Solutions AYJIS EU AI Act Industries Vision Pricing Company Request Assessment
EU AI Act Readiness

The fastest path to EU AI Act readiness.

The EU AI Act is the world's first comprehensive AI law — and it is already in force. For regulated European organisations, readiness is now a board-level obligation, not a future project. OneCompliant™ gets you from "we're not sure where we stand" to a defensible, evidenced position in weeks.

Who It Applies To

If you build, buy, or deploy AI in Europe, you are in scope.

The Act reaches far beyond AI developers. It applies to providers that build or brand AI systems and to deployers that use them — including organisations that simply adopt third-party AI tools. It applies to organisations outside the EU whenever their AI output is used inside it. In practice, that means most mid-market and enterprise organisations operating in Europe today.

Providers

You develop, brand, or place an AI system on the EU market — including AI you build on top of a foundation model.

Deployers

You use an AI system in the course of business. Most obligations that surprise organisations sit here.

Outside the EU

The Act applies whenever your AI's output is used within the EU, regardless of where you are based.

The Risk-Based Approach

The Act sorts AI into four risk tiers. Your obligations follow the tier.

The first step to readiness is knowing which of your AI systems fall into which tier — because that determines what you must do. Most organisations have never classified their AI this way, and most underestimate how much of it is high-risk.

Unacceptable

Prohibited

Practices such as social scoring and manipulative AI are banned outright. Already in force.

High-risk

Strict obligations

AI in areas like employment, credit, critical infrastructure, and safety. This is where the real work sits.

Limited

Transparency duties

Chatbots and generated content must be disclosed to the people interacting with them.

Minimal

Few obligations

Most everyday AI. Low regulatory burden — but you still need to prove it belongs here.

General-purpose AI models — the foundation models many tools are built on — carry their own dedicated obligations on top of this.

EU AI Act Compliance Roadmap

Where are you on the roadmap?

The Act came into force in August 2024 and applies in phases. Here's what applies today — and what's ahead after the 2026 Digital Omnibus moved the high-risk deadlines to fixed later dates.

✓ Aug 2024
In force
Regulation adopted
Governance programmes should begin
✓ Feb 2025
Prohibited practices & AI literacy
Unacceptable-risk AI banned
AI-literacy duties (Art. 4) begin
Build your AI inventory
✓ Aug 2025
General-purpose AI (GPAI)
Foundation-model obligations
Governance bodies established
Penalty provisions in force
● Aug 2026
Transparency & operational governance
Transparency obligations (Art. 50) now apply — disclosing AI use, labelling AI-generated & deepfake content
Focus now: governance, risk management, human oversight, logging, monitoring & runtime controls
Most organisations are here today

Beyond the dates, compliance is not a one-off deadline. Because AI systems change continuously, it becomes an operating loop — which is exactly where AYJIS lives:

Assessment Governance Runtime enforcement Monitoring Audit evidence Continuous compliance

The dates may have moved. The work did not disappear. Organisations still need the inventory, governance, controls, documentation, and evidence required to meet those obligations.

Applicability depends on whether the organisation acts as a provider, deployer, importer, distributor, authorised representative, or product manufacturer, and on the classification and intended purpose of each AI system. OneCompliant supports compliance readiness and operational control implementation — it does not, on its own, guarantee legal compliance.

From Requirement To Solution

Every stage of the Act, mapped to OneCompliant.

Not a timeline to admire — a set of obligations, each with a concrete answer.

EU AI Act requirementOneCompliant
AI inventory (discover shadow AI)OASAT
Risk assessment & classificationOASAT
Governance & controlsOASF
Runtime controls & human oversightAYJIS
AI security & data protectionAYJIS
Audit evidence & loggingAYJIS
Executive & board reportingOneCompliant dashboard
Why It Matters Now

The penalties are set at GDPR scale — and higher.

Non-compliance is not a paperwork risk. The Act's fines are tiered to the severity of the breach and calculated against global turnover.

€35M / 7%

Up to €35 million or 7% of worldwide annual turnover for breaching the prohibitions on banned AI practices.

€15M / 3%

Up to €15 million or 3% of worldwide annual turnover for non-compliance with most other obligations, including those for high-risk systems.

€7.5M / 1%

Up to €7.5 million or 1% of turnover for supplying incorrect or misleading information to authorities.

Beyond fines, the real cost is commercial: audits you cannot pass, tenders you cannot win, and insurers who cannot price your risk. Readiness protects revenue, not just compliance.

What Readiness Requires

Readiness is a defined set of controls — not a mystery.

For high-risk AI, the Act expects concrete, operational capabilities. This is the checklist auditors and customers will hold you to.

A complete inventory of the AI systems you build and use — including shadow AI
Risk classification of each system against the Act's tiers
A risk-management process across each AI system's lifecycle
Data governance covering the data your AI consumes and produces
Human oversight designed into high-risk AI, not bolted on
Transparency for users interacting with AI or AI-generated content
Record-keeping and logging that stands up as audit evidence
Post-market monitoring and clear accountability for AI risk
The OneCompliant Readiness Path

Four steps. Weeks, not quarters.

Large vendors sell you a platform and a multi-year programme. OneCompliant gives you a defined path to readiness that produces evidence at every step — built and deployed by people who have run security in regulated enterprises.

1

Assess — OASAT

A fixed-price assessment inventories your AI, classifies it against the Act, and delivers a prioritised gap analysis and roadmap — in about two weeks.

2

Govern — OASF

A control framework mapped directly to EU AI Act articles — turning obligations into policies, roles, and rules your organisation actually operates.

3

Protect — AYJIS

Runtime enforcement and human oversight where AI is actually used — inspecting, controlling, and logging every governed interaction as it happens.

4

Demonstrate — Evidence

Audit-ready records and control mappings that prove readiness to regulators, customers, and insurers — the evidence the Act requires.

See the full EU AI Act control mapping →

Know exactly where you stand on the EU AI Act.

Start with a fixed-price assessment and get a clear, prioritised readiness roadmap in weeks. You'll work directly with the team that built the platform and deployed it in production.

This page is a practical summary of the EU AI Act (Regulation (EU) 2024/1689) for general information and does not constitute legal advice. Obligations, timelines, and penalty ceilings are set out in the Regulation itself; organisations should confirm their specific obligations with qualified legal counsel.