EU AI Act  ·  AI Governance  ·  Risk & Readiness

EU AI Act Compliance & AI Governance Services

EU AI Act compliance and AI governance services for businesses developing, procuring or deploying AI — including role and risk classification, transparency obligations, AI Act gap analysis, governance, impact assessments, documentation and vendor controls.

Designed to turn AI Act requirements into practical ownership, policies, evidence and implementation — while aligning AI governance with data protection, operational resilience and existing risk frameworks.

Scope & Role
Provider · Deployer
Other operator roles
Risk
Use-case based
classification
Governance
Policies · Controls
Evidence
Cross-Regime
GDPR · DORA
Sector rules
AI Act risk classification

The First Question Is Not “Do You Use AI?” — It Is How the AI Is Used.

AI Act obligations depend on the use case, intended purpose, deployment context and the organisation's role. Classification is therefore a practical first step — but it should be tied to the real operating model, not applied as a generic label to the technology.

01 · Prohibited AI

Is the proposed use permitted at all?

Certain AI practices are prohibited, including specified forms of manipulation, exploitation, social scoring and restricted biometric or emotion-recognition uses.

First step: test the use case against Article 5 and the applicable exceptions.
02 · High-Risk AI

Does the use case fall within a high-risk category?

High-risk rules can apply to sensitive uses in employment, education, biometrics, essential services and other Annex III areas, as well as certain AI embedded in regulated products. In financial services, creditworthiness and credit scoring of natural persons and certain life/health insurance risk or pricing uses are key examples.

Not every compliance or fraud tool is automatically high-risk.
03 · Transparency Risk

Does the system trigger specific disclosure duties?

Article 50 covers defined transparency scenarios, including direct interaction with AI, certain AI-generated or manipulated content, deepfakes, emotion recognition and biometric categorisation.

Article 50 transparency obligations apply from 2 August 2026.
04 · Minimal / Other AI

Is the use outside the high-risk framework?

Many ordinary AI uses do not trigger the AI Act's high-risk compliance regime. That does not mean “no compliance”: GDPR, consumer, employment, cybersecurity and sector-specific rules may still apply.

Classification should always be followed by a cross-regulatory check.
2 August 2026Article 50 transparency obligations apply.
2 December 2027Core high-risk requirements apply to Annex III systems.
2 August 2028Core high-risk requirements apply to Annex I product-embedded systems.

General-Purpose AI (GPAI)

GPAI follows a separate obligations framework focused mainly on model providers. The relevant duties include documentation and information requirements, copyright-related obligations and additional requirements for models presenting systemic risk. Businesses using third-party GPAI should distinguish those provider obligations from their own obligations as deployers of downstream AI systems.

Key EU regulatory sourcesAI Act — Regulation (EU) 2024/1689AI Omnibus — Regulation (EU) 2026/1744Article 50 Transparency Guidelines
Scope of service

EU AI Act Compliance — Six Practical Workstreams.

The service is structured around the questions clients usually need to solve: what is in scope, where the gaps are, how governance should work, what evidence is needed, whether impact assessments are required and how third-party AI should be controlled.

01 · Scope, Role & Risk

AI Act Scope, Role & Risk Assessment

Determine which AI systems and use cases matter, how the organisation is classified and which obligations are triggered.

  • AI use-case and system inventory
  • Provider / deployer / other role mapping
  • Prohibited, high-risk and transparency classification
  • Obligations map by use case
02 · Readiness

AI Act Readiness & Gap Assessment

Review the current operating model against applicable AI Act requirements and identify the work needed before implementation deadlines or supervisory review.

  • Governance and documentation review
  • Control and evidence gaps
  • Human oversight and monitoring review
  • Prioritised remediation roadmap
Regulatory Gap Analysis
03 · Governance

AI Governance & Compliance Framework

Build the policies, decision rights and operating procedures needed to govern AI consistently across development, procurement and use.

  • AI governance framework and AI policy
  • Roles, approvals and escalation
  • Employee / GenAI use rules
  • Human oversight, incidents and change governance
  • Management and board reporting
04 · High-Risk AI

High-Risk AI & Conformity Readiness

Governance and regulatory documentation support for organisations developing or deploying high-risk AI systems.

  • Risk-management and governance documentation
  • Data-governance documentation support
  • Human oversight and instructions-for-use review
  • Technical-documentation coordination
  • Registration, monitoring and conformity-readiness support
05 · Impact Assessments

AI Impact Assessments & Data Protection

Integrated support where AI use affects fundamental rights, personal data, profiling or automated decision-making.

  • Fundamental Rights Impact Assessment where Article 27 applies
  • GDPR DPIA where Article 35 applies
  • DPIA / FRIA alignment and cross-referencing
  • Article 22, transparency and privacy-by-design analysis
See DPIA & Privacy Risk Assessment →
06 · Third-Party AI

AI Vendor, Procurement & Contract Governance

Regulatory due diligence and contract support for businesses procuring or deploying third-party AI in material processes.

  • Vendor and role due diligence
  • Documentation and transparency review
  • Responsibility and information-right allocation
  • Incident, change, audit and monitoring clauses
  • Exit and dependency considerations
Technical and assurance boundary. LEX ARTA covers the regulatory, governance and documentation workstream. AI engineering, model development, technical testing and notified-body conformity assessment are coordinated with appropriately qualified specialist providers where required.
Cross-regulatory interfaces

AI Compliance Does Not Sit in Isolation.

