Service

EU AI Act readiness assessment

Inventory what your teams actually shipped, classify it against the Act, and map the obligations that already bite to concrete platform controls - with a runway to the December 2027 high-risk deadline.

The problem this solves

Most platform teams believe the AI Act slipped to 2027. Half of that is true.

The Digital Omnibus deferred the high-risk obligations - Annex III standalone systems to 2 December 2027, Annex I embedded systems to August 2028. It did not defer the transparency duties in Article 50, which took effect on 2 August 2026, and it did not touch the GPAI provider obligations that have applied since August 2025.

Article 50 bites by what a system does, not by which risk tier someone assigned it. The chatbot, the summariser and the generated-image feature that nobody ever classified are in scope now.

What this engagement produces

  • An inventory of what your teams have actually shipped - found by looking at subscriptions, gateways and repos, not by sending out a questionnaire and hoping.
  • A classification of each system against the Act's tiers, with the reasoning written down so it survives someone disagreeing with it.
  • An obligation map: each duty that applies today, tied to the specific platform control that satisfies it - and the gaps, named plainly.
  • A remediation plan sequenced by what is already enforceable, then by the December 2027 runway.
  • Cross-references to ISO/IEC 42001, DORA and NIS2, because you are almost certainly being asked about all of them by different people.

What you have at the end

A document your risk function can take into a committee and a backlog your platform team can start on - the same findings in both languages. Two to three weeks, depending on how many subscriptions, tenants and business units are in scope.

Where I'm coming from

Let me be straight about this, because you are going to ask and you should.

Nobody has a long track record in AI Act assessments. The transparency duties took effect in August 2026 and the high-risk obligations do not bite until December 2027. Any firm presenting years of experience in this is presenting something else.

What I bring is the part that is not new. Twenty years of building and reviewing cloud platforms inside regulated estates, at ARB level and in the terminal - control mappings against PCI DSS, SOX, DORA and NIS2, identity and access architecture in financial services, and the AI gateway work described here. Finding what is actually deployed in a large estate and mapping it to obligations someone has to defend is work I have done for most of my career. The regulation on the end of it is eighteen months old for all of us.

If you want a reference for the underlying work rather than for this specific engagement, ask on the call and I will arrange one.

What this is not

It is not a legal opinion. I am an architect, not your counsel: I map obligations to controls and tell you what is missing. Where a classification turns on statutory interpretation I will flag it as a legal call and it goes to your lawyers - I would rather hand you a document with honest gaps in it than one that implies certainty I do not have.

Find out where you actually stand

Thirty minutes, no deck. Tell me what your teams have shipped and where the audit pressure is coming from, and I'll tell you what I'd look at first - whether or not you hire me.