Hael
Book a meeting
EU AI Act · Choosing an adviser

Recommendations for a Good EU AI Act Compliance consultant

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 9 min read
Key takeaways
  • Score candidates on seven things: classification method, written work, oversight design, data governance depth, monitoring cover, currency on the law, and independence.
  • A good consultant records reasoning, not just conclusions, and says when a classification is genuinely arguable.
  • Test currency by asking what changed in 2026. Anyone still quoting 2 August 2026 for high-risk obligations is out of date.
  • Ask how they would evidence Article 10 data governance for a model you bought rather than built.
  • Insist on knowing who writes the Annex IV technical file.

The seven marks

A good EU AI Act compliance consultant does three things a weaker one does not. They classify from what a system actually does rather than from its name. They write documentation that describes your real system in terms a supervisor would accept. And they tell you when a position is genuinely arguable instead of asserting certainty.

Everything below is a way of testing for those during the selection conversation. Use it as a scorecard across two or three firms.

MarkWhat good looks likeHow to test it
Classification methodStarts from what the system does, who it affects, and your role for itAsk them to classify one of your systems out loud and explain the reasoning
Written workProduces documentation a supervisory authority would acceptAsk for a redacted Annex IV technical file or classification register
Oversight designBuilds oversight around a named person with time and authorityAsk who performs oversight on a system like yours, and what they can actually stop
Data governance depthEngages with real pipelines and with bought modelsAsk how they would evidence Article 10 for a model you did not build
Monitoring coverEngagement continues past the documentationAsk explicitly when their involvement ends
Currency on the lawKnows the 2026 changes and what did not changeAsk what moved in 2026 and what did not
IndependenceNo commission from certification bodies or platform vendorsAsk directly, in writing

1. How they classify

Classification is the decision every obligation, date and cost follows from. A good consultant asks what the system does, who it affects, what decisions it influences, which markets it reaches, and whether your name is on it. Only then do they reach for Annex III.

They also check the direction most people miss: whether you have become a provider without realising, by rebranding a third-party system, modifying it substantially, or using it for a purpose the original provider did not intend.

Ask a candidate to classify one of your systems in the conversation. Two minutes of reasoning tells you more than any credential.

2. What they write

Ask for a redacted Annex IV technical file or a classification register they have produced.

In a field this young, written work is the most reliable evidence of capability. You are looking for a document that describes a specific system rather than a template, a data governance section that engages with actual data sources, performance claims with a basis, and human oversight described as something a person does rather than as an aspiration.

A firm that has never written one is selling advice. That is a legitimate product, and you should know you are buying it.

3. How they design human oversight

The Act asks for measures enabling a competent person to understand the system, remain aware of automation bias, interpret output, decline to use it, and intervene or stop it.

Ask a candidate who performs oversight on a system like yours, how much of their time it takes, whether they see output before it takes effect, and what they can stop without asking permission. A good answer is concrete on all four. A weaker answer names a job title.

4. Data governance for models you did not build

Article 10 asks about the data used for training, validation and testing: how it was collected, what it is assumed to represent, whether it is relevant and sufficiently representative, what gaps exist, and what bias examination was done.

For a model you bought, those answers sit with your supplier, and your contract may not entitle you to them. Ask a candidate how they handle that. A good answer covers what to request, what to do when the supplier declines, how to document the limitation honestly, and what it means for your classification and your risk assessment. A weak answer is that you rely on the vendor.

5. Whether they stay past the documentation

Post-market monitoring runs for the life of each system. Technical files must be updated when systems materially change. Serious incidents must be reported within defined windows.

Ask when the engagement ends. At the classification register, at the technical files, or continuing. All three are legitimate products at different prices, and they are frequently quoted as if they were the same one. Where the need continues, that is our continuous governance and assurance service.

6. Whether they are current

This is the fastest test available, because the law moved this year.

Ask what changed in 2026. A current answer covers the Digital Omnibus on AI, endorsed by the European Parliament on 16 June 2026, approved by the Council on 29 June 2026 and in force since July, which moved high-risk obligations to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products.

A good answer also covers what did not change. The Article 50 transparency obligations took effect on 2 August 2026 on the original schedule, Article 50(2) reaches systems already on the market on 2 December 2026, and the prohibited practices list was expanded rather than relaxed, with new prohibitions on AI generating non-consensual intimate imagery and child sexual abuse material from 2 December 2026.

Anyone still describing 2 August 2026 as the high-risk deadline has not updated since the spring.

7. Independence

Ask whether the firm takes commission from any certification body or notified body, whether it receives referral fees from platform vendors, and whether it certifies as well as advises. None of these is improper on its own. You should simply know before you choose. Our own position is on the about page.

What a good proposal contains

Named systems and the classification approach. Deliverables listed individually rather than described as a programme. Fees itemised per phase and per system, since system count is the real cost driver. Dated milestones. A responsibility table with one name against each workstream. The named practitioner and committed hours. What triggers a fee change. And whether monitoring is included, optional or absent.

Two proposals cannot be compared until both quote against the same inventory.

What to do next

Build a first-pass inventory, then give the same one to two or three firms and run the seven marks across their written answers.

Our free AI impact assessment gives a first view, our readiness and gap assessment gives the full position for a fixed fee, and the EU AI Act service page sets out how we work.

References

FAQ

What makes a good EU AI Act consultant?

Classification from what the system does, written work a supervisor would accept, oversight designed around a real person, genuine engagement with data governance, cover past the documentation, currency on the 2026 changes, and no commission arrangements.

How do I test whether a consultant is current?

Ask what changed in 2026 and what did not. High-risk obligations moved to December 2027 and August 2028. Article 50 transparency duties did not move and took effect on 2 August 2026.

What is the best single piece of evidence of capability?

A redacted Annex IV technical file or classification register they have written.

Should the fee be per programme or per system?

Per system, or itemised by system. System count and high-risk count drive the work, and a single programme number hides both.

What should I insist on in the proposal?

Itemised fees, deliverables named individually, a responsibility table, dated milestones, the named practitioner, and a clear statement on whether monitoring is included.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of regulatory practice. Every engagement has a named practitioner, a written scope, a responsibility table and a fixed fee. We are not a certification body and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not legal advice on your particular circumstances.

Free check

See where you stand on EU AI Act, free.

Answer a short set of questions and see what EU AI Act expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether EU AI Act applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to EU AI Act.

Or speak to us about your deadline. Book a meeting.