AI systems often sit inside existing privacy, ICT, employment, consumer and sector-regulatory frameworks. The engagement can be structured so that AI Act implementation builds on those controls rather than creating a parallel compliance system.

GDPR & Data Protection

Training and inference data, profiling, automated decisions, transparency, DPIA and privacy-by-design.

DORA & ICT Risk

For financial entities: AI used in ICT-supported processes, third-party dependencies, resilience and control ownership.

Employment & HR

Recruitment, worker management, monitoring and decision-support use cases require careful role, risk and rights analysis.

Consumer & Sector Rules

AI disclosures and controls may also need to align with consumer protection, financial-services and other sector requirements.

Who we work with

Businesses Developing, Procuring or Deploying AI.

The service is designed for organisations that need to understand what the AI Act means for a real product, process or third-party tool — and turn that analysis into governance and implementation.

FinTech & Financial Services
Banks, payment firms, EMIs, investment businesses, CASPs and FinTech companies using AI in customer, risk, fraud, compliance or operational processes.
SaaS & AI Providers
Technology companies building or offering AI-enabled products and needing role, risk, documentation and customer-allocation analysis.
Businesses Using Third-Party AI
Organisations deploying vendor AI, copilots, decision-support systems or generative AI in material business processes.
Employers & HR Tech
Businesses using AI in recruitment, workforce management, evaluation or monitoring and needing high-risk and fundamental-rights analysis.
Consumer Platforms
Digital businesses using AI in customer interaction, recommendations, content generation or automated decision flows.
International Market Entrants
Non-EU businesses assessing whether their AI products, services or outputs bring them within the EU AI Act perimeter.
Why LEX ARTA

Regulatory Depth Without Building a Parallel AI Compliance Silo.

The objective is not another standalone AI policy. It is a governance model that fits the organisation's existing risk, privacy, outsourcing and regulatory architecture.

Use-case first
Classification begins with the actual system, intended purpose, users and business process — not with generic AI labels.
Cross-regime view
AI Act analysis is connected with GDPR, DORA and sector obligations where the same system sits across several regulatory frameworks.
Implementation-focused
Outputs are structured around ownership, controls, documentation, evidence and practical remediation rather than abstract legal summaries.
Specialist delivery model
Technical testing, engineering and assurance work can be coordinated with specialist providers while the regulatory workstream remains clearly defined.
Selected credentials and practitioner background. ACAMS Certified · CySEC AML Certified · ACFE Member · PhD in Law · practitioner experience across AML/CFT, compliance, investigations and regulatory work. Artlex Consult s.r.o. is a regulatory and compliance advisory company; reserved local-law or other licensed professional work is handled by appropriately qualified practitioners where required.
Common client questions

EU AI Act Compliance — Frequently Asked Questions.

We use ChatGPT, Copilot or other third-party AI tools internally. What should we do?
+
Start with an inventory of tools, use cases, data entered, ownership and vendor roles. Then define role and risk classification, internal use rules, vendor review and alignment with GDPR and security controls.
How do we know whether we are an AI provider or deployer?
+
It depends on the actual use of the system. Using a third-party system as intended may indicate a deployer role, while material changes to the system, intended purpose or branding can affect role allocation.
When can an AI system be high-risk?
+
High-risk status depends on the use case and the Article 6 criteria and relevant annexes. Sensitive areas include certain employment, education, biometric, essential-service, creditworthiness and insurance uses.
Do we need a DPIA, a Fundamental Rights Impact Assessment, or both?
+
It depends on the use case and role. A GDPR DPIA applies where processing is likely to create high risk for individuals; an AI Act FRIA applies only to the specified deployers and high-risk use cases. Where both apply, the assessments should be aligned to avoid duplication.
What should an internal AI policy cover?
+
Approved and restricted uses, ownership and escalation, generative-AI use, data handling, procurement and vendor checks, human oversight, documentation, incident handling and approval of new use cases.
What should we require from an AI vendor before procurement?
+
Confirm the vendor role, intended purpose and risk classification, available documentation, monitoring and incident processes, data dependencies, audit or information rights, responsibility allocation and exit arrangements.
What AI Act deadlines should businesses plan for now?
+
The relevant timetable depends on the obligation and AI category. Businesses should map the rules applicable to their systems and maintain a dated implementation plan rather than relying on one general compliance deadline.
Does the EU AI Act apply to businesses outside the EU?
+
Potentially. The territorial rules can capture non-EU providers or deployers where the conditions in the AI Act are met. The assessment should be based on the actual offering, use and EU connection.
Legal & Regulatory Services

Explore Legal & Regulatory Services.

01
Financial Services Regulatory Advisory →
02
PSD2 / PSD3 Support →
03
DORA Compliance →
04 · Current
EU AI Act Compliance
05
Regulatory Gap Assessment →
06
Regulatory Responses →
07
Investment & Financial Services →
← Hub
Legal & Regulatory Overview →
Related: DPIA & Privacy Impact Assessment  ·  DORA Compliance  ·  DPO & Privacy Governance
Need to turn AI Act requirements into a workable compliance plan?
Start with the AI use cases, the organisation's role and the current governance model. The engagement can then be scoped around classification, readiness, governance, impact assessments or third-party AI.