Services · EU AI Act Readiness
EU AI Act Readiness
The EU AI Act imposes binding obligations on providers and deployers of high-risk AI systems, including risk management, technical documentation, human oversight, post-market monitoring, and serious incident reporting. We assess current practice against those obligations and build the documentation trail conformity assessment requires.
What EU AI Act readiness covers
Classification
Determining whether a given system falls within the Act's high-risk categories, is subject to transparency obligations, or falls outside scope. Misclassification in either direction is expensive — under-scoping creates regulatory exposure, over-scoping creates unnecessary compliance cost.
Risk management system
Design and documentation of a continuous, iterative risk management process spanning the system lifecycle.
Data governance
Assessment of training, validation, and testing data practices against the Act's requirements for relevance, representativeness, and examination for bias.
Technical documentation
The documentation package required before market placement, structured so it survives regulator review.
Human oversight
Design of oversight measures proportionate to the risk, with documented rationale for the level chosen.
Post-market monitoring and incident reporting
Monitoring plan design plus the internal workflow for detecting, assessing, and reporting serious incidents to national authorities within required timeframes.
How we approach it
We start with classification, because everything downstream depends on it. From there we run a gap assessment against applicable obligations, then work through remediation in priority order — highest regulatory exposure first, rather than easiest first.
A practical note: most organizations discover their gap is documentation, not practice. Teams are often doing reasonable risk work informally and have no artifact to show for it. Closing that kind of gap is faster than it looks, but it cannot be done retroactively at audit time.
What you receive
A classification determination with reasoning, a gap assessment against applicable obligations, a prioritized remediation roadmap, and the drafted documentation artifacts themselves — not just a list of what you should write.
Who this is for
Organizations placing AI systems on the EU market, deployers of high-risk systems operating in the EU, and U.S. companies whose products reach EU users through customers or distribution partners.
Frequently asked questions
Does the EU AI Act apply to U.S. companies?
It can. The Act applies based on where a system is placed on the market or used, not solely where the provider is established. A U.S. company whose AI system is used in the EU, or whose output is used in the EU, may fall within scope. Classification requires looking at the specific deployment path rather than the company's headquarters.
What counts as a high-risk AI system?
The Act defines high-risk systems through a combination of listed use cases and product safety categories. Listed areas include employment and worker management, education access, essential private and public services, law enforcement, migration and border control, and administration of justice. Systems that are safety components of regulated products can also qualify. Determination requires assessing the specific function against the Act's criteria.
When do the obligations take effect?
Obligations phase in on a staged timeline following the Act's entry into force, with different requirements applying at different dates. Because the schedule has multiple milestones and interpretation continues to develop through guidance, we verify current applicable dates at engagement start rather than working from a fixed assumption.