EU AI Act

AI Act readiness, while the grace window still helps.

A working programme for providers and deployers of AI systems: classification documented, the risk-management system in operation, data governance defensible, the technical file built the way Annex IV expects, and post-market monitoring in place before the obligation lands.

  • Classification decision documented, not assumed, provider, deployer, both.
  • Annex IV technical documentation built in the format the certifier expects.
  • Post-market monitoring and incident reporting workflow live before the obligation bites.
  • Regulation 2024/1689
  • High-risk Annex III
  • ISO 42001-aligned
  • Annex IV technical file
When this is for you

The moments the AI Act becomes urgent.

  • You sell an AI feature to EU employers, schools or essential-service providers.

    Annex III almost certainly catches the system. Your enterprise customer is now your deployer under the Act, and the procurement questionnaire reflects that. Without classification and a technical file, the deal stalls.

  • You deploy AI into HR, hiring or workforce decisions.

    Recruitment screening, performance evaluation and workforce allocation are explicitly Annex III. As the deployer you owe a specific set of duties: human oversight, monitoring, fundamental-rights impact assessment in many cases, transparency to affected persons.

  • Your investors or board want a defensible AI governance answer.

    A slide that says "we comply" is not the answer. A documented programme, a named accountable owner, and an evidence trail tied to the specific articles, that is the answer the audit committee can sign off on.

  • You are building a general-purpose model or using one materially.

    GPAI obligations apply from August 2025, on technical documentation, copyright compliance, and a public training-content summary. Systemic-risk GPAI carries a heavier obligation set. The artifacts need to exist, in the right shape, on day one of enforcement.

The engagement

Five phases, classification to post-market monitoring.

Each phase produces an artifact the Act names by article number, not a deliverable we invented.

  1. 01

    Classification & role mapping 2 weeks

    Provider, deployer, importer, distributor, or several at once. Which systems fall under prohibited practice, high-risk Annex III, limited-risk transparency, minimal-risk or GPAI. A documented classification memo with the reasoning, not a label on a slide.

  2. 02

    Risk-management system & data governance 4–6 weeks

    Article 9 risk-management system designed as a continuous loop, not a one-off assessment. Article 10 data governance covering training, validation and test sets, with documented quality, representativeness, and bias-mitigation measures.

  3. 03

    Technical documentation & transparency 4–6 weeks

    Annex IV technical file in the format the certifier expects, plus the Article 13 transparency artifacts for deployers, instructions for use, intended purpose, performance characteristics, limitations. For GPAI, the Article 53 documentation package on top.

  4. 04

    Human oversight, logging & monitoring 3–4 weeks

    Article 14 human oversight measures specified per system. Article 12 automatic logging configured and retention defined. Post-market monitoring under Article 72 designed so deployer-side feedback finds its way back to provider-side decisions.

  5. 05

    Conformity assessment & CE handover 3–6 weeks

    The right assessment path under Annex VI or VII, the EU declaration of conformity, CE marking where it applies, and the registration in the EU database. We sit alongside the named accountable officer until the file is in.

Outcomes

What a conformity assessor would open.

A classification decision that holds up

Provider versus deployer, high-risk versus limited-risk, GPAI obligations or not, written down with the reasoning, signed by the right party, and ready to show the market surveillance authority on day one.

A working risk-management system

Article 9 implemented as a continuous loop, not a static document. Article 10 data governance in operation. The system the certifier opens at the start of a conformity assessment and finds in working order.

An Annex IV technical file that audits cleanly

Each section in the format the certifier expects, cross-referenced to the operating evidence behind it. Procurement reviewers and notified bodies see the same artifact and reach the same conclusion.

Post-market monitoring that catches drift

Logging, incident reporting and a feedback loop from deployers back to the provider, so the system you launch with conformity is not the system that quietly diverges from it six months later.

From the practice
"The AI Act will not be enforced by a single audit moment. It will be enforced through procurement questionnaires, market surveillance probes and incident triggers, continuously. The programme that survives is the one built for a working week, not for a one-off file."

Purple Dragon Cybersecurity

Frequently asked

Common questions, direct answers.

Does the AI Act apply to us?

If you place an AI system on the EU market, put it into service in the EU, or your output is used in the EU, almost certainly yes, regardless of where you are headquartered. Providers carry the heaviest obligations, deployers carry a smaller but real set, and importers and distributors carry specific duties when they are in the chain.

What is "high-risk" and how do we know?

Annex III names eight domains, biometrics, critical infrastructure, education and training, employment and HR, access to essential services, law enforcement, migration and border, administration of justice and democracy. If your system is intended to be used in those domains as a safety component or as a decision input, it is high-risk and the heavy obligations apply. We confirm classification before scoping work.

When does this actually bind?

The Act is in force since August 2024 with staged obligations. Prohibited practices and AI literacy applied from February 2025. General-purpose AI obligations applied from August 2025. High-risk obligations under Annex III apply from August 2026, and Annex I-product-integrated high-risk from August 2027. The grace window narrows monthly.

How does this relate to ISO 42001 or NIST AI RMF?

ISO/IEC 42001 is the management-system standard for AI, useful as an operating spine. NIST AI RMF is a US framework with no binding force in the EU. The AI Act is the law. We use ISO 42001 as the operating framework and map its outputs to the specific AI Act articles, the certifier you eventually face will be checking the law, not the standard.

Do we need a conformity assessment?

Providers of high-risk AI systems do. Most can self-assess under Annex VI for Annex III systems, biometric identification and a few categories require involving a notified body under Annex VII. We help you understand which path applies, prepare the technical documentation, and stay in the room when the assessment is taking place.

Get a 30-min AI Act scope check

A working session that confirms your role, your classification, and what the next 90 days should produce before the high-risk obligations land.

Talk to a security operator.

Tell us what you're trying to ship, what's stalled, or which buyer security review is up next. We work with companies across the EU, EEA and US, and we reply within one business day.

Get in touch