EU AI Act Readiness & AI Governance

An independent reading of your AI systems against what the EU AI Act actually requires, in writing, by someone with no implementation work to sell.

High-risk obligations under the EU AI Act become enforceable on 2 August 2026. Your organisation is using AI somewhere — in decisioning, in operations, in a vendor’s product you’ve adopted — and what you don’t have is an independent, evidence-based reading of which systems are in scope, what risk tier they sit in, and whether the governance structure around them would actually satisfy a regulator asking to see it.

That is what this engagement is.

€15,000. Three to four weeks. Delivered in writing, with a presentation to whoever needs to hear it.

Fixed fee. No implementation work. No commissions. No product recommendations influenced by suppliers.

Why clients commission this review

  • The board wants confirmation of which AI systems are actually in scope of the Act before the 2 August 2026 enforcement date, not an assumption.
  • A specific AI system — in HR, credit decisioning, customer-facing automation — has been flagged as potentially high-risk and needs a proper classification.
  • Procurement has adopted several AI-enabled vendor products without a consistent governance process behind the decision.
  • A compliance committee wants to know whether the current AI governance structure — named roles, risk management documentation, human oversight — would hold up under scrutiny.
  • An enterprise client or investor has asked for evidence of AI governance maturity as part of their own due diligence.

Who this is for

Boards and compliance functions at organisations using or deploying AI systems who want independent confirmation of AI Act exposure and readiness ahead of enforcement.

Technology and product leaders who need a defensible risk classification for specific AI systems, not just a general policy statement.

Who this is not for

Organisations wanting AI systems built, integrated, or fine-tuned. We identify and recommend; we do not implement.

Anyone wanting formal legal advice on liability exposure. The Review informs that conversation; it isn’t a substitute for regulatory counsel.

Pre-revenue AI product startups building a single system from scratch — the framework assumes an established business with AI adoption spread across several functions or vendors.

What you receive

The Review tells you three things in writing: which AI systems are actually in scope and at what risk tier, where the governance gaps sit, and what to address before enforcement or the next scrutiny event. Five artefacts, delivered together, in plain language.

An AI system inventory and risk classification. Every AI system in use or under development, mapped to the Act’s risk tiers — minimal, limited, high-risk, unacceptable — with the reasoning behind each classification.

An Article 9 risk management gap analysis. For systems classified high-risk, a reading against the specific risk management system requirements — documentation, testing, human oversight, post-market monitoring — with evidence, not assumption.

A governance structure assessment. Whether accountable roles, documentation practices, and escalation paths exist and are genuinely functioning, not just named in a policy document.

A prioritised remediation roadmap. What to address first, second, third, sequenced against the enforcement timeline and the risk tier of each system.

A board presentation. A one-hour session with your board or compliance committee, findings presented, challenged, and discussed in the room.

How the Review runs

Three to four weeks, in four phases.

Week one — scoping and inventory. Mapping every AI system in use across the business, internally built and vendor-supplied, before classification begins.

Week two — interviews and evidence gathering. Interviews across technology, product, procurement, and compliance. Evidence collected against each in-scope system.

Week three — synthesis and writing. Classification and findings written up into the artefacts above.

Week four — presentation and revisions. The board or committee session, scheduled around your existing rhythm.

Everything is written before it is said. Nothing is presented to your board that you have not read first.

What this is not

Legal advice on liability or enforcement exposure. The Review can inform that conversation; it does not substitute for regulatory counsel.

A remediation engagement. We identify and recommend; we do not implement or build AI governance tooling.

A certification or conformity assessment. The Review informs readiness; formal conformity assessment for high-risk systems is a separate, specialist process.

Proof

References available on request. Anonymised excerpts from prior reviews available on request.

What happens next

Start a Conversation

Thirty minutes. Given the 2 August 2026 deadline, we’ll confirm quickly whether the timeline works. No proposal is sent unless you ask for one.

Not sure this is the right depth yet? Start with the Technology Control Assessment — €4,950, three to five working days.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Book a EU AI Act Readiness & AI Governance scoping call