You do not have to build AI to be liable for it
The most expensive misunderstanding we hear: "we do not develop artificial intelligence, so the regulation is not our problem." Regulation (EU) 2024/1689 places separate obligations on the people who provide AI systems and the people who deploy them. If your staff use AI tools, you are a deployer.
And most companies cannot answer the first question an inspector asks: which AI systems are you running?
The timeline has moved more than once. Do not set internal deadlines from a news article or from this page — check the consolidated text in the Official Journal and any implementing acts. This page describes the mechanism and is not legal advice.
Four questions you need answers to
- Which AI systems do we use? Including features switched on by default in software you already own, tools bought on departmental cards, and browser extensions staff installed themselves.
- What risk does each carry? Prohibited practices, high-risk systems, systems with transparency duties, and everything else. Classification drives every obligation that follows.
- Who supervises them? High-risk systems need real human oversight — named, competent people with the authority and the means to intervene or stop the system.
- Do our staff understand what they are using? The AI literacy obligation applies to deployers, not just to model builders.
Where high-risk usually shows up in an ordinary company
- Recruitment — CV screening, applicant ranking, assessment tools. The most common one, and often bought by HR without IT involved.
- Employee evaluation — anything influencing promotion, task allocation or termination.
- Access to essential services — creditworthiness scoring, pricing of certain insurance.
- Safety components in products — relevant if you manufacture equipment.
Practical rule of thumb: an agent matching invoices to purchase orders is normally not high-risk. An agent ranking job applicants very probably is. The obligations differ enormously, and getting the classification wrong in either direction is expensive — over-classifying costs you money, under-classifying costs you a penalty.
What we deliver
Documentation
- An AI register in a format your team can actually maintain
- A record per system with classification and the reasoning behind it
- Human oversight description: who, what they see, when they intervene
- An internal AI usage policy staff can follow
- AI literacy training material
Working mechanisms
- Decision logging that lets you reconstruct any output later
- Confidence thresholds with automatic human escalation
- Pinned model versions, so behaviour cannot change silently
- Reference test sets run on a schedule, results retained as evidence
- Content marking where transparency duties apply
Do this once, not three times
The AI Act, NIS2 and data protection overlap heavily. Your AI inventory is also part of your NIS2 asset inventory. Assessing a model vendor is also a supply chain risk assessment. If the system touches personal data, GDPR applies alongside, not instead.
Companies that hire three separate consultancies end up with three inventories that do not reconcile — and pay three times for the same interviews. We do it as one engagement.
Start with the inventory
It is useful no matter how the timeline shifts, because you cannot govern what you do not know you have. The readiness assessment produces it in three weeks alongside the risk classification and the automation business case.
Book a free 30-minute call — we will tell you roughly how exposed you are before you spend anything.
Find out what this would cost you — in 30 minutes, free
Tell us one process that eats your team's time. We will tell you on the call whether an AI agent can take it over, roughly what it costs, and what it would save. If it is not a good fit, we say so — we would rather lose the sale than sell you the wrong thing.
