AI systems documented
before a regulator asks, not after.
The EU AI Act classifies AI systems by risk tier and imposes strict documentation requirements on anything high-risk. By the time a regulator asks for that documentation, it's too late to retroactively build the traceability — so we design it in from the start: model cards, bias testing, and human-oversight layers.
Risk-tiered,
not one-size-fits-all.
The Act doesn't treat all AI the same — obligations scale with the risk tier your use case falls into. A chatbot answering product questions and a system influencing employment or credit decisions carry very different documentation and oversight requirements. Working out which tier applies, and designing to it, is part of scoping, not an afterthought.
See our full Trust & Safety framework for the underlying architecture — this page is specifically how it applies for UK and EU teams building AI into their business.
Act requirements,
mapped to architecture.
The same decisions we make on every project, specifically mapped to the Act's requirements for higher-risk systems.
| EU AI Act requirement | What we build |
|---|---|
| Risk classification | We reason through where your use case likely sits as part of scoping — the final call stays with you and your legal counsel, not with us. |
| Technical documentation | A model card for every model we deploy — intended use, limitations, training data provenance, and evaluation results. |
| Bias & fairness testing | Systematic testing for demographic bias and disparate impact across protected characteristics, with documented results. |
| Human oversight | Explainability layers architected in, so a human reviewer can understand and, where required, override a system's output. |
| Logging & traceability | Every prompt, output, and model call logged, timestamped, and queryable — the audit trail the Act's record-keeping obligations assume exists. |
No sales pitch,
just how we work.
Four things that are true of every engagement, not just this one.
Built inside your existing stack — not a rewrite, and not a 7-month hiring cycle.
You know the number before you sign. No open-ended retainer.
Security, data handling, and compliance commitments on paper — not a verbal promise.
You own the code and the model config at project completion. We don't hold it hostage.
Before you
book a call.
The questions we get asked most about the EU AI Act — answered straight, no sales pitch.
Is your AI system EU AI Act compliant?
No system is "EU AI Act compliant" off the shelf — the Act classifies systems by risk tier and imposes obligations based on your specific use case and deployment context, which only you and your legal counsel can ultimately determine. What we build are systems documented and tested to the Act's technical requirements for your risk tier: model cards, bias and fairness testing, and human-oversight design.
What counts as a "high-risk" AI system under the Act?
The Act defines specific high-risk categories — things like employment decisions, credit scoring, and access to essential services are common examples. We'll help you reason through where your use case likely falls as part of scoping, though the final classification call sits with you and your legal counsel, not with us.
What documentation do you provide?
A model card for every model we deploy — intended use, limitations, training data provenance, and evaluation results — plus documented bias and fairness testing results and a data flow diagram. That's the technical documentation substrate the Act's high-risk obligations are built on.
What do you actually deliver for an EU AI Act-relevant project?
The same Trust Spec we deliver on every engagement, with the compliance section mapped to the Act specifically — risk-tier reasoning, model cards and documentation, bias and fairness testing, and the human-oversight and explainability layers a regulator would expect for your risk tier.
Tell us what
you're trying to build.
Book a 30-minute call — we'll tell you honestly what EU AI Act readiness would actually look like for your system.