Risk Classification & Gap Analysis
Reliably define AI system risk levels and identify gaps in existing compliance measures.
We help organizations classify AI risk, build governance that regulators approve and train teams to use AI responsibly. We combine deep expertise with legal clarity you can act on.
EU AI Act adds another layer to complex EU regulations like GDPR, NIS2 and sectoral laws.
Regulators, investors and enterprise customers now expect a documented, defensible compliance position - not a best-effort policy on file.
Left unresolved, that uncertainty delays deals, funding rounds and deployments. AI Act penalties alone can reach €35 million or 7% of global turnover per incident.
Our services
Reliably define AI system risk levels and identify gaps in existing compliance measures.
AI Goverance for tailored for your organization - policies, roles and documentation built to withstand audits.
Practical, role-specific AI literacy sessions for leadership and teams.
The EU Artificial Intelligence Act is a new regulation that applies to all AI systems placed on the EU market or used within the EU. It is often referred to as (“AI Act”).
The AI Act introduces a wide range of obligations. The scope of these requirements depends on the organisation’s role (such as provider, deployer or distributor) and the system’s risk level. Non-compliance can result in administrative fines of up to €35 million.
The EU AI Act classifies AI systems into four risk categories.
Unacceptable Risk
AI systems that threaten fundamental rights are prohibited and cannot be developed or used in the EU.
Examples: AI used for social scoring or exploiting vulnerabilities of specific groups.
High Risk
High-risk AI systems must meet strict requirements, including security, governance, transparency and documentation measures. Many AI use cases in healthcare, education, critical infrastructure and human resources fall into this category.
Examples: AI used for cancer detection, or systems used to assess job applicants.
Limited Risk
Limited-risk AI systems are subject to transparency obligations. Users must be informed when they are interacting with an AI system.
Example: AI-assisted customer service chatbots
(Note: the public sector faces additional restrictions.)
Minimal Risk
Minimal-risk AI systems are not subject to specific obligations under the AI Act.
Example: basic spam filtering.
Everything starts with a clear overview of how AI is currently used in your organization. Begin by mapping your existing AI use cases. This allows you to prioritize systems based on their risk level.
A practical way to get started is to build on processes you already have in place, such as data protection risk assessments. It is also important to appoint a responsible person or team for AI governance.
In short: map your AI use, prioritize by risk and establish a governance process.
Some obligations, such as the obligation to ensure adequate AI literacy and the prohibitions on certain AI use cases, are already applicable. Transparency obligations will apply from August 2026. Obligations for high-risk AI systems will become applicable in phases (2027-2028).