AI Act Check
Every AI system inventoried, classified and dated, with the obligations that follow.
- Duration
- 3–4 weeks
- Price
- €6,000 to €12,000
- excl. VAT, indicative
Four practices, held by one team.
Services
Deploy it because it works, and because you can defend it.
Two things are usually true at the same time. Your teams are already using generative AI, often through tools nobody approved. And the projects that have been formally proposed are stuck, because nobody can say whether they are allowed.
This practice resolves both. We inventory what is actually in use, classify each system under the AI Act, and set up governance light enough that it does not become the reason nothing ships. Then we build: a scoped pilot on your data, evaluated against a measured baseline, with access control and logging from the first day rather than added before go-live.
The security work is not a separate phase. An assistant connected to your document store inherits every permission mistake in it. An agent with credentials is an access decision. We treat them that way from the start.
Where AI is worth the effort, and the rules that keep it defensible.
Where you actually stand on data, skills, governance and tooling, including an honest inventory of the shadow AI your teams are already using.
A portfolio of use cases ranked by value and feasibility, sequenced into a roadmap with the platform and governance work that has to happen alongside it.
Roles, approval gates, an AI register and review criteria, aligned with ISO 42001 and the AI Act so that governance and compliance are one piece of work.
Working sessions that leave leaders able to judge an AI proposal: what these systems do well, where they fail, and what the regulation asks of them.
From a scoped use case to a system in production, with the risk work done alongside.
A use case defined precisely enough to build — data, users, success measures — with its AI Act classification settled before any budget is committed.
A working pilot — retrieval-augmented search, an internal assistant or document automation — built on your data, evaluated against a measured baseline, with access control and logging from day one.
Agents that act on systems, built with the permission model and the human checkpoints defined first, because an agent with broad credentials is an access risk before it is a productivity gain.
The work that has to happen before a company-wide assistant is switched on: permission cleanup, data classification, tenant configuration, logging and user guidance.
The engineering that turns a promising pilot into a system you can operate: versioning, evaluation in the pipeline, cost control, monitoring and a rollback that works.
The assurance layer: risk assessment, data protection, and audit of what is already running.
Risk assessment of an AI system across safety, bias, robustness and rights, including the fundamental rights impact assessment the AI Act requires from certain deployers.
Controls for the data an AI system touches: minimisation, pseudonymisation, retention in vector stores, tenant isolation and the contractual position with your model provider.
An independent review of a system already in production: how it performs, how it fails, what it logs, and whether its documentation would survive a regulator's question.
Applying AI where it genuinely helps our own field: alert triage, evidence gathering, policy drafting and supplier questionnaire handling, with a human decision at the end.
Every AI system inventoried, classified and dated, with the obligations that follow.
An assistant rolled out to the whole company without opening the whole file server with it.
The person who owns your AI register, reviews each new use case against the AI Act, and keeps governance moving at the speed your teams are actually adopting these tools.
Your compliance obligations run continuously: evidence collected as it is produced, internal audits on schedule, regulatory changes watched, and the audit answered without a scramble.
AI Act Check takes three to four weeks and tells you what you are running, what it is classified as, and what is owed from when.