Compliance
Regulation (EU) 2024/1689 creates a risk-tiered framework for AI systems placed on the EU market. Most commercial AI applications fall into the “limited risk” or “high risk” categories. High-risk systems (defined in Annex III) must meet eight specific technical and documentation requirements before deployment: risk management, data governance, technical documentation, transparency, human oversight, accuracy, cybersecurity, and automatic event logging.
We help US-based companies building AI products for EU users understand their obligations, classify their systems under the correct risk tier, and implement the required technical controls. The work produces documentation your legal counsel can use for the conformity assessment.
Tell us what you're building.
The Act places every AI system into one of four tiers. Your tier determines what you must do before deploying. Getting the classification wrong (even by misreading Annex III) is a material legal risk.
Unacceptable risk AI is banned outright in the EU. This includes social scoring systems by public authorities, AI that exploits vulnerabilities of specific groups, most real-time remote biometric identification in public spaces, and manipulative subliminal techniques. If your system touches these categories, it cannot legally operate in the EU market.
Requires a conformity assessment before deployment. Annex III covers 8 categories: biometric identification, critical infrastructure, education, employment and HR management, essential services (credit, benefits), law enforcement, migration and border control, and administration of justice. Requirements include risk management, data governance, technical documentation, event logging, transparency, human oversight, and accuracy.
Transparency obligations only. Chatbots must disclose to users that they are interacting with an AI system. AI-generated content (including deepfakes) must be labelled as artificially generated. No conformity assessment is required.
No mandatory requirements under the Act. Spam filters, AI in video games, and most general-purpose productivity tools fall here. You may voluntarily adopt codes of conduct, but no compliance programme is legally required.
These are the six technical deliverables we produce for every high-risk AI engagement. Each maps to a specific article of Regulation (EU) 2024/1689.
A documented risk identification, evaluation, and mitigation log covering the full lifecycle of the system, from design through deployment and post-market monitoring. Updated as the system changes.
Data lineage documentation, bias evaluation across relevant demographic groups, and data quality measures. Required for high-risk systems. We document sources, preprocessing steps, and known limitations.
System architecture description, training data description, performance metrics on representative test sets, and a documented list of known limitations and foreseeable misuse scenarios. Required before deployment.
Automatic event logs covering all high-risk operations, including inputs, outputs, timestamps, and the identity of persons who initiated the operation. Logs must be retained for the period specified by the applicable sectoral law.
Controls that allow human operators to monitor system operation, intervene, override outputs, and stop the system. The interface must be designed so the oversight person can understand the system's output well enough to make a meaningful intervention.
Documented benchmark results against the intended use case, including performance across subgroups where relevant. The system must be resilient to errors, faults, and adversarial inputs that could affect safety or fundamental rights.
If your product deploys or fine-tunes a General Purpose AI model, as defined in Article 3(63) and regulated under Articles 51–56, you have obligations beyond the high-risk tier requirements. These include: model capability evaluation, adversarial testing (red teaming), incident reporting to the EU AI Office, and publication of a sufficiently detailed technical summary.
GPAI models with “systemic risk” (currently defined as models trained with more than 1025 FLOPs) have additional requirements including adversarial testing before release and notification to the European Commission. Most fine-tuned or hosted foundation models from third-party providers (OpenAI, Anthropic, Google) shift the GPAI obligations to the model provider, not to you as the deployer. We can scope these obligations separately.
Read the full regulation text (EUR-Lex) →We turn down projects that are outside our scope.
US companies with zero EU market exposure
Article 2 of Regulation (EU) 2024/1689 explicitly limits scope to AI systems placed on the EU market or put into service in the EU. If you have no EU users, no EU customers, and no EU data subjects, you are outside the Act's scope.
Internal tools with no EU-based users or data
Purely internal tools used only by employees located outside the EU, processing no EU resident data, fall outside scope. If that changes (even one EU-based user) scope applies.
Anyone expecting a legal compliance sign-off without the work
We build the technical controls: risk management system, documentation, logging, oversight interfaces, and accuracy testing. Your legal counsel certifies compliance and signs the Declaration of Conformity. We do not provide legal opinions.