New quiz In-house vs on-demand: 10 questions to save you $500k+ in hiring mistakes and lost time10 questions to save you $500k+ Take the quiz

Services AI EU Compliance (AI Act)

AI EU Compliance Program

The EU AI Act, turned into a roadmap instead of a roadblock.

Selling AI into Europe now comes with a rulebook — and the companies that master it early win the deals. We build your EU AI compliance program — classify your systems, stand up the transparency obligations already in force, and sequence the high-risk requirements due through 2028 — so European deals keep closing.

5.0Gartner Peer Insights · 4.8G2

Get a free EU AI Act classification

Tell us what your AI does. We'll come back with which tier it lands in, what already applies to you, and what can wait.

No sales sequence. A person reads this and replies.

What is the EU AI Act?

The EU AI Act is the first comprehensive AI law, and it applies to companies outside the EU whenever their AI is placed on the EU market or its output is used there. It regulates by risk tier: prohibited practices and AI literacy duties have applied since February 2025, general-purpose AI model obligations since August 2025, and the Article 50 transparency rules — chatbot disclosure, machine-readable marking of synthetic content, deepfake labeling — since August 2, 2026. The 2026 Digital Omnibus deferred the high-risk system obligations to December 2, 2027 (Annex III) and August 2, 2028 (AI embedded in regulated products). Penalties reach €35M or 7% of worldwide turnover.

What you get

01

Classification you can defend

Every AI system you ship, mapped to its tier — prohibited, high-risk, transparency, or minimal — under the Act as amended by the Digital Omnibus, with the reasoning documented for regulators and enterprise buyers alike.

02

The live obligations, handled now

Article 50 transparency in force since August 2026: disclosure to users, machine-readable marking of synthetic content, deepfake labels — including the December 2026 grace deadline for systems already on the market.

03

A 2027–2028 runway, not a scramble

If any of your systems land high-risk, the requirements — risk management, data governance, technical documentation, human oversight — get built into your roadmap on a schedule, well ahead of the Annex III date.

04

One program, three frameworks

We map the Act's requirements onto ISO 42001 and GDPR so one body of evidence serves all three — the same discipline that lets our compliance clients reuse SOC 2 work for HITRUST.

How it works

  1. 1

    Classify

    Typically 1–2 weeks.

    We inventory your AI systems and models, determine what falls in scope and in which tier, and document the reasoning — the artifact every later conversation with buyers or regulators starts from.

  2. 2

    Comply now

    Prioritized by what's in force.

    Transparency obligations implemented — disclosures, content marking, labeling — plus GPAI duties if you train or fine-tune in scope. The things with deadlines behind them come first.

  3. 3

    Build the runway

    Through 2027–2028.

    High-risk requirements built into your engineering roadmap quarter by quarter, with monitoring of guidance and standards as they land — so the 2027 deadline arrives as a checkbox you ticked long ago.

FAQs

AI EU Compliance Program questions, answered

We're a US company. Does the EU AI Act apply to us?
If your AI is placed on the EU market, or its output is used in the EU, yes — the Act reaches non-EU providers deliberately, the same way GDPR does. If you have European customers or your product is available there, assume you're in scope and classify from there.
What actually applies right now?
As of late August 2026: the prohibited-practice bans and AI literacy duties (since February 2025), general-purpose AI model obligations (since August 2025), and the Article 50 transparency rules (since August 2, 2026) — with a grace period to December 2, 2026 for content-marking in systems that were already on the market. High-risk obligations were deferred by the Digital Omnibus to December 2027 and August 2028.
Didn't the EU just delay the AI Act?
Partly — and that nuance matters. The 2026 Digital Omnibus deferred the high-risk deadlines; it did not touch the prohibitions, GPAI duties, or transparency obligations, which are in force now. Teams that keep momentum through the deferral arrive at 2027 ready — and win the buyers who check.
How do we know if we're 'high-risk'?
Annex III lists the use cases — hiring and worker management, credit and insurance scoring, education, critical infrastructure, biometrics, and others — plus AI embedded in regulated products under Annex I. It's a legal determination with real edge cases, which is exactly what the classification phase settles and documents.
We're already pursuing ISO 42001. Doesn't that cover it?
It helps enormously — an AIMS gives you the governance backbone the Act assumes — but a certification isn't a legal compliance program. We map the two so the same evidence serves both, which is materially cheaper than running them separately. We run both.
What does the program cost?
Billed in 15-minute increments with an optional monthly cap, scoped after classification — a chatbot with transparency duties and a high-risk hiring tool are very different programs. The classification itself is where every engagement starts, and yours is free.
European buyers ask two questions: is it compliant, and can you prove it? We make both answers yes.

Keep Europe on your roadmap

Send your company email and we'll come back with your EU AI Act classification.

5.0Gartner Peer Insights · 4.8G2