EU AI Act consultant recommendation
- The field is young, so a recommendation based on a completed AI Act programme is rare. Adjacent regulatory delivery is the realistic test.
- Ask what was actually delivered: a classification register, a technical file, or a slide deck. These are very different outputs.
- Your data protection officer, your sector regulator's guidance, and your ISO/IEC 42001 certification body are underused sources.
- A recommendation tells you a firm delivered for someone. Verify the named practitioner, the deliverable, and any commercial arrangement.
- Ask to see redacted written work. In this field it is more informative than a reference.
Where recommendations come from
Getting a good EU AI Act consultant recommendation is harder than for an established framework, and for a straightforward reason: the largest obligations do not apply until December 2027, so very few organisations have been through a complete programme and had it tested.
That does not make recommendations worthless. It changes what you should ask about. Instead of asking who passed, ask what was actually delivered and by whom.
Companies a stage ahead of you. The strongest source where it exists. Someone who has classified an estate and written technical files can tell you what the work involved and what was hard.
Your data protection officer or privacy counsel. They have been dealing with automated decision-making, impact assessments and data governance for years, and they usually know which advisers write to a supervisory standard and which produce slide decks.
Your ISO/IEC 42001 certification body. If you are certified or pursuing certification, the body has seen the management systems that consultancies build. It cannot recommend for its own audit, but naming firms it has encountered is a different thing.
Your sector regulator's published guidance. Not a recommendation, but the FCA, the ICO, the MHRA and their equivalents publish expectations about AI. An adviser who cannot speak to your regulator's stated position is not the right one for a regulated firm.
Your investors and your board. Investors watching several portfolio companies through AI governance work often hold an informal view. Ask whether any commercial arrangement exists.
Industry bodies and professional networks. Practitioner communities in AI governance are small enough that reputations are known. Weight posts that describe what happened over posts that name a firm.
What to ask the person recommending
What did they actually deliver? This is the decisive question. A classification register with recorded reasoning, an Annex IV technical file, a human oversight design, a monitoring process. Or a workshop and a slide deck. Both get described as "they did our AI Act work".
How many systems, and how many high risk? Advising on two internal tools is different from classifying forty systems across three markets.
Who did the work? Names. In a young field the individual matters more than the firm, and people move.
Did the fee hold? Ask whether the final invoice matched the proposal and if not, why.
Would you use them for the next piece? People are more honest about future intent than past satisfaction.
What a recommendation does not tell you
It does not tell you whether the classification was correct, because in most cases nothing external has tested it.
It does not tell you whether the documentation would satisfy a market surveillance authority, for the same reason.
It does not tell you the scope was comparable to yours, or that the same practitioner is available.
None of that is a reason to disregard a recommendation. All of it is a reason to treat it as a starting point.
The verification that matters most
Ask the firm for a redacted Annex IV technical file, or a redacted classification register, that they have written.
In a field with no long track records this is worth more than a reference. It shows in ten minutes whether they write to a supervisory standard, whether the document describes a real system or a template, whether the data governance section engages with actual pipelines, and whether human oversight is described as something a person does.
A firm that has never produced one is selling advice, which may be exactly what you want, but you should know which you are buying.
Three checks before you act
The named practitioner and their committed hours. Ask who runs your programme and how much of their week it gets.
The deliverable, in writing. Get the proposal to name what you will receive: register, technical files, oversight design, monitoring process. Not "AI Act support".
Commercial arrangements. Ask whether the firm pays or receives referral fees, or takes commission from certification bodies or platform vendors. We take none, which is stated on our about page.
If nobody in your network has done it
Common, and workable. Shortlist three firms from different sources: one your privacy counsel names, one from a professional network, one found independently. Give all three the same first-pass inventory and ask for a written proposal against it.
Then ask each to explain how they would classify one of your genuinely borderline systems and why. The reasoning tells you more than the fee does. The full question set is in Recommendations for a Good EU AI Act Compliance consultant.
What to do next
Build a rough inventory before asking anyone for a recommendation. Cost and effort scale with system count, so a recommendation given against a vague brief arrives against a vague scope.
Our free AI impact assessment gives a starting view, and the EU AI Act service page sets out how we run a programme.
References
FAQ
Where can I get an EU AI Act consultant recommendation?
From companies a stage ahead of you, your data protection officer or privacy counsel, your ISO/IEC 42001 certification body, your investors, and professional networks in AI governance.
Can anyone claim years of AI Act experience?
Not credibly. The Act entered into force in August 2024 and its largest duties apply from December 2027. Adjacent regulatory delivery is the realistic measure.
What should I ask a reference?
What was actually delivered, how many systems and how many high risk, who did the work, whether the fee held, and whether they would use the firm again.
What is the best single verification?
Ask to see a redacted technical file or classification register the firm has written.
Is a law firm recommendation better than a consultancy one?
For a borderline classification or a written opinion, yes. For building the technical file and running the programme, usually not.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. Every engagement has a named practitioner and an agreed scope, timetable and fee. We are not a certification body and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not legal advice on your particular circumstances.