Evaluate

    EU AI Act readiness

    Your role under the regulation, the risk tier of each AI system you build or use, the obligations that follow, and a costed plan to meet them — measured against the timetable as it stands after the Digital Omnibus, not the one published in 2024.

    Duration

    4–6 weeks

    Built on

    EU AI Act · ISO/IEC 42001 · NIST AI RMF

    Indicative price

    €8,500–19,000 per engagement

    Who this is for

    • Chief compliance officer or general counsel

      Owns this and needs the classification documented.

    • CEO

      Is being asked by clients what the company's AI position is.

    • Head of product

      Is shipping something that may be a high-risk system and needs to know now.

    • Procurement or vendor management

      Is buying AI and inheriting obligations through the contract.

    Your obligations depend on a role you may not have established

    The Act does not regulate AI in general. It assigns obligations according to what you are in relation to a specific system — provider, deployer, importer or distributor — and according to which risk tier that system falls into. Two organisations using the identical tool can carry very different duties, and the same organisation can be a provider of one system and a deployer of another.

    Most organisations have not established either dimension, which means they cannot know what they owe. The work is therefore not 'become compliant' in the abstract; it is inventory, classify, determine role, and then read off the obligations that follow.

    The inventory is harder than it sounds, because the systems in scope are not only the ones procured as AI. A feature inside a tool you already pay for counts. A model someone in marketing is using on a corporate card counts. Something a supplier embedded in a service they provide you counts, and the contract may or may not tell you.

    One obligation reaches far more organisations than the rest, and it was rewritten this summer. The AI literacy duty used to require providers and deployers to ensure a sufficient level of AI literacy among the people operating AI on their behalf. Regulation (EU) 2026/1744 — the Digital Omnibus, in force since 27 July 2026 — softened it to a duty to take measures to support the development of AI literacy, and added that nobody has to guarantee a specific level in any individual. The duty still binds; it is now an obligation of means rather than of result. That lowers the legal floor and raises the commercial one, because the client procurement questionnaires asking how your staff are trained did not soften at the same time.

    We give you the inventory, the classification per system with the reasoning, the obligations that follow, and a costed plan. Where the answer is that a system should not be deployed in its current form, we say so plainly — that finding is worth more than a conformity checklist.

    How we do it

    1. 01

      Scoping and inventory

      1–2 weeks

      Every AI system you build, buy, embed or use — including the features inside tools you already own and the ones arriving through suppliers. Assembled through structured survey, expenditure review and contract review rather than surveillance.

    2. 02

      Role determination

      3–5 days

      Provider, deployer, importer or distributor, per system, with the reasoning recorded. This is the determination everything else depends on.

    3. 03

      Risk classification

      1 week

      Each system placed in its tier, with the argument written down. Borderline cases are flagged as borderline rather than resolved optimistically.

    4. 04

      Obligation mapping

      1 week

      What each classification requires of you, expressed as things to do rather than articles to read.

    5. 05

      Gap and cost

      1 week

      Current position against those obligations, with effort and cost per gap, and the sequence.

    6. 06

      Readout

      half a day

      To the people accountable, with the borderline calls and the uncomfortable findings surfaced rather than buried in an annex.

    Named artefacts

    What you receive

    • AI system inventory, including embedded and supplier-provided systems
    • Role determination per system, with recorded reasoning
    • Risk tier classification per system, with borderline cases flagged
    • Obligation map — what each classification requires, as actions
    • AI literacy obligation assessment, by role
    • Gap analysis with effort and cost per gap
    • Costed and sequenced remediation plan
    • Executive and board readout

    What we need from you

    • A route to what is actually in use, including the unsanctioned. An inventory that only contains procured systems is not an inventory.
    • Supplier contracts for services with an AI component.
    • Product and engineering time where you build rather than only buy — provider obligations are materially heavier.
    • Someone who can decide to stop using something if that is where the analysis lands.

    What changes

    1. 01You know what you are, per system, and can show the reasoning.
    2. 02Obligations are expressed as work rather than as legal text.
    3. 03The literacy obligation has a plan and an evidence trail rather than an intention.
    4. 04Client and procurement questions are answered from a document that already exists.
    5. 05Anything that should not ship in its current form is identified before it ships.

    What it costs

    €8,500–19,000 per engagement

    All prices exclude VAT.

    Questions

    Does the Act apply to us if we only use AI, not build it?

    Almost certainly yes, as a deployer, and deployer obligations are real though lighter than a provider's. The distinction matters because it is easy to become a provider without noticing — substantially modifying a system, or putting your name on it, can move you.

    The high-risk deadlines moved. Can we wait?

    The Digital Omnibus deferred the Chapter III obligations for Annex III high-risk systems to 2 December 2027, and for Annex I systems — AI embedded in regulated products — to 2 August 2028. Nothing else moved. The prohibitions have applied since February 2025, the general-purpose model obligations since August 2025, and the Article 50 transparency rules from 2 August 2026. What the deferral buys is time to do the work properly, and it does not touch the part that takes longest, which is knowing what you have. Organisations that use the extra time to build the inventory and the classification arrive at the deadline with a position. The ones that wait arrive with a survey.

    We are not established in the EU. Does it reach us?

    It can, where output is used in the Union. The determination turns on specifics, and it is the first thing the assessment establishes rather than something to assume either way.

    Does ISO/IEC 42001 certification make us compliant?

    No. Certification is not compliance and the Act does not mention the standard. But an AI management system builds most of the structure the Act expects — inventory, risk process, oversight roles, evidence — so running one body of work mapped to both is cheaper than running two.

    What does it cost?

    €8,500–19,000 per engagement. The range reflects the number of systems and whether you build as well as use. Organisations that only deploy sit at the lower end.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.