Deployers of AI tools
You use AI in decisions about people: recruitment, credit, customer service. Deployer obligations apply even though you built none of it.
EU AI Act · Regulation (EU) 2024/1689
The European Union's Artificial Intelligence Act is phasing in obligations between 2025 and 2027 for organisations that provide or deploy AI systems, including organisations outside the EU whose systems reach the EU market. The alignment review establishes the facts: which of your systems the Act touches, which obligations apply, and where the gaps are, ranked and stated plainly.
The problem
The AI Act regulates by risk category: some practices are prohibited outright, high-risk systems carry substantial obligations around risk management, data governance, documentation, human oversight and monitoring, and general-purpose AI models have their own regime. Which category each of your systems falls into is a factual question about what the system does and where it is used, and most organisations have not answered it system by system. Guessing in either direction is expensive: over-compliance wastes engineering effort, under-compliance risks penalties that scale with global turnover.
The alignment review does the factual work: inventory, classification, obligation mapping and an evidence-based assessment of where your current practices stand.
Deliverables
Who this is for
You use AI in decisions about people: recruitment, credit, customer service. Deployer obligations apply even though you built none of it.
Provider obligations follow your product into the EU market, wherever you are based. Buyers are already asking for evidence of alignment.
The Act and the standard overlap heavily. Map once, use twice: the review's outputs feed directly into an AI management system.
An assurance review, not legal advice: we establish the technical and governance facts, test them against the Act's requirements and document the gaps. Interpretation of genuine legal edge cases belongs with your counsel, and our reports are written to slot straight into that conversation.
FAQ
No, though it helps substantially. The Act is law with its own specific obligations; the standard is a management system that builds the governance, documentation and oversight those obligations rest on. Organisations running both an AI management system and an obligation-level mapping are in the strongest position, and the two share most of their groundwork.
Quite possibly. The Act places obligations on deployers, not only on the companies that build AI. If your organisation uses AI systems in areas the Act treats as higher risk, such as employment decisions or access to essential services, deployer obligations such as human oversight and monitoring apply to you.
No. It is an evidence-based assurance review: we establish what your systems do, classify them with documented reasoning, and test your practices against the Act's requirements. Where genuine legal interpretation is needed, the report frames the question precisely for your counsel, which makes their time cheaper and their answer better.
Request a review
Tell us what AI you provide or deploy and where it is used. We will come back with a fixed scope, a fixed price and a start date.
Contact Attestware