Service · Software development

Custom AI Act compliance software development.

The EU AI Act (Regulation 2024/1689) requires organisations that deploy AI to maintain a demonstrable register, risk classification, technical documentation and human oversight. We build the platform in which you manage all of this centrally, tailored to your AI portfolio, your governance and your auditors.

AI system registerRisk classificationHuman-in-the-loopAudit trail

Why a dedicated AI Act platform rather than a generic GRC tool.

The AI Act (Regulation 2024/1689) has been in force since August 2024 and is being phased in until August 2027. It is the world's first comprehensive AI regulation and works on a risk-based model: unacceptable risk is prohibited (government social scoring, real-time biometric identification in public spaces, emotion recognition in the workplace), high risk is heavily regulated, limited risk carries transparency obligations, and minimal risk faces hardly any requirements. High-risk AI comes with strict obligations: an AI system register, a risk management system covering the entire lifecycle, data governance with bias controls, technical documentation, logging, transparency towards users, human oversight, cybersecurity requirements, CE marking and registration in the EU database.

Generic GRC and privacy tools (OneTrust, Holistic AI, comparable suites) are often strong on the legal layer, but they rarely align with the ML process itself: how models are trained, which datasets go in, which metrics signal drift, how human-in-the-loop fits into the production flow. We build the piece that sits between your AI engineers, your compliance officer and your board, either as the core of your AI governance or as a specialised layer alongside existing tooling. For the broader strategy, this ties in with our approach to enterprise AI.

If you bring the AI system to the European market as a product, the requirements of the Cyber Resilience Act also apply: reporting deadlines, security updates and a component inventory. We set up the documentation so that you maintain it once and can use it in two places.

Three flavours of AI Act software.

Depending on where you stand: just starting to take inventory, midway through classifying your first high-risk system, or working on a full governance platform for your entire AI portfolio. We advise which variant suits you in the first working session.

Compact project · fixed sprint budget

AI system register

A central register of all AI systems in your organisation: purpose, dataset, model version, supplier, owner, risk category and compliance status. The starting point for every AI Act implementation and the query many organisations search for, rightly so, because without a register you don't know what the law applies to.

System inventoryOwnershipVersion controlAudit export
Mid-sized project · fixed sprint budget

Compliance dashboard with risk flow

On top of the register: a practical risk assessment flow from project start to decommissioning, classification into unacceptable/high/limited/minimal, and a dashboard where the board and compliance officer see the status of each system at a glance. Includes a technical file vault and model cards.

Risk classificationLifecycle managementDocumentation vaultStatus dashboard
Larger project · fixed sprint budget

Full AI governance platform

Mission-critical platform with bias monitoring, drift detection, human-in-the-loop workflows, incident management, vendor management for third-party AI, and integrations with your ML stack (MLflow, SageMaker, Vertex AI, Azure ML). Suited to organisations with dozens of AI systems, regulated sectors or a pronounced board-level governance question.

Bias & fairnessDrift detectionVendor riskML stack integrations

What you get at the end.

A production-ready AI Act platform, plus everything around it so that your compliance team, AI engineers and auditors can operate it independently.

  • AI system register + classification flowA central register with risk categorisation under the AI Act, ownership per system and automatic trigger events for reclassification when models change.
  • Documentation vaultVersion-controlled storage for technical files, model cards, data sheets, DPIAs, FRIAs and risk assessments, delivered in the format supervisory authorities expect.
  • Logging and audit trailVerifiable logging of model runs, decisions, human reviews and changes to training data, in line with the AI Act requirement for traceability.
  • Bias and drift monitoringFairness metrics for each protected group, drift detection at feature and outcome level, and alerts for your data science team as soon as a model moves outside its tolerance range.
  • Human-in-the-loop workflowConfigurable review and sign-off process for decisions made by high-risk systems, with SLAs, escalation and a complete audit log.
  • Incident and vendor managementRecording of serious incidents in line with the AI Act, risk assessment of third-party AI suppliers, and post-market monitoring per system.
  • Codebase, training and maintenanceFull source code, a deployment runbook, two training sessions for your compliance and data science teams, and an optional maintenance contract for ongoing development.

When AI Act software is the right investment.

