Your product uses AI. That does not tell you what the AI Act requires.
We determine whether your product and use cases are in scope, your legal role, the relevant classification, applicable duties and the current timeline — before uncertainty delays a customer deal or turns into unnecessary compliance work.
One product · Up to three AI use cases · Written classification and action plan
The legal question usually arrives through the business.
The trigger is rarely "we need an Article 6 analysis". It is a customer request, a product decision, a contract warranty or an investor question that the team cannot answer confidently.
We determine which statements your company can support and where the requested warranties go beyond your actual obligations.
A conclusion is useful only if it is supported by the intended purpose, affected decisions, product design and written legal reasoning.
Your position may depend on model documentation, technical information and contractual cooperation elsewhere in the AI value chain.
Article 50 can apply even where the product is not classified as high-risk.
Your company may assume provider responsibilities even though another business developed the underlying model or system.
Classification prevents unnecessary compliance work and expensive changes shortly before launch.
Classification is not paperwork. It changes commercial and product decisions.
A customer may request an AI questionnaire, an AI Act warranty, human-oversight information or confirmation that the product is not high-risk.
The answer determines whether the product needs AI notices, machine-readable marking, logging, human oversight or a high-risk compliance framework.
Treating every AI feature as high-risk creates an oversized project. Treating every feature as low-risk can leave Article 50 or other duties unaddressed.
A broad compliance warranty or responsibility clause may make your company promise more than its actual role and available evidence support.
Missing documentation from the external model provider can prevent you from substantiating your own customer-facing compliance position.
Classification determines what must happen now, what can be planned later and which product decisions should not wait for the high-risk deadlines.
Digital Omnibus changed some dates — not the need to classify.
AI literacy measures, existing prohibited practices and GPAI-provider rules.
Article 50 transparency duties, including notices and relevant content-marking requirements.
High-risk obligations for standalone systems classified under Annex III.
High-risk obligations for systems embedded in regulated products under Annex I.
The review applies the revised high-risk timetable, clarified safety-component rules, Article 50 transition where relevant, and available SME or small mid-cap simplifications.
The additional time is for implementing specific high-risk requirements. It does not remove the need to determine whether your product is high-risk, subject to Article 50, dependent on a GPAI provider or outside those regimes. Customer contracts, product architecture, vendor documentation and public compliance statements are being decided now.
The delay gives companies more time to implement high-risk requirements — not a reason to postpone classification.
The consequences are not limited to a fine.
Authorities may require corrective action and may restrict use or sale, withdraw a system from the market or require a recall. In practice, unsupported customer statements and late product changes may become a problem earlier than enforcement.
of worldwide annual turnover for prohibited AI practices.
of worldwide annual turnover for specified operator obligations, including Article 50 transparency duties.
of worldwide annual turnover for incorrect, incomplete or misleading information supplied to authorities.
Maximum statutory amounts. Actual penalties must be proportionate and take account of the circumstances. For SMEs, including start-ups, the relevant ceiling is generally the lower of the fixed amount and turnover percentage.
A reasoned position your product, legal and commercial teams can use.
Separate analysis for up to three intended purposes.
Provider, deployer and relevant value-chain changes.
Conclusion and legal rationale for each use case.
Notices, marking and disclosure duties under Article 50.
GPAI relevance and missing third-party information.
Applicable dates, priority gaps and next steps.
One product · Up to three AI use cases
Delivered within 5 working days after receiving complete materials and holding the product workshop.
Start the reviewPotential high-risk implementation, full technical documentation and company-wide AI governance are scoped separately.
Send what already exists. We identify what is missing.
Send materials
Product description, diagrams, model information, terms or customer questionnaires.
Product workshop
A focused session with the people who understand the intended use and implementation.
Receive the memo
Reasoned classification, obligations matrix and prioritised next steps.
One model. Three use cases. A customer asking for one compliance answer.
A European SaaS company used the same external language model for document summarisation, drafting assistance and a customer-configured ranking feature. A prospective customer asked it to confirm its AI Act status and accept broad compliance warranties.
The internal team had treated the product as one AI system. That did not show whether the three features had the same intended purpose, whether Article 50 applied, whether the ranking function required a separate high-risk analysis or which information had to come from the model provider.
- A written classification and legal rationale for each use case
- A legal-role analysis for the company and the external model provider
- An Article 50 transparency assessment
- A list of missing information to request from the model provider
- Proposed wording for the customer questionnaire and contractual response
- A prioritised roadmap of required and non-required measures
The company had a documented position it could use with the customer, avoided giving a blanket warranty for the entire product and gave its product team a defined list of actions instead of starting an unnecessarily broad AI governance project.
This is a classification and scoping assessment, not an AI Act certification or a complete high-risk compliance audit. Any deeper work identified by the review is quoted separately.
Before you decide whether the review fits.
Send the materials you already have.
We will confirm whether the review fits your situation, what is included, the fee and the delivery date before starting.
Email your product materials
Opens your email app with the subject and questions already filled in. Attach whatever you already have and send.
Send product details →Useful materials include product descriptions, technical diagrams, model documentation, customer-facing materials, terms, AI questionnaires and existing legal analysis.
Email app didn’t open? Write to
Prefer to talk first? Book a 20-minute call