EU AI Act compliance
Classify first, then build the governance
Most organisations approaching the AI Act start with the wrong question. They ask how do we comply, when the answer depends entirely on a prior question they have not answered: which of the AI systems we already use fall into which risk category.
The regulation is already in force and phases in by risk tier. Prohibited practices have applied since February 2025, obligations for general-purpose AI models since August 2025, and the main body of high-risk obligations since 2 August 2026, with high-risk systems embedded in regulated products following in August 2027. High-risk systems carry substantial requirements across risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and cybersecurity. Limited-risk systems mainly carry transparency duties. Most systems in most companies land lower than their owners fear, but you cannot claim that without having done the classification.
Where do most organisations actually stand?
They do not have an inventory
AI has entered through procurement, through features switched on inside existing SaaS products, and through teams adopting tools directly. The first deliverable of almost every AI Act project is a list of AI systems in use, and it is almost always longer than expected.
They are deployers, not providers, and the difference matters
Obligations differ significantly depending on whether you build and place an AI system on the market or deploy someone else’s. Getting your role wrong means preparing for the wrong obligations entirely.
What we do
AI system inventory and classification. Identifying AI systems in use across the organisation, determining your role for each, and classifying against the risk tiers of the regulation. This produces the scope for everything else.
Gap analysis against the obligations that actually apply to your classification, not a generic checklist covering requirements you do not carry.
Governance framework. Roles, human oversight arrangements, incident handling, documentation and logging practices, and the review cycle that keeps the classification current as systems change.
ISO/IEC 42001 implementation. Where a certifiable AI management system is the goal, we implement 42001 and align it to the AI Act obligations, so one system serves both. This is the same pattern as ISO 27001 serving several security obligations at once.
Cybersecurity requirements for high-risk systems. Accuracy, robustness and cybersecurity are explicit obligations for high-risk AI. This is where our security practice and our AI practice meet: adversarial testing, model and pipeline security, and the evidence that the measures work.
How does this relate to ISO 42001?
The AI Act is law. ISO/IEC 42001 is a certifiable management system standard for AI. They are not the same thing, and certification does not equal compliance.
What 42001 gives you is the operating structure, covering governance, risk assessment, lifecycle controls and continual improvement, into which the regulatory obligations fit. For organisations that already run ISO 27001, the integration is straightforward because the management system structure is shared.
We build and run AI products ourselves
We operate our own AI platform under the same obligations we advise on, so the governance we describe is not theoretical for us: human oversight with override and stop controls, risk-classified actions with approval gates, and full audit logging. If you want to see what these requirements look like in a working system rather than in a policy document, we can walk you through ours.
Does the AI Act apply to us if we are not in the EU?
It can. The regulation has extraterritorial reach where AI systems are placed on the EU market or where their output is used in the EU. Non-EU providers also reach it through customers who impose the obligations contractually.
Is our chatbot a high-risk system?
Almost certainly not. Most customer-facing assistants fall under transparency obligations rather than the high-risk regime. But the answer depends on the use case, and the classification needs to be documented rather than assumed: that documentation is what a supervisor or an enterprise customer will ask for.
Do we need ISO 42001 certification?
Not as a legal requirement. It becomes worth doing when customers or partners ask for assurance about your AI governance, or when you need an operating structure rather than a set of documents.
Where do we start?
With the inventory and classification. It is the fastest piece, it usually reduces the perceived scope of the problem, and nothing built before it can be trusted.