EU AI Act Readiness & ISO/IEC 42001
The Act is 113 articles and 13 annexes. Most of it will never apply to you. We establish which parts do, prove it with evidence, and build the management system that keeps it true.
In plain terms
The EU AI Act is big on paper. One hundred and thirteen articles, thirteen annexes, a hundred and eighty recitals, and a set of deadlines that started passing in February 2025. Read end to end it is overwhelming, which is why most organisations either freeze or buy a policy template and hope.
Most of it will never apply to you. What you need is a defensible answer to three questions: which of our AI systems are in scope, what role do we hold for each one, and what must we be able to put in front of an auditor. Answer those three and the Act shrinks from 113 articles to a list you can actually work through — for most companies, somewhere between forty and a hundred and twenty requirements.
That is the whole approach. We scope first and write the reasoning down, because a classification you cannot defend is worse than no classification. Then we assess against the requirements that survived, evidence by evidence, and hand you a register with an owner and a date on every open row.
What you get
- A documented scoping and role determination per AI system — deployer, provider, importer, distributor, authorised representative, GPAI provider — with the article reasoning behind each one, including the Article 25 traps that quietly turn a buyer into a provider
- Classification against Annex III and Annex I, with the Article 6(3) exception argument written out where you rely on it
- A requirement-level gap register: every applicable obligation, its current status, the evidence that proves it, the gap, the remediation action, the owner and the date
- An evidence catalogue — the 48 documents an auditor expects, and which of them you already have under another name
- Reporting clocks (Articles 73, 26(5), 50) folded into your existing incident process next to GDPR's 72 hours and NIS2's 24 and 72
- A roadmap sequenced by legal deadline, not by what is convenient this quarter
- Where you want certification: ISO/IEC 42001 management system design, internal audit, and support through the certification body's two stages
ISO/IEC 42001, and what it is honestly worth
ISO/IEC 42001:2023 is the AI management system standard, and it is the closest structural fit to what the AI Act asks an organisation to run. We build the AIMS around clauses 4 to 10 and the Annex A controls, draw on ISO/IEC 23894 for AI risk management and ISO/IEC 42005 for AI system impact assessment, and take it through internal audit to certification.
One thing we will not tell you is that the certificate makes you compliant. It does not. ISO/IEC 42001 is not a harmonised standard under Article 40, so it carries no presumption of conformity, and no certification body can grant you one. What it gives you is the governance backbone — ownership, a risk method, change control, an audit trail — that turns AI Act evidence into a by-product of how you already work, instead of a project you repeat from scratch every year.
You have already paid for most of this
If you run ISO 27001, GDPR or NIS2, a real part of the AI Act is already sitting in your evidence library under a different name. We map it before we ask you to build anything — and we are explicit about where the mapping stops.
7.2 Competence · A.6.3 Awareness, education and training
The competence process extends to AI roles; the content has to be AI-specific.
A.5.1 Policies · A.5.2 Roles · A.5.9 Asset inventory
The policy and roles framework carries over. The asset inventory can carry an AI flag, but AI-specific attributes are missing.
6.1.2 Risk assessment · 6.1.3 Risk treatment
The method is reusable. The harm criteria are not: Article 9 is about health, safety and fundamental rights, not confidentiality, integrity and availability.
A.5.26 Response to information security incidents
Your incident process can carry the AI Act escalation path and its 2, 10 and 15-day clocks.
Article 35 DPIA · records of processing
A DPIA is not a FRIA. The fundamental-rights scope is wider than data protection, and Article 27 has its own trigger list.
Article 23 incident notification
One incident process, three sets of deadlines. Running them separately is how one gets missed.
Clauses 4–10 · Annex A controls
The closest structural fit there is — but not a harmonised standard under Article 40, so it carries no presumption of conformity.
High-risk systems
If something you build or use lands in Annex III, the work changes shape. This is where the Act stops being paperwork and starts being engineering:
- Fundamental rights impact assessment (Article 27) where the trigger applies — public bodies, public services, credit scoring, life and health insurance pricing
- Annex IV technical documentation, built as a maintained file rather than written once before an audit
- Human oversight that works: designed into the system under Article 14, assigned to named and competent people under Article 26(2), with genuine authority to overrule the output
- Logging and retention under Articles 12, 19 and 26(6) — including the common discovery that the vendor keeps your logs for thirty days and the law wants six months
- Conformity assessment and registration (Articles 43, 47, 49) and the EU declaration of conformity
- Post-market monitoring (Article 72) and serious incident reporting (Article 73)
- Worker and affected-person information (Articles 26(7) and 26(11)), plus the Article 86 right to an explanation — with national co-determination law checked alongside, because the EU text is not the whole duty
AI literacy — Article 4
Article 4 has applied since February 2025, and a single all-staff video does not meet it. We build role-based tracks: one for the people who buy AI, one for the people who build it, one for whoever is named as the human overseer of a high-risk system, and a short one for the board — because Article 99 penalties are a board-level risk and should appear in the risk register as one. Attendance records are part of the deliverable; without them the training is unevidenced.
The AI Governance Workbench
The assessment runs in the open
Most compliance work disappears into a consultant's laptop and comes back as a PDF. Ours does not. Every classification shows the article it rests on, every requirement shows why it switched on for you, and you can follow any finding back to the legal text behind it.
