AI Compliance
Readiness you can evidence, not readiness you can assert
AI regulation has moved from consultation to enforcement. The question a supervisory authority asks is not whether you have a policy — it is whether you can produce the record.
What this covers
Four compliance capabilities
EU AI Act
Where the obligations currently stand
Regulation (EU) 2024/1689 applies in phases. The dates below are the operative ones for planning; obligations attach differently to providers and deployers, and both may apply to the same organisation.
- 2 Feb 2025
- Prohibitions on unacceptable-risk practices, and AI literacy obligations, took effect.
- 2 Aug 2025
- Obligations on providers of general-purpose AI models began applying, together with the Member State governance and penalty architecture.
- 2 Aug 2026
- General application of the Regulation, including transparency obligations and the Annex III high-risk regime as originally legislated.
- Dec 2027
- Under the provisional agreement reached in May 2026, the compliance deadline for Annex III high-risk systems is extended. Organisations should plan against the extension without relying on it, and should watch for the final adopted text.
- Standards
- Harmonised standards remain in development. ISO/IEC 42001 covers a substantial share of the organisational and documentation expectations but certifies a management system, not a product — it is not a substitute for conformity evidence on a specific high-risk system.
Beyond Europe
One system, several regimes
A model deployed across markets meets more than one rulebook. We assess against the regimes that apply to your footprint and identify the controls that satisfy several at once, so compliance work is done once rather than repeated per jurisdiction.
- EU AI Act
- Sectoral financial regulation
- Medical device regimes
- Data protection law
- Employment and equality law
- Consumer protection duties
Related capabilities
Deploy AI with confidence.
Start with an independent assessment of your highest-stakes AI system.