Take inventory
Record all AI systems and models, including the bought-in and the unofficial ones: SaaS features, copilots, models inside your own products, shadow AI out of the business units.
AI inventoryThe transparency obligations of the EU AI Act have applied since 2 August 2026. Most companies do not know how many AI models they use, let alone in which risk class. We record them, classify them, implement the obligations and leave behind an evidence file that holds up in front of the regulator and the auditor.
The AI Act does not regulate “AI”, it regulates use cases. The same technology is subject to transparency obligations as a customer service chatbot, high-risk in recruitment, and prohibited in emotion recognition at the workplace. Only the classification tells you which obligations apply.
The Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) postponed only the high-risk dates. Art. 50 was not postponed; the only transition period is the marking obligation under Art. 50(2) for generative systems that were on the market before 2 August 2026, running to 2 December 2026 (Commission guidelines C(2026) 5054, paras. 2 and 153).
We treat the AI Act like a security programme, not like a legal opinion: first the inventory, then the class, then the role, then the gap, then the implementation, then the evidence. Stage six does not come to an end. Every new AI system, every model version, every change of role goes through stage one again.
Record all AI systems and models, including the bought-in and the unofficial ones: SaaS features, copilots, models inside your own products, shadow AI out of the business units.
AI inventoryPer system: in scope under Art. 3? Prohibited under Art. 5? High-risk under Art. 6 and Annex I/III? Subject to transparency obligations under Art. 50? GPAI, possibly with systemic risk?
Classification registerProvider, deployer, importer or distributor — often several at once. Anyone who renames a system or substantially modifies it becomes a provider under Art. 25, with everything that follows.
Role matrixObligation by obligation: applicable, met, finding, action. With a key date per obligation and a comparison against existing evidence from the ISMS, the GDPR and NIS2.
Finding register · roadmapTechnical documentation, risk management, logging, human oversight, transparency notices, FRIA. Run as a programme with a SteerCo and handover to your operations.
Implementation programmeOne evidence file per system: decisions, date, the people responsible, the proof. Updated each quarter so that management can demonstrate its duty of care.
Evidence file · quarterly reportThe matrix is the heart of the gap analysis. It shows at a glance which articles bite for your combination of role and risk class. For the deployer of a bought-in chatbot that is two cells. For the provider of a high-risk system it is the entire row.
Every module has a fixed output document and an article reference. You book what your classification requires — a deployer without a high-risk system does not need module 06. Modules 01 to 09 and 11 are mandates with an output document; modules 10 and 12 are ongoing services. Where a statement of ours needs legal review, it is marked as such.
Structured recording of all AI systems and models through interviews, contract review, the SaaS register and technical discovery in cloud accounts. The result is an inventory with purpose, data sources, the business unit that deploys it, provider and supply chain for every system. Shadow AI is actively searched for, not merely asked about.
A documented classification for every system: prohibited, high-risk, subject to transparency obligations, minimal — plus GPAI status and systemic risk (10²⁵ FLOPs). We examine the exemption under Art. 6(3) and document it under Art. 6(4) where you rely on it. Borderline cases we mark as borderline and recommend legal review, rather than smoothing them over.
Provider, deployer, importer, distributor, authorised representative — per system and per contractual relationship. Examined with particular care: when does fine-tuning, white-labelling or a change of purpose make you a provider under Art. 25? Which obligations does your supplier owe you, and are they in the contract?
A targeted review against the prohibited practices, with the emphasis on the borderline cases: emotion recognition in the workplace, biometric categorisation, manipulative design in customer interfaces. For generative systems, additionally the new practices from 2 December 2026 and the question of whether prohibited outputs are a foreseeable result or a purpose.
In force since 2 August 2026. We review and design: the disclosure that a user is interacting with AI; the machine-readable marking of synthetic audio, image, video and text content; deepfake disclosure; informing the people affected where emotion recognition is used. Implemented in your interfaces and output pipelines, not only in a document.
The full programme for providers of high-risk systems: risk management system (Art. 9), data governance (Art. 10), technical documentation under Annex IV (Art. 11), logging (Art. 12), instructions for use (Art. 13), human oversight (Art. 14), accuracy, robustness and cybersecurity (Art. 15), quality management (Art. 17), conformity assessment, EU declaration of conformity, CE marking, registration in the EU database. We lead the programme and build the documentation; conformity assessment by a notified body remains that body’s task wherever it is prescribed.
For companies that use high-risk systems: operation in line with the instructions for use, assignment and training of human oversight, control of input data, log retention, informing employees and the people affected. Where Art. 27 bites — public bodies, creditworthiness, insurance pricing — we carry out the fundamental rights impact assessment and interlock it with the DPIA under the GDPR.
For companies that make their own foundation models available, or adapt someone else’s far enough to count as a provider: technical documentation, information for downstream providers, copyright policy, summary of the training data. Where there is systemic risk, additionally model evaluation, incident reporting and cybersecurity of the model and its infrastructure.
Since 2 February 2025, providers and deployers must ensure that their staff are sufficiently AI-literate — graded by role and context. We draw up the literacy concept, run training for management, the business units and the oversight staff, and document attendance in a form that works as evidence.
The obligations on logging, robustness and cybersecurity are infrastructure tasks. We build the environment your AI systems run in: a separate landing zone on AWS or Azure, infrastructure as code with Terraform, Pulumi or Ansible, logging and metrics with Grafana, Prometheus, Datadog or Dynatrace, retention under Art. 26(6). On request with 24/7 operation and a named point of contact.
The AI Act does not stand alone. A FRIA builds on the DPIA, Art. 15 cybersecurity on the ISMS, incident reporting under Art. 73 on the NIS2 and DORA reporting channels. We map the overlaps so that you produce evidence once and use it several times — and we show where a management system to ISO/IEC 42001 makes sense and where it does not.
After the implementation, running the governance begins: keep the inventory current, classify new systems, reassess model versions, post-market monitoring, follow up incidents. The management receives a report each quarter on a fixed date — in the same format as the cyber governance report, so that both are discussed in one meeting.
Art. 99 grades the fines by severity. In each case the higher amount applies — the fixed sum or the percentage of worldwide turnover in the preceding year; for SMEs, the lower one. On top of that comes what no schedule of fines captures: a system withdrawn from the market, the standstill of a process that depends on it, and the personal question to management of whether it can evidence its duty of care.
Secureskies does not provide legal advice. We structure, document and implement technically; legal assessments in borderline cases, conformity assessment by notified bodies and coordination with the regulator happen with your legal department or law firm. Official self-assessment: the European Commission’s AI Act Service Desk. Harmonised standards (CEN-CENELEC JTC 21) have not yet been published; the Commission’s guidelines on high-risk classification exist as a draft dated 19 May 2026.