Four situations in which we support organisations. If you recognise one of these patterns, we would be happy to discuss the approach with you.

High risk

You deploy AI in a high-risk application

Recruitment, credit assessment, education, critical infrastructure, law enforcement, biometrics, migration or justice. The AI Act imposes its most stringent obligations here: a register, technical documentation, human oversight, CE marking and EU registration.

Scale

Your AI portfolio has outgrown spreadsheets

You can still manage one or two AI systems in Excel. At ten or more, version control, data governance and classification become unmanageable without a central system that connects to your ML stack.

Supervision

You fall under a sector regulator

DNB, AFM, AP, ACM or the Health and Youth Care Inspectorate will examine AI systems alongside sector-specific rules. A demonstrable register and risk management system is then practically essential to get through an audit.

Governance

Your board wants control over AI risks

Directors can be held liable for AI-driven decisions. A dashboard showing the current compliance status of each system lets them discharge that responsibility without relying on verbal updates from the data science department.

Which modules we typically build.

AI system register. The heart of your platform. For each AI system we record purpose, owner, supplier, datasets, model version, deployment location, business impact and risk category. Dynamic fields depend on the category: a high-risk system requires considerably more documentation than a minimal-risk chatbot. The register is searchable, exportable in audit formats and can be connected to your CMDB or MLflow instance.

Risk assessment flow. A structured wizard that guides a new AI project from idea to deployment. At each stage it asks the right questions, automatically classifies the system as unacceptable, high, limited or minimal risk, and includes a gate that prevents a system going live without completed documentation. For high-risk systems this includes a Fundamental Rights Impact Assessment (FRIA) under Article 27.

Documentation vault. Version-controlled storage for technical documentation (Article 11), data sheets, model cards, training data overviews, evaluation reports and declarations of conformity. Templates for the standard formats supervisors expect, with version history and a sign-off process for each document.

Human-in-the-loop module. Configurable review workflows for decisions made by high-risk systems. For each use case you determine which decisions may be automated, which require human sign-off and which should be escalated. Includes SLA tracking, queue management and a complete decision audit log for later reconstruction.

Monitoring layer. Drift detection on input features and output distributions, fairness metrics per protected group, accuracy tracking against benchmarks, and alerts for your data science team. We integrate with MLflow, SageMaker Model Monitor, Vertex AI Model Monitoring or a custom pipeline, depending on your stack.

Incident and post-market monitoring. Logging of serious incidents in line with the AI Act reporting obligation, root cause analysis, corrective actions and reporting flows to your national supervisory authority. For ongoing post-market monitoring per system, we build the automatable part; the legal part remains with your compliance team.

Vendor management. For third-party AI systems, such as a purchased recruitment tool with an AI component or a SaaS supplier using LLMs, we register the supplier, their declarations, their classification and the risks for your organisation. When a contract is renewed, the platform triggers a fresh assessment.

Target groups we serve.

The AI Act affects every organisation deploying AI in the EU, but the impact varies considerably by sector. These are four groups we often work with.

Financial sector

Banks, insurers, asset managers

AI in credit assessment, fraud detection and life insurance pricing almost always falls under high-risk. It also overlaps with DORA (operational resilience) and sector rules from DNB and AFM. We link AI Act compliance to your existing risk management without duplicate administration.

HR & recruitment

Organisations using AI in selection

CV screening, video interview analysis and skills matching: these applications are explicitly listed in Annex III as high risk. This applies both to your own recruitment tooling and to the tools of your suppliers. A register plus vendor management is therefore practically indispensable.

Public sector & healthcare

Government, education, care, critical infrastructure

Almost every AI application in the public sector touches high-risk domains: educational assessment, justice, migration, social services and critical infrastructure, and in healthcare the overlap with the MDR. In addition, transparency requirements around automated decision-making toward citizens often apply.

Tech & scale-ups

Companies selling AI as a core product

If you supply AI functionality to other businesses, you are often a provider under the AI Act and bear the heaviest obligations. For SaaS companies selling to enterprise clients, a demonstrable register and technical file has become a sales requirement; your clients will ask for it during their own audits.

How an AI Act project works.

1

Introduction and AI inventory

Together we map which AI systems you currently have or are building, which suppliers are involved, which processes depend on them, and where the greatest risks lie. For organisations without an existing register, this is often where the real surprises emerge.

