Regulation · EU AI Act
AI Act Diagnostic
The AI Act imposes staggered obligations depending on the risk level of your AI systems. A clear diagnostic tells you what applies to you, by when, and what to put in place — without costly over-compliance.
What the AI Act changes for you
The EU Artificial Intelligence Act is in force and applies in phases: prohibition of certain uses, obligations for general-purpose AI models, then reinforced requirements for high-risk systems. Penalties can reach several percent of global turnover.
The challenge is not primarily legal: it is knowing which category your products and uses actually fall into, and avoiding two symmetric mistakes — missing an applicable obligation, or imposing "high-risk" constraints on yourself when you are not concerned.
A structured diagnostic settles that uncertainty and gives you a proportionate roadmap aligned with the application timeline.
Our 4-step approach
An actionable diagnostic, designed for technical teams that want an operational answer, not a doctrinal memo.
AI systems inventory
Listing your AI uses (built, integrated, generative AI, vendor models) and your role under the regulation: provider, deployer, importer.
Risk-level classification
Qualifying each system (unacceptable, high, limited, minimal risk) and identifying applicable transparency obligations, notably for generative AI.
Gap analysis
Comparing your current practices against applicable obligations: risk management, data governance, technical documentation, human oversight, robustness and transparency.
Roadmap and timeline
A prioritised action plan aligned with the application dates, with a possible bridge towards an ISO 42001 management system.
What you get
- A register of your AI systems with their regulatory role
- The classification of each system by risk level
- A matrix of applicable obligations and observed gaps
- A prioritised roadmap with deadlines
- Transparency recommendations for your generative AI uses
- An executive-ready summary note
Who is it for?
- Software vendors integrating or providing AI features
- Banks, insurers and regulated organisations deploying AI in their processes
- Companies deploying generative AI in their products or processes
- Scale-ups needing to reassure customers and investors on compliance
- Product and legal teams wanting an operational reading of the regulation
Frequently asked questions
Am I concerned if I only use a third-party AI API?
Most likely yes, as a "deployer". Your obligations differ from those of the model provider, but they exist (transparency, oversight, compliant use). The diagnostic clarifies your exact role.
Is my product "high-risk"?
Few software products truly are, but some use cases (HR, biometrics, scoring, critical infrastructure) trigger it. Classification removes the ambiguity and avoids over-compliance.
Which deadlines matter?
Obligations apply in successive waves since entry into force, from prohibited practices through to high-risk systems. The diagnostic places each of your deadlines on the official timeline.
Does the diagnostic replace legal advice?
No. It gives you a solid technical and operational reading to act and prioritise; legal counsel remains relevant on sensitive interpretation points, as a complement.
Assess your exposure to the AI Act
In 30 minutes we identify your sensitive systems and priority deadlines. You will know where to start.