EU Artificial Intelligence Act

We help you comply with the AI Act

The EU AI Act places obligations on any company that uses artificial intelligence, even if it didn't build it. We identify the obligations that apply to you, put them in place and document them, then hand you the documentation file that proves it.

Tell us about your case

The AI you already have in-house

Most of the AI inside a company was never bought as AI. It arrived already switched on in software the company was paying for, and nobody recorded it as a project. These are the places where it usually sits without anyone having assessed it:

  • Automatic CV screening in your HR software
  • Lead or customer scoring in your CRM
  • Anomaly and fraud detection in your ERP
  • The assistant bundled with your office suite
  • The customer service chatbot on your website
  • The recommendation engine in your online shop

Each of those systems carries a risk level and a set of obligations. Some carry none at all. Others fall under Annex III of the Act and bring technical documentation, human oversight and activity logging with them. You can't assume which is which: each one has to be classified.

How we work

Four steps over six to eight weeks, depending on how many systems need reviewing.

01

We find the AI you already use

Including the AI built into third-party software. We work with read-only access to your systems and interviews with the departments that use them.

02

We classify each system

Using the Act's criteria: its risk level, which obligations apply, what permissions and connections it works with, and whether any use is already prohibited.

03

We put the obligations in place

A written usage policy based on how you actually work, supplier and incident procedures, human oversight assigned system by system, and named owners confirmed in writing.

04

We hand over the documentation file

Dated, organised and backed by evidence of what was reviewed for every statement in it. Plus a yearly review so it stays accurate.

If you'd rather start with something shorter, there's an initial two-to-three-week phase that ends with an exposure report: which AI you use, where you're non-compliant today and which of those gaps could lead to a fine. It doesn't put the obligations in place; it identifies them.

What it's useful for

The documentation file doesn't sit in a drawer. It's what you show when someone asks.

  • Answering the AI questionnaires your customers send you
  • Responding to a request from an authority with the documentation already prepared
  • Providing evidence during due diligence or supplier approval
  • Submitting it with a tender that requires it
  • Telling the board which AI is in use and who is accountable for it
  • Meeting the Act's deadlines without a last-minute rush or penalties

What applies and from when

The timeline changed in July 2026: Regulation (EU) 2026/1744, the digital omnibus on AI, postponed the high-risk obligations that were due in August 2026. Everything else stays as it was.

DateWhat applies
Feb 2025Prohibited practices and the obligation to ensure AI literacy among staff. Already enforceable.
Aug 2025Obligations for general-purpose AI models. Already enforceable.
Aug 2026Transparency: telling people they are interacting with an AI and labelling generated content. Already enforceable.
Dec 2026New prohibitions on non-consensual sexual content and child sexual abuse material.
Dec 2027Annex III high-risk systems: HR, credit and insurance, education, biometrics and access to essential services.
Aug 2028AI built into products that are already covered by their own safety legislation.

The postponement didn't change any requirement, only the date from which it can be enforced. Fines for the most serious infringements reach 7% of worldwide annual turnover.

Frequently asked questions

Does the Act apply to me if I only use third-party tools?
Yes, and that's the most common situation. The Act distinguishes between the provider that develops a system and the deployer that uses it, and places obligations on both. If you use third-party AI in a process that affects people, you are the deployer and have obligations of your own: checking that the provider complies, assigning human oversight and keeping usage logs.
If high-risk has been pushed back to December 2027, can I wait?
You can, but waiting doesn't make the work any shorter. What takes time is the inventory and the risk classification, not signing the documents. And some obligations are already enforceable today: prohibited practices, AI literacy for staff and the transparency rules from August 2026. The postponement gives you time to get ready, not a reason to do nothing.
Do systems need to be switched off while they're reviewed?
No. The inventory is carried out with read-only access and interviews with the departments that use each tool. Your systems keep running throughout.
Does this replace the GDPR?
No, it sits alongside it. Many AI systems process personal data, so both sets of rules apply. Any data protection work you've already done is reused, but the AI Act asks for things the GDPR doesn't: risk classification, assigned human oversight and traceability of the system's decisions.
Who does the work?
One of the certified companies in our network that specialises in AI regulatory compliance. Yeeply selects the right company for your case, coordinates the project from start to finish and is accountable to you for the whole process.
How much does it cost?
It depends on how many AI systems need classifying and on the size of your organisation, so the price is agreed once we've looked at your case. Get in touch and we'll send you a proposal with a defined scope.

Shall we look at your case together?

Tell us which systems you use and in which processes. We'll tell you where to start and what the work would cover.

Talk to us