2

Workshop: scope, classification and governance

A working session with your compliance officer, data science lead and business owners. We map your AI systems to the AI Act categories, link them to GDPR overlap, and determine which modules are in scope for the first release.

3

Building in sprints

A working build every two weeks. First the register and classification flow, then the documentation vault and audit log, then monitoring and human-in-the-loop. Your team tests along the way, and your compliance officer gives feedback on the legal conformity of each module.

4

Rollout, training and post-market monitoring

Phased rollout per business unit, training for compliance and engineering teams, and ongoing management for security patches, regulatory updates and extensions. The AI Act will keep evolving in the coming years, and your platform needs to keep pace.

Frequently asked questions.

What organisations typically want to know before starting an AI Act implementation.

When does our AI system need to comply with the AI Act?
The Act has been in force since 1 August 2024. The bans on unacceptable-risk AI have applied since February 2025. Obligations for general-purpose AI (GPAI) model providers have been active since August 2025. The stricter rules for high-risk AI are being introduced in phases through to August 2027. For most organisations, that means starting now with inventory and classification, rather than waiting until 2027.
How do I know whether my AI system is high-risk?
The AI Act explicitly lists the high-risk domains: critical infrastructure, education and recruitment, creditworthiness and life insurance, law enforcement, migration and border control, the administration of justice, and certain biometric applications. A risk assessment in our classification flow maps your specific use case to the correct category and determines which obligations apply.
What is the difference between GPAI obligations and high-risk obligations?
GPAI (general-purpose AI) obligations apply to providers of foundation models, such as OpenAI, Anthropic and Mistral. They must provide technical documentation for the model, respect copyright and report on energy efficiency; for models with systemic risk, they also need model evaluation, red-teaming and serious-incident reporting. High-risk obligations apply to whoever deploys such a model in a regulated domain, such as critical infrastructure, recruitment, credit assessment or law enforcement. You can very well be both a user of a GPAI model and a provider of a high-risk AI application at the same time. In that case you take on both roles, and your platform needs to make that separation clear.
Which obligations apply to limited-risk AI, such as chatbots?
For limited-risk systems, such as chatbots, deepfakes and AI-generated text and images, the main requirements are transparency obligations. Users must be told they are interacting with an AI, AI-generated content must be labelled, and deepfakes must be flagged. There is no registration obligation and no technical file, but clear disclosure is required. Our platform also records this category, for example in the central list for your board, but with lighter documentation requirements than for high-risk systems.
Does this replace OneTrust, Holistic AI or similar suites?
Not necessarily. For enterprise organisations with an existing GRC stack, we would rather build a specialised AI layer that works alongside it: the ML side (data governance, drift, fairness, model versions) is ours, while the legal side (policy management, awareness) can stay in your existing tool. For organisations without a major GRC investment, our platform can become the central hub.
How does the AI Act relate to the GDPR?
There is considerable overlap, but one does not replace the other. The GDPR covers personal data, the AI Act covers AI systems, and the two intersect when your AI processes personal data. In practice this means a DPIA is often needed alongside an AI risk assessment, and an automated decision under Article 22 GDPR almost always also falls under the AI Act's high-risk rules. Our platform connects both processes.
What determines the lead time and cost?
Mainly: the number of AI systems that need to go in the register, the maturity level of your existing ML stack, how many data sources are connected for monitoring, and whether you are building a specialised layer or a full governance platform. A register for a single department can be working within a few sprints; an organisation-wide governance platform is a multi-sprint project. After the inventory, we provide a concrete plan.
Do you work together with our legal and data science teams?
Almost always. The AI Act sits at the intersection of law and engineering, so we don't build a page that lawyers can't understand or technology that the data science team can't connect to. We run workshops during scope definition, peer reviews of the classification flow, and knowledge transfer in the final sprint so your team can manage the platform independently.

Talk to us about your AI Act compliance.

A no-obligation introductory call of half an hour. We listen to your AI portfolio, your governance question and your deadlines, and give direction on a platform that fits. Related topics: DORA compliance software, KYC/AML compliance software and custom risk management software. For automation around AI decision-making, this aligns with AI agents.

Edit content