AI Act Compliance Consulting: Adapting to the EU AI Regulation
Regulation (EU) 2024/1689 (the AI Act) is the world's first comprehensive AI law. It classifies AI systems by risk level and imposes concrete obligations on anyone who develops, distributes or simply uses AI in their business — yes, SMBs and freelancers too.
Does your business use or develop AI systems in the EU?
If your business uses AI for hiring, credit scoring, facial recognition surveillance, customer service chatbots, or any system that makes automated decisions about people, the AI Act likely affects you, regardless of your size. The obligation isn't limited to whoever builds the AI system: it also applies to whoever deploys it within their organization. Many SMBs and freelancers using third-party AI tools (HR, marketing, customer service) wrongly assume the responsibility lies only with the provider.
What our AI Act consulting covers
- Risk classification of your AI systems: prohibited, high-risk, limited or minimal risk
- Identifying your role: provider, deployer, importer or distributor, each with different obligations
- Gap analysis against Annex III requirements (high-risk systems) and transparency obligations
- Registering high-risk systems in the EU database where required
- AI governance policy and mandatory technical documentation
- Phased compliance plan aligned with the regulation's application timeline
AI Act compliance process
- AI systems inventory: We identify every AI system your business develops, integrates or uses, including third-party tools.
- Risk classification: We determine each system's risk category under Annex III of the regulation.
- Obligation mapping: We establish what the AI Act requires based on your role (provider or deployer) and risk category.
- Compliance plan: We prioritize measures by legal deadline and risk, focused on the prohibitions already in force since February 2025.
- Ongoing support: We review your compliance posture as harmonized technical standards are published and your AI use evolves.
Deliverables
- Inventory and risk classification of your AI systems
- AI Act gap analysis report
- Compliance plan with deadlines and owners
- Technical documentation templates and high-risk system registration
- AI governance policy for your organization
Who typically requests this?
- Companies using AI for hiring or employee evaluation
- Fintechs and financial entities with automated credit scoring
- Companies with video surveillance or biometric systems
- SMBs and freelancers integrating third-party AI tools or chatbots
- Developers of general-purpose AI (GPAI) models
Frequently asked questions about the AI Act
Who does the AI Act apply to?
It applies to providers who develop AI systems, to deployers who use them within their organization, and to importers and distributors, inside and outside the EU if the system is used in European territory. It applies regardless of company size.
I'm a freelancer using third-party AI tools, do I have obligations?
Yes, as a deployer you have obligations even if you didn't build the system: informing affected people where required, human oversight for high-risk systems, and not using prohibited AI practices such as social scoring.
How much time do I have to comply?
The timeline is progressive: prohibited AI practices have already been illegal since February 2025; governance and general-purpose model obligations apply from August 2025; Annex III high-risk system obligations apply from August 2026.
What penalties does the AI Act impose?
Up to €35M or 7% of global annual turnover for prohibited AI practices; up to €15M or 3% for other regulatory breaches; up to €7.5M or 1% for providing incorrect information to authorities.
Does the AI Act replace GDPR?
No, they're complementary. The AI Act specifically regulates AI systems and their risk level; GDPR still applies to any personal data processing that system performs.