and build the documentation and oversight the Act requires.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the EU AI Act engagement, 6 phases in order, each one selectable. Phase 1, AI Inventory and Classification. We list your AI systems and classify each one by the Act's risk tiers, from prohibited to minimal risk. Activities: Inventory AI systems and models in use; Classify each against the Act's risk tiers; Confirm provider or deployer role per system; Flag anything close to a prohibited practice. Hands over AI System Inventory and Classification Register. Phase 2, Obligation Mapping. We map the specific duties for each system, whether it is high-risk, limited-risk, or a general-purpose model. Activities: Map high-risk duties to affected systems; Identify transparency obligations for limited-risk systems; Assess general-purpose model obligations; Match each duty to its enforcement deadline. Hands over Obligation Mapping Report. Phase 3, Gap Assessment. We measure your current practices against those duties and give you a prioritised roadmap to the deadlines. Activities: Assess current governance against each duty; Review data, documentation, and oversight practices; Rank gaps by deadline and enforcement risk; Build the remediation roadmap. Hands over Gap Assessment and Compliance Roadmap. Phase 4, Documentation and Oversight Design. We help you build the technical documentation, risk management, and human oversight high-risk systems need. Activities: Draft Annex IV technical documentation; Design the AI risk management process; Define human oversight measures per system; Prepare conformity assessment groundwork. Hands over Technical Documentation Pack and Oversight Design. Phase 5, Implementation Support. We help you embed transparency notices, logging, and monitoring across the relevant systems. Activities: Deploy transparency notices for AI interactions; Implement event logging on high-risk systems; Set up post-market monitoring processes; Train teams on the new obligations. Hands over Implemented Transparency, Logging, and Monitoring Controls. Phase 6, Readiness Review. We run a review so you can show a customer or a regulator that your AI governance is on track. Activities: Verify each obligation against implemented controls; Test documentation completeness per system; Compile the compliance evidence pack; Set the cadence for tracking new guidance. Hands over EU AI Act Readiness Report. Each phase begins from the artefact the phase before it produced.

Phase 01 AI Inventory and Classification

We list your AI systems and classify each one by the Act's risk tiers, from prohibited to minimal risk.

What Happens In This Phase

  • Inventory AI systems and models in use
  • Classify each against the Act's risk tiers
  • Confirm provider or deployer role per system
  • Flag anything close to a prohibited practice

The Handover

AI System Inventory and Classification Register

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    AI Inventory and Classification

    We list your AI systems and classify each one by the Act's risk tiers, from prohibited to minimal risk.

    OutputAI System Inventory and Classification Register

    Activities

    • Inventory AI systems and models in use
    • Classify each against the Act's risk tiers
    • Confirm provider or deployer role per system
    • Flag anything close to a prohibited practice
  2. 02

    Obligation Mapping

    We map the specific duties for each system, whether it is high-risk, limited-risk, or a general-purpose model.

    OutputObligation Mapping Report

    Activities

    • Map high-risk duties to affected systems
    • Identify transparency obligations for limited-risk systems
    • Assess general-purpose model obligations
    • Match each duty to its enforcement deadline
  3. 03

    Gap Assessment

    We measure your current practices against those duties and give you a prioritised roadmap to the deadlines.

    OutputGap Assessment and Compliance Roadmap

    Activities

    • Assess current governance against each duty
    • Review data, documentation, and oversight practices
    • Rank gaps by deadline and enforcement risk
    • Build the remediation roadmap
  4. 04

    Documentation and Oversight Design

    We help you build the technical documentation, risk management, and human oversight high-risk systems need.

    OutputTechnical Documentation Pack and Oversight Design

    Activities

    • Draft Annex IV technical documentation
    • Design the AI risk management process
    • Define human oversight measures per system
    • Prepare conformity assessment groundwork
  5. 05

    Implementation Support

    We help you embed transparency notices, logging, and monitoring across the relevant systems.

    OutputImplemented Transparency, Logging, and Monitoring Controls

    Activities

    • Deploy transparency notices for AI interactions
    • Implement event logging on high-risk systems
    • Set up post-market monitoring processes
    • Train teams on the new obligations
  6. 06

    Readiness Review

    We run a review so you can show a customer or a regulator that your AI governance is on track.

    OutputEU AI Act Readiness Report

    Activities

    • Verify each obligation against implemented controls
    • Test documentation completeness per system
    • Compile the compliance evidence pack
    • Set the cadence for tracking new guidance

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the EU AI Act scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: Credo AI, Holistic AI, OneTrust AI Governance, Vanta, Jira, Confluence, MLflow. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: EU AI Act (Regulation (EU) 2024/1689), Regulation (EU) 2026/1744 (Digital Omnibus on AI), ISO/IEC 42001:2023, ISO/IEC 23894, NIST AI Risk Management Framework.

