NEW The 2026 State of AI Trust Report is now available. Read the report →

AI Compliance

Readiness you can evidence, not readiness you can assert

AI regulation has moved from consultation to enforcement. The question a supervisory authority asks is not whether you have a policy — it is whether you can produce the record.

What this covers

Four compliance capabilities

Regulatory readiness Gap assessment against the regimes that apply to you, by role — provider, deployer, importer, or distributor.
Compliance automation Controls and evidence collection wired into the delivery pipeline, so documentation is a by-product of building rather than a project of its own.
Evidence & documentation Technical documentation, risk management files, data governance records, and logs, structured to the form the regulation expects.
Audit preparation Rehearsal against the questions an auditor or supervisory authority will actually ask, and remediation of what that rehearsal exposes.

EU AI Act

Where the obligations currently stand

Regulation (EU) 2024/1689 applies in phases. The dates below are the operative ones for planning; obligations attach differently to providers and deployers, and both may apply to the same organisation.

2 Feb 2025
Prohibitions on unacceptable-risk practices, and AI literacy obligations, took effect.
2 Aug 2025
Obligations on providers of general-purpose AI models began applying, together with the Member State governance and penalty architecture.
2 Aug 2026
General application of the Regulation, including transparency obligations and the Annex III high-risk regime as originally legislated.
Dec 2027
Under the provisional agreement reached in May 2026, the compliance deadline for Annex III high-risk systems is extended. Organisations should plan against the extension without relying on it, and should watch for the final adopted text.
Standards
Harmonised standards remain in development. ISO/IEC 42001 covers a substantial share of the organisational and documentation expectations but certifies a management system, not a product — it is not a substitute for conformity evidence on a specific high-risk system.

Beyond Europe

One system, several regimes

A model deployed across markets meets more than one rulebook. We assess against the regimes that apply to your footprint and identify the controls that satisfy several at once, so compliance work is done once rather than repeated per jurisdiction.

  • EU AI Act
  • Sectoral financial regulation
  • Medical device regimes
  • Data protection law
  • Employment and equality law
  • Consumer protection duties
Regulatory intelligence
Certified engineer programming an industrial robot on an automotive assembly line.

Deploy AI with confidence.

Start with an independent assessment of your highest-stakes AI system.