All services
EU AI Act Compliance Package
Phase 03 — Enterprise AI Solutions

AI Act compliance, ready for your next audit

We classify your AI use cases against the EU AI Act, build your AI register, write your DPIA templates and stand up your governance committee — so your compliance team has receipts, not headaches.

Features

What you get

EU AI Act risk classification

We catalogue every AI use case in your company — ChatGPT, Copilot, Bedrock, custom models — and classify each one against the AI Act's risk tiers. You know exactly which systems need what.

AI register and DPIA templates

A live AI register your team maintains, plus DPIA and AI Impact Assessment templates ready for your DPO. Built once, reusable for every new AI rollout.

Governance committee setup

We help you stand up an internal AI governance committee, draft its charter, define escalation paths and review cadence, and run the first two meetings with you.

Process

From discovery to documented compliance

1

AI inventory & risk classification

Two-week sprint to discover every AI use case across your company and classify each against the AI Act.

2

Documentation & templates

We deliver your AI register, DPIA template, vendor risk assessment template, and an Acceptable Use Policy in DE+EN.

3

Governance committee launch

Charter, roles, cadence, escalation paths — and we run the kickoff meeting with your stakeholders.

4

Monthly retainer

Ongoing reviews of new AI use cases, regulatory monitoring, and a quarterly risk-tier re-assessment.

The EU AI Act is here — and it has teeth

Since August 2024 the EU AI Act is reality. Bans on unacceptable risks have applied since February 2025, GPAI obligations since August 2025, high-risk requirements from August 2026. Penalties reach up to €35M or 7 % of global annual revenue — whichever is higher. Most mid-sized companies already use AI (ChatGPT, Copilot, custom bots) and don't know which risk tier they fall into. We bring clarity, documentation and a governance process you can actually live with.

Aug 2026
High-risk obligations live
up to 7 %
of global revenue at risk
100 %
audit-ready documentation
Use Cases

Who needs the compliance package

Three typical starting points from the German Mittelstand.

🛡️
Insurer · 280 employees

Risk assessment with ChatGPT-based tooling — high-risk system under the AI Act. Regulator asks for documentation.

Complete AI register, DPIA packs for every high-risk system, governance committee live. Passed BaFin audit with no follow-up requests.
🏭
Machinery manufacturer · 450 employees

150+ employees use Copilot, ChatGPT and Gemini without clear rules. Works council demands a position on AI Act conformity.

Acceptable Use Policy rolled out in DE+EN, training programme with proof of attendance, all tools classified. Works-council hearing closed in a single session.
🏥
Hospital network · 600 employees

AI-supported triage (high-risk application). Hospital owner requires GPAI and high-risk documentation before rollout.

Technical documentation, DPIA and governance charter delivered. Rollout cleared 6 weeks ahead of schedule.
Technology

Four building blocks for AI Act compliance

Compliance isn't a document — it's a process. We build it so your team can run it without the consulting clock ticking forever.

classification

Risk classification — the inventory

Every AI use case in your business gets classified against the four AI Act risk tiers: minimal, limited, high, unacceptable. You know exactly which system triggers which obligations.

documentation

Mandatory documentation — the evidence pack

AI register, DPIA templates, technical documentation, vendor risk assessment. All in DE+EN, all reusable for every new AI rollout.

monitoring

Continuous monitoring — the watchdog

Quarterly re-classification of new systems, regulatory update tracking, audit prep. Compliance that grows with your business.

training

Training records — the staff protection

The AI Act requires you to train staff on AI risks. We supply the material, attendance tracking and proof — all audit-ready.

Pricing
On request Individual quote

scoped to complexity

  • Risk classification per EU AI Act
  • AI register and DPIA templates
  • Vendor risk assessment for AI tools
Same phase

Related services

Enterprise
Pricing
On request
scoped to complexity

AI Foundation on AWS

A governed AI environment on your own AWS account: Bedrock with access to Claude and OpenAI (ChatGPT) models, Guardrails, audit logs and cost controls — set up in 4 weeks.

  • AWS Bedrock + Guardrails in Frankfurt
  • Access to Claude and OpenAI models
  • Cost controls and full audit trail
Learn more
Pricing
On request
scoped to complexity

AI Assistant for Your Business

A digital team member that knows all your company documents and gives your staff the right answers instantly — around the clock.

  • Knows your entire company knowledge
  • Built into your daily tools
  • Gets smarter over time
Learn more
Enterprise
Pricing
On request
scoped to complexity

Agent Factory

A management platform for AI agents: deploy new agents independently, assign tasks, monitor results — no external vendor required.

  • Deploy new agents at the push of a button
  • Assign tasks & monitor results
  • Own AWS account, enterprise-grade security
Learn more
Regulated industries
Pricing
On request
scoped to complexity

Sovereign LLM Deployment

AI inside your own AWS environment — your keys, your data, no traffic to the public internet. For finance, healthcare and the public sector.

  • Data never leaves your AWS network
  • Encrypted with your own keys
  • Zero data retention with the model provider
Learn more
Pricing
On request
scoped to complexity

AI Cost & FinOps

Stop paying for what you don't need. Audit your AI spend, implement caching, set budgets, and assign costs back to teams.

  • Audit existing Bedrock & API spend
  • Prompt caching and model right-sizing
  • Per-team chargeback dashboards
Learn more
Pricing
On request
scoped to complexity

AI Security & Red-Team Audit

We test your AI systems the way an attacker would: prompt injection, data leakage, agent abuse and MCP server hardening — with a fix list you can act on.

  • Prompt injection & data leakage tests
  • MCP server and agent hardening
  • Prioritised remediation report
Learn more
No sales pitch. No pressure. Just a conversation.

Let's talk.

30 minutes, no obligation, no cost. We'll honestly tell you if and how we can help.