EU AI Act Readiness and Compliance Services
- Readiness establishes what you have, what tier each system falls in, and what each classification obliges you to do.
- The deliverable is a classification register plus a requirement-by-requirement gap position, not an opinion that you are compliant.
- Run it now, whatever the deadline. Classification takes longer than expected and every later obligation depends on it.
- Readiness typically costs £5,000 to £20,000 and takes two to six weeks.
- The most common finding is systems nobody had recorded, usually AI features inside purchased software.
Readiness and compliance, in sequence
EU AI Act readiness services establish where you stand before you commit to a build. The output is a register of every AI system you provide or use, a documented classification for each, and a requirement-by-requirement statement of what is met, what is not and what closes each gap.
Compliance services then cover the work that follows: writing the technical documentation, establishing risk management, designing human oversight, configuring logging, and putting the transparency disclosures in place.
The two are sequential in a way that is more absolute here than in other frameworks, because until classification is done nobody knows which obligations apply, which dates bind, or what the build will cost.
What a readiness assessment should contain
| Element | What good looks like |
|---|---|
| System inventory | Every AI system provided or used, including AI features inside purchased software |
| Role determination | Provider or deployer for each system, with the reasoning recorded |
| Risk classification | Prohibited, high risk under Annex III or Annex I, Article 50 transparency, or minimal, with the basis stated |
| Applicable dates | Which of the confirmed deadlines binds each system |
| Requirement-by-requirement gaps | For each system, what duty applies, what you currently have, and whether it is sufficient |
| Remediation plan | What closes each gap, who does it, and roughly how long |
| Documentation plan | Which Annex IV technical files are needed and in what order |
| Delivery call | A conversation where the borderline classifications get explained |
The findings should be stated as findings. "These systems fall in this tier, these duties apply, these are met and these are not" is defensible and useful. "You are AI Act compliant" is a warranty on a self-assessed regime, and no responsible practitioner writes it.
When to run readiness
Now, regardless of which deadline applies to you.
The high-risk obligations were moved to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products. That is time to do the work properly, not time to do nothing.
Three things are live before either of those dates. The Article 50 transparency obligations took effect on 2 August 2026. Article 50(2) reaches systems already on the market on 2 December 2026, alongside the new prohibitions on AI generating non-consensual intimate imagery and child sexual abuse material. And classification itself takes weeks to months for anything beyond a handful of systems.
There is also a commercial reason that has nothing to do with deadlines. Enterprise buyers and investors are already asking AI governance questions in due diligence, and the classification register is the artefact that answers them.
What readiness commonly finds
The same items recur.
Systems nobody had recorded, almost always AI features inside software the company already pays for, used by a team that never thought of it as an AI system.
A deployer that has quietly become a provider, by putting its own name on a third-party system or using it for a purpose the original provider did not intend.
Human oversight that exists as a sentence in a policy, assigned to someone with neither the time nor the authority to intervene.
No record of why a classification was reached, so the position cannot be defended or revisited.
Article 50 disclosures missing on customer-facing systems, which is a live obligation rather than a future one.
And GDPR work that covers part of the data governance requirement but was never mapped across, so the same ground gets covered twice.
Cost and timing
| Service | Typical cost | Typical duration |
|---|---|---|
| Inventory and classification | £5,000 to £15,000 | 2 to 6 weeks |
| Full readiness including gap assessment | £5,000 to £20,000 | 3 to 6 weeks |
| Build, depending on high-risk count | £15,000 to £50,000 | 3 to 6 months |
| Annex IV technical file, per system | £8,000 to £25,000 | 3 to 8 weeks each |
Cost scales with system count and high-risk count. A forty-person company with three high-risk systems costs more than a four-hundred-person company with none.
What compliance services cover after readiness
Technical documentation for each high-risk system. A risk management process that runs rather than sits in a folder. Data governance covering training, validation and testing data. Logging that retains what the Act requires for the period it requires. Human oversight designed around a named competent person. Accuracy, robustness and cybersecurity measures. Instructions for deployers where you are a provider. Registration in the EU database where required. And post-market monitoring that continues for the life of the system.
That is our implementation service, and in most programmes it is the largest share of the effort.
What to do next
Build a first-pass inventory yourself. It costs nothing, it is the input every proposal needs, and it usually surfaces two or three systems the leadership team did not know about.
Our free AI impact assessment gives an immediate first view, our readiness and gap assessment produces the full position for a fixed fee, and the EU AI Act service page sets out how readiness and the build fit together.
References
FAQ
What is an EU AI Act readiness assessment?
An inventory of your AI systems, a documented classification for each, and a requirement-by-requirement statement of what is met, what is not, and what closes each gap.
Should we wait until 2027 to start?
No. Article 50 duties are live now, new prohibitions arrive on 2 December 2026, and classification takes weeks to months. The deferral is time to do it properly.
How long does readiness take?
Two to six weeks for most companies, driven by how many systems there are and how many are borderline.
What does readiness cost?
Typically £5,000 to £20,000, scaling with system count rather than headcount.
Can readiness tell us we are compliant?
It can tell you which duties apply and which are met. Compliance for most systems is self-assessed, so no adviser can certify it, and one offering to should be questioned.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. Our readiness and gap assessment is delivered as a fixed fee with a delivery call, and states findings requirement by requirement rather than issuing an opinion. We take companies through the EU AI Act, ISO/IEC 42001, SOC 2 and ISO 27001, and maintain the position afterwards. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not legal advice on your particular circumstances.