ComplianceData ManagementMedium complexity
AI Act Readiness
Prohibited practices and the rules for general-purpose AI models already apply, high-risk duties follow, and many organisations still have no list of their AI systems.
How we approach it
Build the AI inventory, including AI inside purchased software. Classify each system as prohibited, high-risk, subject to transparency duties or minimal risk, and set the organisation's role for each, provider or deployer. Plan the work against the dates: Annex III high-risk uses from 2 December 2027, AI in Annex I products from 2 August 2028.
Business value
A dated plan instead of a last-minute scramble
Technology stack
- AI system inventory
- classification rules
- regulatory text corpus
- GRC integration
Related service
Governance & ComplianceFurther reading
Related use cases
- Cross-Industry · ComplianceShadow AI InventoryStaff paste client data into personal AI accounts and browser extensions nobody approved, often on consumer terms that allow training and long retention.
- Cross-Industry · ComplianceAuditable Document GenerationRegulated outputs such as risk reports, suitability letters and audit findings need wording that can be reproduced and defended, which a free-writing model cannot guarantee.
- Cross-Industry · ComplianceRegulatory Horizon ScanningSee which proposed EU and national rules will affect the business, early enough to plan.