← All services Our services

EU AI Act: from scan to dossier

For anyone using AI or shipping AI inside their own product. We determine per system which risk category it falls into, which role you hold and what that means in obligations. Then we build the dossier that goes with it.

The regulation is not one deadline, and since the Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026) the dates diverge further. Prohibited practices have applied since 2 February 2025. The Article 50 transparency duties have applied since 2 August 2026. High risk under Annex III moved to 2 December 2027, and AI embedded in regulated products to 2 August 2028. In between sits 2 December 2026: generative systems already on the market before 2 August 2026 must mark their AI output machine-readably by then, and two new prohibited practices take effect. Which date counts for you depends on what your system does and which role you hold. Working that out is a short engagement; finding out during an inspection costs more.

What you get

Classification per AI system: prohibited, high risk, transparency or minimal Your role per system: provider, deployer, importer or distributor AI inventory, transparency notices and the logging the regulation requires A FRIA alongside the DPIA where both are required A timeline showing what has to be ready when, using the revised Digital Omnibus dates

Priced per case. The difference sits in the number of AI systems and whether you build them or only use them. You can start for free with the quickscan on this site: that gives you the category, this engagement gives you the dossier.

Does your AI fall under the EU AI Act?

Free · 10 questions · 3 minutes

Start the quickscan →
EU AI Act: from scan to dossier

Questions and answers about this service

What do I need to arrange for the EU AI Act?

First, for each AI system, determine which risk category it falls into and which role you hold, because your obligations follow from that. Datawonder delivers the classification per system, your role (provider, deployer, importer or distributor), an AI inventory, transparency notices, the logging the regulation requires, a FRIA where needed and a timeline of what has to be ready when.

Which EU AI Act dates apply?

Prohibited practices and the AI literacy duty have applied since 2 February 2025. The Article 50 transparency duty has applied since 2 August 2026. On 2 December 2026, generative systems that were already on the market before 2 August 2026 must mark their AI output machine-readably and two new prohibited practices take effect. High risk under Annex III follows on 2 December 2027 and AI in regulated products on 2 August 2028. These dates come from the Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026.

Am I a provider or a deployer?

If you build an AI system yourself or put it on the market under your own name, you are a provider. If you use someone else's AI tool in your own work, you are a deployer, and you have obligations of your own in that role too. That distinction is often misjudged and it determines which duties rest on you.

Who is an EU AI Act project for?

For organisations that use AI or have AI inside their own product, such as a chatbot or voice agent for customers, AI tools staff use every day or a software product of their own with AI features. The scope depends on the number of AI systems and whether you build them yourself or only use them.

How do I get started with the EU AI Act?

For free, with the quickscan on this site: ten questions in about three minutes. You see straight away which risk category your application falls into. Alongside that, make an inventory: for each AI application the purpose, the supplier, which data goes in and who checks the outcome. That list is the basis for the dossier this project delivers.

Thinking along, arranging it, staying inside the law

Three things that don't fit in a service list, but that decide how working with me feels.

I think along with you

You're not hiring a pair of hands that builds whatever the brief says. If I think your question isn't your real problem, I'll say so. Often there's a simpler or cheaper route, and sometimes the answer is that you shouldn't build this yet. Sparring over that choice is part of the work.

You don't have to figure it out

I run the whole track: choice of technology, the build, integrations with your existing systems, testing with real cases, explaining it to your team and maintenance afterwards. One point of contact, and one person responsible when something breaks. No vendors pointing at each other.

Compliant, and provably so

Everything I build has to survive current legislation: GDPR, the EU AI Act and the Data Act. That means agreeing up front which data the system may see, where it is processed, retention periods, a data processing agreement and a log of what the system did. So you can explain it when somebody asks.

Other services

AI voice agents and telephony

An agent that answers the phone after hours, at peak moments and when everyone is already on a call. It recognises why someone is calling, books an appointment in your calendar, transfers when unsure and emails you the rest.

View this service →

Process automation

The work nobody enjoys: retyping invoices, moving data from system A to system B, producing the same report every Monday. I map the steps and build the chain that runs without you.

View this service →

Custom software, SaaS & AI assistants

For when off-the-shelf doesn't fit: a portal, an internal tool, or an assistant that answers from your own documents and data. Built around your way of working, not a vendor's.

View this service →

AI audit & AI training

The cheapest way to start. I come to you, and afterwards you get a report with the processes that return the most, what each costs, what it saves and what goes wrong if you approach it badly. I also run AI training for teams: what the technology can and cannot do, how to use it safely, and where the gains sit in your own work.

View this service →

GDPR & privacy in order

Mapping what happens to personal data and delivering the documents you need to be able to show: a record of processing activities, a DPIA where one is required, processor agreements and a working method for data breaches and data subject requests.

View this service →

European software regulation

GDPR and the AI Act are not the only laws that touch your software. Depending on what you build and for whom, NIS2, the Cyber Resilience Act, the accessibility directives, the Data Act or DORA apply too. I work out which ones apply to you and what has to happen next.

View this service →

Penetration testing and security testing

I attack your own software with your written permission, looking for what an attacker would find: logging in without the right password, reaching another customer's data, changing an amount in an order. Whatever works, you get on paper with the evidence attached and with the check that proves later on that it is really closed.

View this service →

Ready to see what's being left on the table?

Book a free thirty-minute call. You'll get an honest answer, even when that answer is “don't do this yet”.

Book your free intro call → Free · 30 minutes · no obligations