COMPLIANCE
Governance & AI Act
The EU AI Act doesn't ask you to stop innovating. It asks you to know what you're running, at what risk level, and to be able to prove it.
The problem this solves
In most organizations, nobody knows exactly how many AI systems are actually in use: a scoring module in the ERP, a resume-screening component, three assistants built by business teams without going through IT. Compliance starts with that inventory, and it's almost always the step that gets skipped.
Our approach
- An inventory of every system in use, including those built outside IT — that's where the surprises are.
- Classification by risk level as defined in the regulation: unacceptable, high risk, limited risk, minimal risk.
- Impact assessments for high-risk systems, with the associated mitigation measures.
- Drafting the required technical documentation and setting up the usage register, kept up to date by your teams.
What you get
- A register of AI systems, classified and documented, that your team can maintain in-house.
- Risk and impact assessments for the systems concerned.
- The technical documentation and disclosure notices required for your users.
- A qualification procedure for future systems: every new project is classified before it launches.
FAQ
Frequently asked questions
Does the AI Act apply to a small business that only uses ChatGPT?
Yes, but with light obligations. Using a conversational assistant for writing falls under limited risk: the main obligation is transparency — telling people they're interacting with an AI or that content is AI-generated. The heavier obligations target high-risk systems, particularly in recruitment, credit, education and access to essential services.
How do we know if one of our systems is classified as "high risk"?
The regulation lists the relevant domains in an annex. In practice, for an ordinary business, the three most common cases are automated resume screening, decision support for granting credit or insurance, and employee evaluation. If a system decides or strongly influences a person's access to a job, a right or a service, it needs close scrutiny.
What are the actual risks of non-compliance?
The regulation provides for administrative fines that can reach several percent of global revenue, depending on the severity of the breach. Beyond the penalty itself, the immediate risk for a small business is contractual: large clients now require compliance guarantees from their suppliers.
Do we need an AI officer the way we have a DPO?
The regulation doesn't require a role equivalent to a data protection officer. It does require that the people using these systems have a sufficient level of proficiency, which implies clearly designated owners and a training plan.
Contact
Let's talk about your next use case.
Thirty minutes is enough to work out together whether an aumia diagnostic makes sense for your organization. No commitment, no jargon.