Three panes, one conversation
The consultant talks to the customer in plain language on the left. The centre shows the AI Act reasoning behind every question, with the article and recital it comes from. The right-hand pane shows requirements switching on in real time as the answers land — so the customer watches their obligation set being built rather than receiving it as a verdict weeks later.
Where the organisation stands today
Overall compliance against the requirements that actually apply, split between what is already in force and what is not yet due. Top five actions ranked by risk, the next legal deadline with days remaining, and compliance broken down by chapter, tier and AI system. This is the page a board sees.
Inventory by use case, not by vendor
Every AI system with its purpose, owner, role, the people it affects, whether personal or sensitive data is involved, its risk track, and the Annex III category where one applies. Shadow AI — the model inside a SaaS product nobody registered — is the single most common finding, and this is where it surfaces.
Every open obligation, with an owner and a date
Requirement, entity, when it applies, current compliance state, what is true today, the evidence held against the evidence needed, risk rating, remediation action, owner, due date and status. Filterable by entity, tier, risk and date; exports to Excel or CSV so it can live in your own GRC tool.
Where your existing work already counts
AI Act obligations mapped to ISO/IEC 27001:2022, ISO/IEC 42001:2023, GDPR, NIS2, NIST AI RMF, NIST CSF 2.0, SOC 2 and ISO/IEC 27701, each graded: directly relevant, partially reusable, supporting evidence, or not sufficient by itself. A mapping shows where existing work can help — never that one framework satisfies another.
Every article, annex and recital behind the answer
113 articles, 13 annexes, 180 recitals and all 68 Article 3 definitions, with the legal text alongside the consultant interpretation — labelled as interpretation, never blended into the quote. Amendments made by the AI Omnibus are tracked separately, so you can always see what changed and when.
Artefacts
Take the work away and read it
Two things come out of this engagement. Here is one of each — the report you receive, and the workpaper we assess against.
The deliverable, start to finish, on a fictional company. Executive summary, scoping, classification with the article reasoning for every system, compliance status by tier and entity, the open gaps with owners and dates, the evidence still needed, the reporting clocks, framework reuse, and a roadmap sequenced by legal deadline.
The workpaper itself, not a summary of it. Twenty-two sheets: a scoping questionnaire that resolves your roles, an AI inventory that classifies each system automatically, Article 5 prohibited screening, a master register of 242 requirement rows covering every article and annex, a point-by-point Article 9–15 checklist, filtered role views, reporting and retention clocks, a 48-document evidence catalogue, all 68 Article 3 definitions in plain English, and an AI Omnibus change log.
Dates
What has already happened, and what is next
Two of the three obligation sets below are in force today. The deadline people talk about — high-risk — is the one that has not arrived yet.
AI literacy and the prohibited practices
Article 4 and Article 5 have applied since this date. If you have never run a documented screening of your AI uses against the Article 5 list, or you have no role-based AI training records, you are already late — not preparing for something.
GPAI model obligations and governance
Chapter V duties for general-purpose AI model providers, the governance structures, notified bodies, and the penalty regime other than Article 101.
Transparency, sandboxes, market surveillance
Article 50 applies: people must be told when they are talking to AI, synthetic content must be machine-readably marked, and deepfakes and emotion recognition carry disclosure duties. This is the obligation most often missed, because a chatbot feels too ordinary to be regulated.
New prohibition, end of the marking grace period
The AI Omnibus added an Article 5 ban covering AI for non-consensual intimate imagery and CSAM, and closed the Article 50(2) marking grace period for generative systems already on the market before 2 August 2026.
Stand-alone high-risk obligations apply
Chapter III for Annex III uses — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice — together with conformity assessment, registration, post-market monitoring and incident reporting.
Product high-risk obligations apply
Article 6(1) high-risk AI embedded as a safety component in Annex I products — machinery, medical devices, vehicles, lifts, toys and the rest of the product legislation.
Dates follow Article 113 of Regulation (EU) 2024/1689 as amended by the AI Omnibus, Regulation (EU) 2026/1744. Amendment dates should be confirmed against the consolidated text before they are relied on for a filing or a board decision — we do that confirmation as part of the engagement.
Fit
Who this is for
You use AI inside the business — Copilot, an applicant tracking system, a CRM scoring model, a support chatbot. You are almost certainly in scope, and almost certainly do not have a complete inventory, because half of it arrived inside software you already owned.
You build AI into a product you sell, or you put your name on someone else's. Your duty set is the long one, and Article 25 can hand it to you without anyone deciding to take it on.
You train, fine-tune or release a general-purpose model. Chapter V has applied since August 2025, and the systemic-risk threshold brings a notification duty with a two-week clock.
A customer or an investor has asked for the certificate. We build the management system so it carries the AI Act work too, rather than leaving you with two programmes and one budget.
You want to know how much of the AI Act you have already covered. Usually more than you expect on governance and competence, less than you hope on risk, data and technical documentation.
Then start here. The scoping questionnaire is fifteen questions and resolves both whether the Act applies and which role you hold. It is the cheapest part of the engagement and it changes everything after it.
Start here
A free 30-minute AI Act scoping call
Bring the list of AI you think you use. We will tell you what is missing from it, which role you most likely hold, and whether anything you run looks like it lands in Annex III. No slides, no pitch deck.
