The EU AI Act, from the questions you have to ask
Most of the difficulty in an AI Act engagement is upstream of the regulation. Before anything can be classified, somebody has to know which systems the client actually uses, who built each one, and whether the client changed it — and clients routinely do not know, because a summarisation feature switched on inside an existing subscription does not feel like adopting a system.
The writing here is about getting that inventory out of a client, and about the two questions that decide everything downstream: what role the client holds for each system, and what the system is used to decide. The dates come last, and only attach once a category is confirmed.
Guides
Long-form, written for a practitioner.
- AI Act readiness for SMEs: what consultants need to ask
The questions that separate a provider from a deployer, a minimal-risk system from a high-risk one, and what to document before the deadlines.
Notes
Shorter pieces on one thing that changed.
- Article 25(1) and the moment your client becomes the provider
How an SME that buys a model and fine-tunes it takes on the provider's obligations, the questions that surface it, and what changes in the file.
- What the Digital Omnibus moved, and which notes to re-date
The amending regulation, the dates as they now stand, and the client files worth re-dating before you send the next round of letters.
Doing this work
What the product does with it.
- Records of processing
Build an Article 30 record of processing for each client from facts you confirmed once: purposes, categories, recipients, transfers and retention, with the vendor rows filled from a verified registry.
Reference
The pages the facts come from.
See what changed since your clients' policies were written
Enter up to ten client websites. Free, no sign-up, the first report in about a minute.