Knowing what the AI Act requires of you, which security risks each use brings and which controls you need. It starts with an applicability review, system by system.
In most companies AI does not arrive with a project. It arrives with a Copilot licence, a browser extension, a new feature in the CRM or someone in sales using their personal ChatGPT account. When someone asks what is being used, with what data and what the AI Act requires, nobody has the full answer.
This service brings order from a cybersecurity standpoint: what applies to you and by when, which risks each use brings and which controls you need to keep using AI without improvising.
Staff use assistants on their own, the tools you pay for switch on AI features with every update, and there is no inventory of what is used or with what information.
A client sends a questionnaire about your use of AI, the board asks about the AI Act, or the Omnibus has moved dates and it is unclear which ones affect you.
A chatbot, an agent connected to your systems or an AI recruitment tool. It pays to know how it will be protected and which obligations come with it before you sign or deploy.
It is where almost every engagement starts. It begins with an inventory of what is actually in use and ends with a matrix that answers four questions for each system.
The actual classification depends on how each system is used and is documented case by case, with its reasoning. The second example is worked through in the guide to AI in recruitment.
They can be engaged together or separately. It almost always starts with the first, because it decides how much of the other two you need.
What the AI Act requires of you and how it fits with what you already comply with.
Rules, owners and a process for deciding before AI turns up on its own.
The risks specific to AI, built into the usual security analysis.
Four phases, with scope and days agreed before starting. If you only need the applicability review, the engagement ends at the third.
Which AI is actually in use: what you pay for, what comes switched on inside other tools and what people use on their own.
Role, classification and obligations for each system, with their dates and where they overlap with the GDPR, NIS2 or the CRA.
Gaps ranked by risk and deadline: what must be resolved now, what can wait and who owns each item.
Policy, controls and training put in place with your team, plus an inventory that can be kept up to date when the next tool arrives.
A written answer to what applies to you, and the plan to resolve what is missing.
Scope of the serviceThe work is technical and compliance-focused: what applies to you, what is missing and how to resolve it. It does not replace legal advice; when a case is in a grey area, such as whether a system is high-risk or whether a modification makes you a provider, I document it with its reasoning so that your legal adviser can confirm it. I don't issue ISO/IEC 42001 certificates or conformity assessments, I don't run penetration tests against models and I don't resell AI tools.
Yes, although usually in its lightest form. Using a general-purpose assistant to draft or summarise is not a high-risk use, but it makes you a deployer: you have to take AI literacy measures for the people who use it and make sure nobody uses it for something that is classified, such as filtering CVs. On top of that, whatever is pasted into the assistant is still subject to the GDPR and to your confidentiality commitments.
It has postponed the high-risk obligations: to 2 December 2027 for Annex III systems and to 2 August 2028 for Annex I systems. Prohibited practices have applied since February 2025 and are extended on 2 December 2026, and the AI literacy duty still applies, now worded as taking measures to support it. It is all explained in the article on the Omnibus.
No. My job is to identify what applies to you, what is missing and how to resolve it with controls, processes and training. When the answer depends on interpreting the regulation in a borderline case, I document it with the arguments for and against so that your legal adviser can settle it. That tends to be a short conversation, because the technical work is already done.
It is not mandatory, and being certified does not mean you comply with the AI Act either. It is a good framework for organising AI governance and demonstrating it to clients, and the applicability review is a sound basis for the statement of applicability the standard requires. You can gauge your starting point with the ISO 42001 checklist; certification, if you go for it, is issued by an accredited body.
Permissions, above all. Copilot answers with whatever each user can already open, so folders shared with the whole organisation or sites without an owner end up surfacing in an answer. Before the rollout it is worth reviewing data exposure, labelling and data loss prevention policies, work that overlaps with Microsoft security and DLP.
It depends on the number of systems and on whether there is in-house development. An organisation that uses third-party AI for internal tasks can be reviewed in a few days; if there are high-risk cases or an in-house product with AI, it takes weeks. Scope and days are agreed before starting, so you know the cost from the outset.
Tell me which tools you use, whether anything has been built in-house and who is asking. One conversation is enough to see whether a few days of applicability review will do or whether it makes sense to set up full AI governance.
I reply personally within 24 working hours · No commitment