Know Which of Your AI Systems Are Actually Regulated

Know Which of Your AI Systems Are Actually Regulated

Know Which of Your AI Systems Are Actually Regulated

Inventory every AI system in the business, classify it by risk tier, and close the obligations that apply — including the AI literacy duty that is already in force.

Inventory every AI system in the business, classify it by risk tier, and close the obligations that apply — including the AI literacy duty that is already in force.

Aligned with Regulation (EU) 2024/1689 & ISO/IEC 42001

Aligned with Regulation (EU) 2024/1689 & ISO/IEC 42001

A marble bust dissolving into a grid of data cubes

EU AI Act Readiness

Problem

Shadow AI Meets Hard Law

Shadow AI Meets Hard Law

Ask a management team to list the AI systems in use across the business and you will get a short answer. Ask the employees and you will get a much longer one. The gap between those two lists is where the regulatory exposure sits.

The AI Act binds deployers, not just the companies building models — and the AI literacy duty in Article 4 applies regardless of how low-risk your use case is. Meanwhile vendors are reassuring customers that their product is compliant, which says nothing at all about your own obligations.

Solution

Inventory, Classify, Close the Gaps

Inventory, Classify, Close the Gaps

We build the inventory first, including the tools nobody declared, then classify each system by risk tier and establish whether you act as a provider or a deployer for it. Those two answers determine everything that follows.

From there we map the obligations that actually apply to you, close the gaps, and stand up the AI literacy programme Article 4 requires. Where you want a management system rather than a one-off assessment, the same evidence maps onto ISO/IEC 42001.

Agenda

How It Works

How It Works

01

AI Inventory & Shadow AI Discovery

  • Every AI system in use, including embedded features in tools you already licence.

  • Shadow AI discovery — the accounts and tools that never went through IT.

  • Purpose, data touched, and decision impact recorded per system.

  • A living inventory, not a one-time snapshot.

01

AI Inventory & Shadow AI Discovery

  • Every AI system in use, including embedded features in tools you already licence.

  • Shadow AI discovery — the accounts and tools that never went through IT.

  • Purpose, data touched, and decision impact recorded per system.

  • A living inventory, not a one-time snapshot.

02

Classification & Role Determination

  • Risk tier per system: prohibited, high-risk, limited, or minimal.

  • Provider or deployer — the role that determines which duties attach.

  • General-purpose AI models handled under their own regime.

  • Documented classification reasoning, ready for a supervisory authority.

02

Classification & Role Determination

  • Risk tier per system: prohibited, high-risk, limited, or minimal.

  • Provider or deployer — the role that determines which duties attach.

  • General-purpose AI models handled under their own regime.

  • Documented classification reasoning, ready for a supervisory authority.

03

Obligation Mapping & Gap Closure

  • Obligations mapped per system rather than as a generic checklist.

  • Transparency, human oversight and record-keeping duties made concrete.

  • Gap closure prioritised by the date each obligation bites.

  • Overlap with your GDPR records identified and reused.

03

Obligation Mapping & Gap Closure

  • Obligations mapped per system rather than as a generic checklist.

  • Transparency, human oversight and record-keeping duties made concrete.

  • Gap closure prioritised by the date each obligation bites.

  • Overlap with your GDPR records identified and reused.

04

AI Literacy & Governance

  • AI literacy programme under Art. 4 — already in force, and role-specific.

  • Usage policy that people can actually follow.

  • Governance: who approves a new AI system, and on what basis.

  • Documented training records as part of the evidence set.

04

AI Literacy & Governance

  • AI literacy programme under Art. 4 — already in force, and role-specific.

  • Usage policy that people can actually follow.

  • Governance: who approves a new AI system, and on what basis.

  • Documented training records as part of the evidence set.

4

AI Literacy & Governance

  • AI literacy programme under Art. 4 — already in force, and role-specific.

  • Usage policy that people can actually follow.

  • Governance: who approves a new AI system, and on what basis.

  • Documented training records as part of the evidence set.

Execution

Compliance That Doesn’t Stop the Rollout

Compliance That Doesn’t Stop the Rollout

This is where our two competencies meet. The same team that assesses your obligations also trains your people and hardens your AI deployments — so the governance and the rollout are one project, not two.

You receive:

  • AI system inventory including shadow AI.

  • Risk classification with documented reasoning per system.

  • Obligation map and gap plan with dates.

  • AI literacy programme and usage policy.

Target Audience

Ideal For:

Ideal For:

  • Companies rolling out AI: and unsure what they are already obliged to do.

  • Regulated industries: where an AI system touches a high-risk use case in Annex III.

  • Anyone with shadow AI: which, in practice, is almost everyone.

  • Teams pursuing ISO/IEC 42001: who want one assessment to serve both.

ROI & Business Impact

Why Invest in This?

Deadline Certainty

The obligations phase in on fixed dates. Knowing which ones touch you turns an open-ended risk into a dated plan.

Keep Shipping AI

The alternative to governance is a blanket ban that your teams route around anyway. Classification lets you say yes deliberately.

One Assessment, Two Standards

The same evidence answers the AI Act and ISO/IEC 42001, and overlaps heavily with your GDPR records.

Pricing

Scoped Around Your Team.

Every engagement is scoped to your team, your industry, and your risk profile. Tell us what you need and we’ll put together a concrete offer.

EU AI Act Readiness

AI inventory, risk classification and obligation mapping

  • Format: workshops plus discovery, remote or on site.

  • Duration: three to five weeks depending on system count.

  • Scope: inventory, classification, obligation mapping, literacy programme.

  • Deliverables: AI inventory, classification record, gap plan, usage policy.

  • Optional: ISO/IEC 42001 mapping and ongoing governance.

EU AI Act Readiness

AI inventory, risk classification and obligation mapping

  • Format: workshops plus discovery, remote or on site.

  • Duration: three to five weeks depending on system count.

  • Scope: inventory, classification, obligation mapping, literacy programme.

  • Deliverables: AI inventory, classification record, gap plan, usage policy.

  • Optional: ISO/IEC 42001 mapping and ongoing governance.

EU AI Act Readiness

AI inventory, risk classification and obligation mapping

  • Format: workshops plus discovery, remote or on site.

  • Duration: three to five weeks depending on system count.

  • Scope: inventory, classification, obligation mapping, literacy programme.

  • Deliverables: AI inventory, classification record, gap plan, usage policy.

  • Optional: ISO/IEC 42001 mapping and ongoing governance.

FAQ

Common Questions

We only use ChatGPT and Copilot. Does this even apply to us?
Our vendor says their tool is AI Act compliant. Isn’t that enough?
Do we need ISO/IEC 42001?
How does this relate to your AI training and Secure AI Operations work?

That's not all

Continue the Journey

Turn Your Team into Power Users

Stop the guesswork. Start the strategy.

Turn Your Team into Power Users

Stop the guesswork. Start the strategy.

Turn Your Team into Power Users

Stop the guesswork. Start the strategy.