Where you standon the EU AI Act.
A defensible classification for every AI system you run, a gap map against the high-risk obligations, and a remediation roadmap with the articles and deadlines that apply to you attached. No panic, no lawyer's guess.
Every system, walked
through the decision tree.
Scope comes first, because most of what teams expect to be high-risk is not, and the obligations that do land arrive with dates attached.
Scope classification
We walk every AI system through the Annex III decision tree and the prohibited-practices list. You get a defensible tier for each one, not a guess.
Obligation gap map
Where a system is high-risk, we assess it against Articles 9 to 15: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness.
Deadline-anchored roadmap
Every gap is tied to the article it breaches and the date it has to close by, ranked so you fix what carries the most exposure first.
Three phases, and you
own the output of each.
No phase ends in a slide deck. Each one leaves you something you can run, read, or hand to another team.
- 01
Inventory and classify
We list every AI system in scope and run each through the Annex III and prohibited-use tests. Two weeks, the same diagnostic rigor as our operations audits.
- 02
Gap assessment
For each high-risk system we score you against the Act's Article 9 to 15 obligations and document exactly where the evidence is missing.
- 03
Remediation roadmap
A ranked plan mapping every gap to its article and deadline, with owners and effort. Yours to keep, whoever does the remediation.
We built the free EU AI Act classifier at ishighriskai.com. It walks your systems through the Annex III decision tree and returns your tier, the governing article, and your deadline. The audit is that same logic, applied in depth across your whole estate.

The rest of the work
we take on.
Most engagements start with one of these and pull in a second along the way. They share a team and a delivery rhythm.
Thirty minutes,
and three things to keep.
No deck, and no discovery phase you pay for. If the answer is that you do not need us, you get that answer on the call.
- 01
Your scope, named
Which of your systems the Act likely touches, and at what tier, before you commit to anything.
- 02
The obligations that apply
The specific articles and deadlines tied to your highest-risk system.
- 03
A first move
The one gap worth closing first, and whether you need us to do it or can run it in-house.
“Most teams learn they're in scope from a lawyer, months too late. We start from your systems and the Annex III tree, so you get a defensible classification and a dated plan, not a fire drill.”