Skip to main content
AI governance

The EU AI Act clock is still running.

High-risk obligations were deferred to 2027 — but the August 2026 transparency rules were not. If you build or deploy AI in Europe, you need to know what actually applies to you, fast.

Request scoping See the ITCA™ method
Sound familiar?
  • You’re not sure whether your system is high-risk, limited-risk, or a GPAI provider — and the answer changes everything.
  • You added an LLM to your product and quietly inherited obligations no one flagged.
  • The 2 August 2026 transparency deadline is close, and “we’ll deal with it later” has stopped being a plan.
How we fix it

A senior operator, embedded — not a report.

01

Classify every AI system

Each system mapped to a risk tier — prohibited, high-risk, limited, minimal — with the reasoning documented and defensible.

02

Resolve your GPAI / provider status

For every third-party model you build on, determine whether your use makes you a provider with obligations of your own.

03

Ship the Article 50 transparency work

Chatbot disclosure, deepfake and AI-content labelling, and machine-readable marking — designed in for the August 2026 deadline that did not move.

04

Build an ISO 42001-aligned governance layer

A durable AI management system that also feeds your ISO 27001 evidence — so this is infrastructure, not a one-off scramble.

EU AI ActISO 42001NIST AI RMFGDPR
He got us ahead of the AI risks as we added LLMs, aligning us early for the EU AI Act — well before enforcement pressure arrived.
B2B SaaS · ISO 27001 · read the case

Know exactly what applies.

30-minute scoping call. Written proposal within 5 business days. You leave with a one-page scope of what applies — yours to keep.

Request scoping