← Digital, E-Commerce & AI

AI · European compliance

EU AI Act compliance audit

The AI Act does not apply to a company in only one way. For each system, the organisation’s role as provider, deployer, importer or distributor must be established, together with the system’s function and whether internal modifications change that legal role.

AI inventory risk classification compliance roadmap
Unit of analysisEach system and each purpose of use
OutcomeClassification, gap analysis, measures and owners
2026 timetableArticle 50 transparency obligations apply from 2 August 2026
01

Inventory and roles in the AI value chain

The audit covers internally developed systems, APIs, AI functions integrated into ordinary software and general tools used by teams. For each, we record the provider, purpose, affected persons, data, output and decisions supported.

A company merely using a system is generally a deployer but may become a provider if it develops the system, places it on the market under its own name or substantially modifies it under the Regulation’s conditions.

02

Classification by levels and obligations

The commercial label ‘AI assistant’ does not determine the regime. What matters is the function and context in which the system is put into service.

  • Prohibited practices: immediate review and cessation of scenarios covered by the Regulation’s prohibitions.
  • Transparency: AI interaction, emotion recognition, deepfakes and certain public-interest materials.
  • High risk: identifying cases in the Regulation’s annexes and applicable exceptions.
  • GPAI: distinct obligations for general-purpose model providers and downstream cooperation.
  • Limited risk: internal governance, GDPR, consumers, intellectual property and security.
  • Exclusions: research, personal use or other situations only if the precise conditions are met.
03

Current application timetable

Prohibitions and AI literacy apply from 2 February 2025, while governance rules and GPAI-model obligations apply from 2 August 2025. Article 50 transparency obligations apply from 2 August 2026.

Following amendments agreed at EU level in 2026, the Commission indicates application of the rules for Annex III high-risk systems from 2 December 2027 and systems embedded in regulated products from 2 August 2028. The timetable must be rechecked for each project because AI Act implementation remains dynamic.

04

Evidence and the compliance plan

The report links each obligation to an owner, deadline and evidence: register, assessment, procedure, log, instruction, training or contractual clause. Measures are prioritised by applicability and impact.

For high-risk systems, risk management, data quality, technical documentation, logging, deployer information, human oversight, accuracy, robustness and security may be relevant. The legal audit is coordinated with the technical team and, where appropriate, conformity assessment.

05

How we work together

  1. 01
    AI inventory

    We identify systems, providers, purposes, data, affected persons and process integration.

  2. 02
    Classification

    We establish the organisation’s role and risk level for each use, explaining the conclusion.

  3. 03
    Gap analysis

    We compare existing processes and documents with applicable obligations and the current timetable.

  4. 04
    Roadmap

    We deliver actions, priorities, owners, deadlines and evidence to retain.

QUESTIONS

Frequently asked questions

Is every use of ChatGPT high-risk?

No. Classification depends on purpose and context. A general tool may become part of a sensitive use, but is not high-risk for every task.

Does an AI Act audit replace a GDPR DPIA?

No. The regimes overlap, and a personal-data impact assessment may be required separately or as an integrated exercise, without being replaced by AI Act classification.

Do I still have obligations if I use a major provider?

Yes. The provider has its own obligations, but the deployer must use the system according to instructions, manage the context and fulfil the requirements applicable to it.

Need an AI Act compliance audit?

Send your documents for a legal assessment and a solution tailored to your commercial objective.