ConsultancyAI governance
In control of AI, ready for the AI Act.
The EU AI Act sets requirements for every organisation that develops or uses AI. We map your AI, assess the risks and set up policy, oversight and documentation. Guided by an IAPP-certified AI Governance Professional (AIGP).
Which rules apply to your use case?
The AI Act classifies AI systems by risk. Pick an example to see its risk class, what is expected of you and from when.
Simplified and indicative, not legal advice. The classification depends on the exact use case and on your role, for example as provider or deployer. In addition, the AI Act asks every organisation that uses AI to pay attention to the AI literacy of its staff (Art. 4), and separate rules apply to providers of general-purpose AI models.
What applies when.
The AI Act takes effect in phases. The Digital Omnibus of July 2026 moved the deadlines for high-risk systems; the prohibitions and transparency obligations stayed in place.
Entry into force
The AI Act takes effect.
Prohibitions and AI literacy
Prohibited practices and the AI literacy duty start to apply.
General-purpose AI models
Rules for GPAI providers, governance and penalties.
Transparency obligations
Art. 50. The Digital Omnibus entered into force just before.
Marking and a new prohibition
Transition for existing generative systems ends.
High risk, Annex III
Including recruitment, credit and education.
High risk, Annex I
AI in products such as medical devices.
Dates according to the AI Act (Regulation (EU) 2024/1689) as amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744). Always consult the official text on EUR-Lex before making decisions.
Certified in AI governance.
Anton Dolganov is a certified Artificial Intelligence Governance Professional (AIGP) of the IAPP, the global professional association for privacy and AI governance. The certification tests knowledge of AI governance across the full life cycle: from laws and standards such as the EU AI Act, the NIST AI Risk Management Framework and ISO/IEC 42001, to managing risk in the development and deployment of AI.
We combine that knowledge with hands-on experience building AI, including in healthcare, where the AI Act meets the MDR and IVDR. That way governance does not stay on paper, but works in the systems and processes you use.
View the profile on LinkedIn (opens in a new window)What we set up for you.
From a first overview to a full management system. We build on what you already have for privacy, security and quality.
AI register and classification
An overview of all AI systems, including purchased systems and AI embedded in existing software, with the risk class of each system and your role as provider or deployer.
- Art. 6
- Annex III
- Role assessment
Gap analysis and roadmap
What is already in place, what is missing and what comes first, with a plan that fits the deadlines of the AI Act.
- Art. 9 to 15
- Art. 26
- Prioritisation
Policy and governance structure
AI policy, roles and responsibilities, and an AI board that decides on new applications.
- AI policy
- RACI
- AI board
AI management system
A management system according to ISO/IEC 42001, aligned with your ISO 27001 or quality system.
- ISO/IEC 42001
- ISO/IEC 23894
- NIST AI RMF
Impact assessments
A fundamental rights impact assessment and a DPIA in one coherent process, so you do not do the same work twice.
- FRIA, Art. 27
- DPIA, GDPR Art. 35
Procurement and suppliers
Requirements and contract clauses for purchased AI, and review of the documentation suppliers provide.
- Due diligence
- Contract requirements
AI literacy
Tailored training for boards, professionals and developers, from awareness to responsible design.
- Art. 4
- Board
- Teams
From overview to demonstrable control.
Six steps we take together with your legal team, privacy officer and IT. After each step you can carry on independently.
- 01
Inventory
A complete AI register, including purchased systems and AI in existing software.
- 02
Classify
For each system, the risk class and your role: provider, deployer, importer or distributor.
- 03
Gap analysis
What is in place, what is missing and what comes first.
- 04
Set up
Policy, roles and processes for new applications, aligned with privacy and security.
- 05
Document
Technical documentation, impact assessments and evidence for regulators and customers.
- 06
Embed
Monitoring, incident reporting, periodic reassessment and AI literacy.
Further reading on the AI Act.
Practical articles on the mistakes we see most often, the Digital Omnibus and the obligations that come with procured AI.
Do you know which AI runs in your organisation?
An AI Act scan gives you a register, a classification per system and a prioritised action list.
Book an AI Act scan