The first question is not what you must do but which category you fall into. The Regulation treats a recommendation system and one used to screen job candidates very differently, and your role — provider or deployer — changes the list of duties again.
We work with companies that build AI systems and with those that merely use them. The second group is larger and usually more surprised: many firms have obligations without having developed anything.
Situations in which we are called
- You use an AI tool in recruitment, lending or employee assessment
- You are building a product with an AI component and want to know what is required
- A client asks for contractual assurances about AI Act compliance
- You are integrating a general-purpose model into your own product
- You need the technical documentation and a governance policy
- You process personal data through AI systems and two regulations overlap
What we cover
- Inventory of AI systems and their classification by risk level
- Establishing your role — provider, deployer, importer or distributor
- Technical documentation, user information and human oversight
- Internal governance policies and staff training
- Contractual clauses between providers and deployers
- The overlap with data protection and with copyright
How we work
We start with an inventory: which AI systems are actually in use, who built them and what they are used for. The list is often longer than management expected, because tools bought by different departments all come into scope.
The application dates are staggered, and the obligations do not all start at once. We tell you at the first conversation which ones concern you and in what order, so that you do not build documentation for requirements that do not apply.
What helps us start
- The list of AI tools in use, including those embedded in other products
- The contracts with the providers of those tools
- A description of the decisions those systems influence
- Existing technical documentation, if you develop the system yourself
