logo

Current legal status incl. Digital Omnibus

EU AI Act Compliance

EU AI Act Compliance: Governance, ISO 42001 and Trustworthy AI Systems

AI inventory and policy

AI inventory and policy

Every system recorded and governed

Preparation for ISO/IEC 42001

Preparation for ISO/IEC 42001

A structured path to certification

Hosted in Germany

Hosted in Germany

Data protection and AI Act aligned

|EU AI Act| Compliance

Which requirements apply to your company?

The requirements depend on two questions: what role does your company play, and which category does the AI system fall into? Providers develop AI systems or place them on the market under their own name. Deployers use AI systems under their own responsibility.

High-risk

Examples: recruitment, creditworthiness assessment. Focus: risk management, documentation and human oversight.

Transparency

Examples: chatbots, AI-generated text and images. Focus: labelling and user information.

Light requirements

Examples: writing assistance, document recognition, spam filters. Focus: internal rules and good practice.

Many applications in mid-sized companies fall into the transparency or light-requirement categories and can be set up properly with manageable effort.

With clear AI governance, you use artificial intelligence with legal certainty and full transparency. We inventory your AI systems, classify them under the EU AI Act and establish the processes that keep you compliant over time, pragmatic and scaled to the size of your company. Compliance support is part of our AI consulting for mid-sized companies.

Implementing the transparency obligations of Article 50

For existing systems, machine-readable labelling applies from 2 December 2026. We implement notices, metadata and the related documentation for your systems.

Chatbots and voice assistants

They clearly identify themselves to users as AI.

AI-generated content

Text, images, audio and video are labelled in a machine-readable way.

Deepfakes

They are clearly disclosed to viewers as artificially generated.

The AI policy for your company

An AI policy gives employees guidance and sets a binding framework. It covers:

  • approved AI tools and their areas of use
  • handling of confidential and personal data
  • labelling of AI-generated content
  • quality assurance and approval processes
  • responsibilities and contacts
  • training and regular updates

We draft your policy based on a proven template and tailor it to your organisation.

Request the AI policy template
AI-supported contract management

ISO 42001 certification: building an AI management system

ISO/IEC 42001 is the internationally recognised, certifiable standard for AI management systems. It extends ISO 27001 with the topics that arise specifically when using AI.

ISO/IEC 27001 and ISO/IEC 42001 compared

  • Focus: information security (27001) and responsible use of AI (42001)
  • Core topics: confidentiality, integrity and availability (27001); fairness, explainability and AI risk management (42001)
  • Combinable: yes, both follow the same management system structure

Our services: gap analysis, setting up processes and controls (data provenance, prompt-injection protection, testing, model monitoring, third-party model management) and focused preparation for the audit by an accredited certification body.

Where does your company stand on the AI Act?

We inventory your AI systems, classify them and show you the next steps.

AI and GDPR: aligning data protection and the AI Act

We combine the requirements of both frameworks in one process: data protection impact assessments, data processing agreements, deletion concepts for vector databases and hosting in Germany. For AI cloud services, we follow the BSI AIC4 criteria catalogue.

For the highest requirements, we run open-source models in your own infrastructure: Sovereign AI with open-source models.

Start with an AI Act check

We inventory your AI systems, classify them and show you the next steps up to 2 December 2026 and beyond.

Let’s Make Things Happen

By submitting my data, I agree to be contacted. I have read and accept the Privacy Policy.