Get Ready for AI Regulation
EU AI Act Readiness and AI Regulation Compliance
The EU AI Act is the world's first broad law for artificial intelligence. We help you classify your AI systems, meet the duties for their risk level, and prepare for the deadlines.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
The EU AI Act regulates AI by risk. It bans a small set of practices, places heavy duties on high-risk systems, sets transparency rules for others, and adds obligations for general-purpose AI models. It matters because it reaches providers and deployers who touch the EU market, and its obligations phase in over the coming years with real penalties. We help you inventory and classify your AI, understand what each system must do, and build the technical documentation and oversight the Act requires.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the EU AI Act engagement, 6 phases in order, each one selectable. Phase 1, AI Inventory and Classification. We list your AI systems and classify each one by the Act's risk tiers, from prohibited to minimal risk. Activities: Inventory AI systems and models in use; Classify each against the Act's risk tiers; Confirm provider or deployer role per system; Flag anything close to a prohibited practice. Hands over AI System Inventory and Classification Register. Phase 2, Obligation Mapping. We map the specific duties for each system, whether it is high-risk, limited-risk, or a general-purpose model. Activities: Map high-risk duties to affected systems; Identify transparency obligations for limited-risk systems; Assess general-purpose model obligations; Match each duty to its enforcement deadline. Hands over Obligation Mapping Report. Phase 3, Gap Assessment. We measure your current practices against those duties and give you a prioritised roadmap to the deadlines. Activities: Assess current governance against each duty; Review data, documentation, and oversight practices; Rank gaps by deadline and enforcement risk; Build the remediation roadmap. Hands over Gap Assessment and Compliance Roadmap. Phase 4, Documentation and Oversight Design. We help you build the technical documentation, risk management, and human oversight high-risk systems need. Activities: Draft Annex IV technical documentation; Design the AI risk management process; Define human oversight measures per system; Prepare conformity assessment groundwork. Hands over Technical Documentation Pack and Oversight Design. Phase 5, Implementation Support. We help you embed transparency notices, logging, and monitoring across the relevant systems. Activities: Deploy transparency notices for AI interactions; Implement event logging on high-risk systems; Set up post-market monitoring processes; Train teams on the new obligations. Hands over Implemented Transparency, Logging, and Monitoring Controls. Phase 6, Readiness Review. We run a review so you can show a customer or a regulator that your AI governance is on track. Activities: Verify each obligation against implemented controls; Test documentation completeness per system; Compile the compliance evidence pack; Set the cadence for tracking new guidance. Hands over EU AI Act Readiness Report. Each phase begins from the artefact the phase before it produced.
Phase 01 AI Inventory and Classification
We list your AI systems and classify each one by the Act's risk tiers, from prohibited to minimal risk.
What Happens In This Phase
- Inventory AI systems and models in use
- Classify each against the Act's risk tiers
- Confirm provider or deployer role per system
- Flag anything close to a prohibited practice
The Handover
AI System Inventory and Classification Register
The next phase starts from this.
Phase 01 AI Inventory and Classification
We list your AI systems and classify each one by the Act's risk tiers, from prohibited to minimal risk.
What Happens In This Phase
- Inventory AI systems and models in use
- Classify each against the Act's risk tiers
- Confirm provider or deployer role per system
- Flag anything close to a prohibited practice
The Handover
AI System Inventory and Classification Register
The next phase starts from this.
- 01
AI Inventory and Classification
We list your AI systems and classify each one by the Act's risk tiers, from prohibited to minimal risk.
OutputAI System Inventory and Classification RegisterActivities
- Inventory AI systems and models in use
- Classify each against the Act's risk tiers
- Confirm provider or deployer role per system
- Flag anything close to a prohibited practice
- 02
Obligation Mapping
We map the specific duties for each system, whether it is high-risk, limited-risk, or a general-purpose model.
OutputObligation Mapping ReportActivities
- Map high-risk duties to affected systems
- Identify transparency obligations for limited-risk systems
- Assess general-purpose model obligations
- Match each duty to its enforcement deadline
- 03
Gap Assessment
We measure your current practices against those duties and give you a prioritised roadmap to the deadlines.
OutputGap Assessment and Compliance RoadmapActivities
- Assess current governance against each duty
- Review data, documentation, and oversight practices
- Rank gaps by deadline and enforcement risk
- Build the remediation roadmap
- 04
Documentation and Oversight Design
We help you build the technical documentation, risk management, and human oversight high-risk systems need.
OutputTechnical Documentation Pack and Oversight DesignActivities
- Draft Annex IV technical documentation
- Design the AI risk management process
- Define human oversight measures per system
- Prepare conformity assessment groundwork
- 05
Implementation Support
We help you embed transparency notices, logging, and monitoring across the relevant systems.
OutputImplemented Transparency, Logging, and Monitoring ControlsActivities
- Deploy transparency notices for AI interactions
- Implement event logging on high-risk systems
- Set up post-market monitoring processes
- Train teams on the new obligations
- 06
Readiness Review
We run a review so you can show a customer or a regulator that your AI governance is on track.
OutputEU AI Act Readiness ReportActivities
- Verify each obligation against implemented controls
- Test documentation completeness per system
- Compile the compliance evidence pack
- Set the cadence for tracking new guidance
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
TrustGrid
Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.
What Is Examined, and What it Is Measured Against
Map
Map of the EU AI Act scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: Credo AI, Holistic AI, OneTrust AI Governance, Vanta, Jira, Confluence, MLflow. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: EU AI Act, ISO/IEC 42001:2023, ISO/IEC 23894, NIST AI Risk Management Framework, EU AI Act harmonised standards.
What We Run
7 tools
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- AI ACTEuropean Union
- AI ACTEuropean Union
Deliverables
What You Receive
- AI system inventory and classification
- Obligation mapping report
- Gap assessment and roadmap
- Technical documentation templates
- Human oversight design
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
How does the EU AI Act classify AI systems?
By risk: prohibited, high-risk, limited-risk, and minimal-risk, with separate rules for general-purpose AI models. The classification decides which duties apply, so we start there.
When do the obligations take effect?
They phase in over several years, with prohibited practices first and high-risk duties later. We build a roadmap to the deadlines that matter to you.
How does the Act relate to ISO 42001?
ISO 42001 gives you a management system that supports many EU AI Act duties. It is not automatic compliance, but it is a strong foundation, and we often pair them.
Keep Moving Through Compliance
Service 12 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Extend your ISMS into a privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.