AI Act readiness
From AI Act classification to a board that can defend the programme, in one focused engagement.
The EU AI Act is the first regulation that governs AI systems directly, with obligations that scale to risk classification. Norwegian entities are in scope through the EEA. Here is what a provider or deployer of an AI system has to deliver, and how I run a programme that lets the board stand behind it.
What we deliver
-
ScopingClassifies each AI system against the AI Act risk categories (prohibited, high-risk, limited, or minimal) and clarifies the role as provider, deployer, distributor, or importer.
-
Gap analysis against the core requirementsWe assess your current AI systems and governance controls against the core AI Act requirements and produce a prioritised list of what needs to close before each application date.
-
Risk management and data governanceWe build the risk management system, the Annex IV technical documentation, the data quality controls, and the post-market monitoring that Articles 17 and 72 expect.
-
Human oversight and transparencyWe design the oversight mechanisms, user instructions, and transparency obligations that Articles 13 and 14 require for high-risk systems.
-
Supply chain and GPAIMaps obligations against GPAI models you depend on, and the duties that come with integrating those components further downstream.
-
Board accountabilityWe design the board's reporting cadence for AI governance, run the required training, and document oversight so the management body can stand behind the programme.
How we deliver this service
- In a project
Classification, gap analysis, and roadmap with clear owners and dates.
- In a role at the customer
Programme owner inside the organisation through transposition and up to each application date.
- As part of a service
Included in the Secured by FM CyberSecurity bundle as an ongoing AI-compliance programme.
Recent insights on AI Act readiness
- ISO 27001 vs NIS2: what each one is, and how they differ
ISO 27001 is a voluntary standard you can be certified against. NIS2 is EU law with mandatory duties, reporting clocks and fines. They overlap in content, not in consequence.
- How long does ISO 27001 take?
The ISO 27001 timeline depends on your starting point, the controls you need to implement and the certification body's audit schedule.
- Where AI can help with ISO 27001 preparation
AI can help draft policies and organise evidence. People still need to make risk decisions, implement controls and verify that the records describe reality.