Regulation · EU AI Act

AI Act Diagnostic

The AI Act imposes staggered obligations depending on the risk level of your AI systems. A clear diagnostic tells you what applies to you, by when, and what to put in place — without costly over-compliance.

What the AI Act changes for you

The EU Artificial Intelligence Act is in force and applies in phases: prohibition of certain uses, obligations for general-purpose AI models, then reinforced requirements for high-risk systems. Penalties can reach several percent of global turnover.

The challenge is not primarily legal: it is knowing which category your products and uses actually fall into, and avoiding two symmetric mistakes — missing an applicable obligation, or imposing "high-risk" constraints on yourself when you are not concerned.

A structured diagnostic settles that uncertainty and gives you a proportionate roadmap aligned with the application timeline.

Our 4-step approach

An actionable diagnostic, designed for technical teams that want an operational answer, not a doctrinal memo.

01

AI systems inventory

Listing your AI uses (built, integrated, generative AI, vendor models) and your role under the regulation: provider, deployer, importer.

02

Risk-level classification

Qualifying each system (unacceptable, high, limited, minimal risk) and identifying applicable transparency obligations, notably for generative AI.

03

Gap analysis

Comparing your current practices against applicable obligations: risk management, data governance, technical documentation, human oversight, robustness and transparency.

04

Roadmap and timeline

A prioritised action plan aligned with the application dates, with a possible bridge towards an ISO 42001 management system.

What you get

  • A register of your AI systems with their regulatory role
  • The classification of each system by risk level
  • A matrix of applicable obligations and observed gaps
  • A prioritised roadmap with deadlines
  • Transparency recommendations for your generative AI uses
  • An executive-ready summary note

Who is it for?

  • Software vendors integrating or providing AI features
  • Banks, insurers and regulated organisations deploying AI in their processes
  • Companies deploying generative AI in their products or processes
  • Scale-ups needing to reassure customers and investors on compliance
  • Product and legal teams wanting an operational reading of the regulation

Frequently asked questions

Am I concerned if I only use a third-party AI API?

Most likely yes, as a "deployer". Your obligations differ from those of the model provider, but they exist (transparency, oversight, compliant use). The diagnostic clarifies your exact role.

Is my product "high-risk"?

Few software products truly are, but some use cases (HR, biometrics, scoring, critical infrastructure) trigger it. Classification removes the ambiguity and avoids over-compliance.

Which deadlines matter?

Obligations apply in successive waves since entry into force, from prohibited practices through to high-risk systems. The diagnostic places each of your deadlines on the official timeline.

Does the diagnostic replace legal advice?

No. It gives you a solid technical and operational reading to act and prioritise; legal counsel remains relevant on sensitive interpretation points, as a complement.

Assess your exposure to the AI Act

In 30 minutes we identify your sensitive systems and priority deadlines. You will know where to start.