What We Run

7 tools

  • Credo AI
  • Holistic AI
  • OneTrust AI Governance
  • Vanta
  • Jira
  • Confluence
  • MLflow

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • AI ACTEuropean Union
  • REGURegulation (EU) 2026/1744Digital Omnibus
  • ISO/IEC 42001:2023
  • ISO/IEC 23894
  • NIST AI Risk Management Framework
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • AI system inventory and classification
  • Obligation mapping report
  • Gap assessment and roadmap
  • Technical documentation templates
  • Human oversight design

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Does the EU AI Act apply to an Indian company?

It can, in two main ways. You are a provider if you develop an AI system or general-purpose AI model and place it on the EU market or put it into service there under your own name or trademark, whether or not you have an establishment in the Union. You are a deployer if you use an AI system under your own authority within the EU. The Act also reaches providers and deployers located outside the EU where the output produced by the system is used in the Union, which catches many Indian SaaS and services companies serving European clients. We establish your role for each system during scoping, because the obligations differ sharply between provider and deployer. Getting the role right matters commercially as well as legally, because a provider carries documentation, conformity assessment and registration duties that a deployer does not, and contracts sometimes push those duties between the parties.

What are the current deadlines?

The Act entered into force on 1 August 2024 and applies in stages. Prohibited practices and AI literacy duties have applied since February 2025, and rules for general-purpose AI models since August 2025, with the Commission's enforcement powers over those models from 2 August 2026. Transparency duties under Article 50, such as telling people they are interacting with an AI system and marking synthetic content, apply from 2 August 2026. The high-risk deadlines moved: Regulation (EU) 2026/1744, the Digital Omnibus on AI of 8 July 2026, published on 24 July 2026, set 2 December 2027 for standalone high-risk systems listed in Annex III and 2 August 2028 for AI embedded in products covered by Annex I. Confirm the dates for your systems, since amendments continue. We track amendments as they are published rather than working from a slide of the original timetable, and we plan work against the date that applies to your classification instead of the earliest date in the Act.

How do we know whether our AI system is high-risk?

Classification follows the Act rather than intuition. A system is high-risk if it is a safety component of, or itself a product covered by, the Union legislation listed in Annex I and requires third-party conformity assessment, or if it falls within one of the use cases in Annex III, which covers areas such as biometrics, critical infrastructure, education, employment, essential services including credit scoring, law enforcement, migration, and justice. Annex III has a filter: a system may escape the classification where it performs only a narrow procedural task or improves a previous human activity without replacing judgement, but that assessment must be documented and the system registered. We work system by system and record the reasoning, because the classification decides everything that follows. We also record the decision and its evidence for each system, because the Act expects that reasoning to be documented and a regulator or customer can ask for it later, long after the people who made the call have moved on.

What must a provider of a high-risk system actually do?

Run a risk management system across the lifecycle, govern the training, validation and testing data, produce and keep technical documentation, design the system to keep automatic logs, provide instructions that let deployers use it correctly, build in human oversight, and meet appropriate levels of accuracy, robustness and cybersecurity. You also need a quality management system, must carry out the relevant conformity assessment and draw up an EU declaration of conformity, affix the CE marking, register the system in the EU database, and monitor it after it is on the market, reporting serious incidents. Providers established outside the Union must also appoint an authorised representative in the EU. Deployers carry lighter but real duties, including using the system per instructions, assigning competent human oversight and monitoring operation. We map each of those duties to something concrete in your organisation, an owner, a document and a process, so obligations do not sit as a list in a report that nobody can act on.

Does ISO 42001 certification mean we comply with the Act?

No, and no certification body can grant compliance with the Act. ISO/IEC 42001 is a management system standard: it gives you the inventory, risk and impact assessment, data governance, documentation, oversight and monitoring routines that the Act's duties depend on, which makes the evidence exist and stay current. The Act's own conformity assessment route for high-risk systems, its registration in the EU database, the CE marking and the declaration of conformity are separate legal steps. Harmonised standards developed for the Act will carry a presumption of conformity where they apply; ISO 42001 does not. We usually recommend running both together: the management system to keep AI governance working, and a mapping from its controls to the specific Act obligations each of your systems carries. Where a vendor or consultant offers you EU AI Act certification, treat the claim carefully and check exactly what is being certified, because that phrasing is common in marketing and misleading in procurement.

Where should we start, and what does readiness cost?

Start with an inventory and classification, because every duty and deadline depends on them. Most teams discover AI in more places than expected: product features, vendor tools embedded in workflows, and internal automation. From there we map obligations per system and role, run a gap assessment, and build the documentation, data governance and oversight the Act expects, usually over two to four months depending on how many systems are in scope. We do not publish a price, since the effort depends on the number and classification of systems, whether you are a provider, a deployer or both, and how much documentation already exists. Legal advice on classification questions in the EU, where you need it, sits outside our fee. We scope first, then quote a fixed price in writing. We also prioritise by exposure rather than tackling everything at once, starting with prohibited practices and transparency duties that already apply, then the high-risk work that the revised dates now allow you to plan properly.

Keep Moving Through Compliance

Service 12 of 13 in this practice area