AI Act Check
Every AI system inventoried, classified and dated, with the obligations that follow.
- Duration
- 3–4 weeks
- Price
- €6,000 to €12,000
- excl. VAT, indicative
Four practices, held by one team.

Services
Deploy AI you can defend, and defend with AI.
Two things are usually true at the same time. Your teams are already using generative AI, often through tools nobody approved. And the projects that have been formally proposed are stuck, because nobody can say whether they are safe or allowed.
This practice resolves both. We inventory what is actually in use, put governance in place that is light enough not to become the reason nothing ships, and build: a scoped pilot on your data, evaluated against a measured baseline, with access control and logging from the first day rather than added before go-live.
Then we attack it. Prompt injection, data exfiltration through an assistant connected to your document store, an agent holding credentials it should not — an AI red team finds these before a customer or a regulator does. And the same models go the other way: into detection, triage and the compliance evidence that used to take a person a week.
Where AI is worth the effort, and the rules that keep it defensible.
Where you actually stand on data, skills, governance and tooling, including an honest inventory of the shadow AI your teams are already using.
A portfolio of use cases ranked by value and feasibility, sequenced into a roadmap with the platform and governance work that has to happen alongside it.
Roles, approval gates, an AI register and review criteria, aligned with ISO 42001 and the AI Act so that governance and compliance are one piece of work.
From a scoped use case to a system in production, with the risk work done alongside.
A use case defined precisely enough to build — data, users, success measures — with its AI Act classification settled before any budget is committed.
A working pilot — retrieval-augmented search, an internal assistant or document automation — built on your data, evaluated against a measured baseline, with access control and logging from day one.
Agents that act on systems, built with the permission model and the human checkpoints defined first, because an agent with broad credentials is an access risk before it is a productivity gain.
The work that has to happen before a company-wide assistant is switched on: permission cleanup, data classification, tenant configuration, logging and user guidance.
The engineering that turns a promising pilot into a system you can operate: versioning, evaluation in the pipeline, cost control, monitoring and a rollback that works.
The assurance layer: risk assessment, data protection, and audit of what is already running.
Risk assessment of an AI system across safety, bias, robustness and rights, including the fundamental rights impact assessment the AI Act requires from certain deployers.
Controls for the data an AI system touches: minimisation, pseudonymisation, retention in vector stores, tenant isolation and the contractual position with your model provider.
An independent review of a system already in production: how it performs, how it fails, what it logs, and whether its documentation would survive a regulator's question.
Applying AI where it genuinely helps our own field: alert triage, evidence gathering, policy drafting and supplier questionnaire handling, with a human decision at the end.
Models, prompts, agents and the data behind them, tested the way an attacker would.
Security review of AI systems against the OWASP Top 10 for LLM applications: prompt injection, data leakage through context, tool and agent permissions, and model supply chain.
Adversarial testing of an assistant, RAG system or agent: jailbreaks, indirect prompt injection through retrieved content, data exfiltration and abuse of connected tools.
Every AI system inventoried, classified and dated, with the obligations that follow.
An assistant rolled out to the whole company without opening the whole file server with it.
The person who owns your AI register, reviews each new use case against the AI Act, and keeps governance moving at the speed your teams are actually adopting these tools.
AI Act Check takes three to four weeks and tells you what you are running, what it is classified as, and what is owed from when.