EU AI Act consulting: readiness check, risk tiers and documentation

Our EU AI Act consulting starts with a structured readiness check: capture all AI systems, establish likely roles and risk classes, then identify requirements for legal validation. Next we support documentation—system descriptions, risk-management templates and logging where relevant. You get a clear roadmap for EU AI Act compliance work, not a legal opinion or compliance guarantee.
Status: September 2026. Primary sources: European Commission overview of the AI Act entering into force and the European Commission implementation update.
AI Act readiness check: five steps
- AI inventory: all models, SaaS AI and automations in use.
- Risk classification: map each system to EU tiers and obligations.
- Gap analysis: compare current documentation and governance to requirements.
- Action plan: documentation, roles, training and tooling.
- Monitoring: review cycles and change management for new AI apps.
What we deliver
Inventory & risk classification
Structured capture of AI in HR, service, Copilot, custom models and vendors—with risk tier per system.
Documentation setup
Annex-style technical packs, logging concepts and templates aligned to your architecture—not generic PDFs.
Governance & training
AI owner role, approval flows, human oversight and workshops for management, IT and business teams.
Ongoing compliance rhythm
Review cycles when tools or models change—linked to Microsoft Copilot and AI agents where relevant.
Deep-dive topic: EU AI Act for SMEs. Estimate effort via AI costs.
EU AI Act consulting: definition and risk classes
Definition: The EU AI Act governs artificial intelligence across the European Union. It groups AI systems into four risk classes. Each class has graduated duties, from prohibition to transparency or conformity assessment. Our consulting classifies your use cases and derives the required measures.
The matrix shows the four risk classes with examples, obligations and consequence. For company rollout see AI implementation.
| Risk class | Examples | Obligations | Consequence |
|---|---|---|---|
| Unacceptable risk | Social scoring, manipulative systems | Prohibited | Use banned |
| High risk | AI in HR, lending, medical | Conformity assessment, docs, oversight | Strict requirements before use |
| Limited risk | Chatbots, deepfakes | Transparency duty (labelling) | Disclosure to users |
| Minimal risk | Spam filters, AI in games | No special obligations | Voluntary codes of conduct |
Compliance: EU AI Act and responsible rollout
EU AI Act consulting on /en/services/eu-ai-act-consulting – with clear risk classes and governance. Introduction: AI implementation. Overview: AI services overview.
Frequently asked questions
FAQ: EU AI Act consulting
EU AI Act: fundamentals and compliance
What does the EU AI Act mean for companies in Germany?
Regulation (EU) 2024/1689 sets different duties depending on the organisation's role, the system and its risk class.
A company may be a provider, deployer, importer or distributor, and high-risk obligations are not identical for every role. Groenewold IT supports technical and organisational analysis but does not replace legal advice.
How does an EU AI Act rollout typically run?
A structured rollout starts with an AI inventory.
Risk classification then maps each system to one of four tiers. A gap analysis compares current controls with the requirements. The action plan covers documentation, governance and training. Ongoing monitoring completes the cycle. We support each technical and organisational step.
What does AI compliance consulting include?
AI compliance consulting starts with inventory and risk classification.
It also covers technical documentation, governance, human oversight, staff training and monitoring. We act as a technical-organisational partner. Specialised IT law firms handle legal classification.
Which steps belong to EU AI Act implementation in Germany?
First, inventory every AI system and assign its risk class.
Next, review documentation and define governance with owners, oversight and approval flows. Then train teams and establish monitoring. The scope depends on each system's risk class.
What is AI compliance in a company?
AI compliance combines technical and organisational controls for lawful AI use.
Under the EU AI Act, these include transparency, documentation and risk classification. High-risk systems also require human oversight. Defined approvals and monitoring govern new AI applications.
Which companies must implement the EU AI Act?
Scope depends on whether an organisation is a provider, deployer, importer or distributor and on the concrete system classification.
Higher-risk contexts can include HR, creditworthiness and critical infrastructure. Timelines are staggered and include special cases, so relevant dates should be checked per role and system rather than treated as one universal deadline.
What is the EU AI Act?
Regulation (EU) 2024/1689 is the first comprehensive EU framework for AI.
It classifies systems from prohibited to minimal risk. The rules set duties for providers and deployers. Their purpose is trustworthy AI across the single market.
When does the EU AI Act apply?
The Act has been in force since August 2024, but its provisions apply in stages and include special or transitional rules.
The relevant date depends on role, risk class and system type. Companies should maintain an AI inventory and verify deadlines for each use case with qualified legal counsel.
What are high-risk AI systems under the EU AI Act?
High-risk systems operate in sensitive areas.
Examples include HR, credit scoring, biometric identification, critical infrastructure, education, justice and medical devices. They require strict documentation, transparency and conformity assessment.
What documentation do we need for the EU AI Act?
High-risk systems need a system description, training-data records and performance metrics.
They also require conformity declarations, risk management and quality-management evidence. Logging and monitoring concepts complete the technical pack. We support these records from a technical-organisational perspective, not as legal counsel.
What does AI compliance cost after the EU AI Act?
The EU AI Act cost calculator gives EUR 1,999 – 137,049 excl.
VAT as its non-binding overall range. The concrete result depends on the number and risk class of systems. Inventory and classification sit lower than full documentation for a high-risk system.
Ongoing governance and annual reviews are quoted separately by system inventory and review cadence. Our AI cost overview provides more context.
EU AI Act consulting vs AI implementation: what comes first?
For high-risk or GPAI systems, classify risk and document first.
For early pilots without critical decisions, implementation plus privacy review may suffice—deep compliance when the use case is clear.

Discuss EU AI Act compliance
In an intro call we clarify which systems are in scope and sensible next steps.


