EU AI Act Compliance Consulting
Classify your AI systems, close the gaps and produce the technical documentation the EU AI Act requires, led by an engineer rather than a lawyer.
- Typical duration
- 5–10 weeks
- Investment
- from €42,000
- Team
- One AI architect plus a governance specialist
Short answer
Rubra helps organisations classify their AI systems under the EU AI Act, identify obligations by risk tier, and produce the technical evidence the regulation requires: risk management records, data governance documentation, accuracy and robustness testing, logging, and human oversight design. I cover the engineering half; I work alongside your counsel on the legal half.
Last reviewed
The EU AI Act is the first comprehensive AI regulation anywhere, and it is already shaping procurement across Europe, including for companies that are not themselves in scope, because their European customers now ask.
Most of the obligations are engineering obligations. That is the part I do.
The classification problem comes first
Almost every conversation starts in the wrong place: is my AI high-risk? The question cannot be answered about a technology, only about a use case. The same retrieval system is minimal risk when it helps staff find a policy document and high-risk when it screens candidates for a role.
I inventory every AI system you operate, classify each use case against the Act’s tiers, and then write down why. That last step is the one that matters. A classification you cannot justify is worse than no classification, because it looks like a decision was made and then cannot be defended.
Then the obligations, article by article
For each system I map exactly which obligations attach and what evidence satisfies them:
- Article 9. A risk management system that operates across the lifecycle
- Article 10. Data governance: provenance, representativeness, bias examination
- Article 11 and Annex IV. Technical documentation
- Article 12. Automatic logging with sufficient traceability
- Article 13. Transparency and instructions for use
- Article 14. Human oversight that is effective, not nominal
- Article 15. Accuracy, robustness and cybersecurity, with declared metrics
For limited-risk systems the burden is much lighter: disclosure that the user is interacting with an AI system, and marking synthetic content. I will tell you plainly when that is all you need.
The overlap nobody mentions
If you have already built a serious evaluation harness, you are most of the way to Article 15 evidence. If you have proper tracing, Article 12 is largely handled. Good engineering practice and AI Act compliance converge to a surprising degree, which means the work is rarely wasted even if your classification later turns out to be lighter than feared.
What I do not do
I am not your lawyers, and I will not give you a legal opinion on classification. I give you a technical classification with documented reasoning, the engineering evidence, and a gap analysis with real effort estimates. Your counsel owns the legal position and I work alongside them. When the Act’s harmonised standards and Commission guidance move, I will tell you what changes for your systems.
What you get
- AI system inventory with risk classification and reasoning
- Obligation mapping per system, article by article
- Gap analysis with remediation effort estimates
- Technical documentation package (Annex IV structure)
- Accuracy, robustness and cybersecurity test evidence
- Human oversight and logging design
Outcomes
- A defensible classification for every AI system you operate
- Technical documentation that maps to specific articles
- Engineering changes scoped and costed, not just identified
Frequently asked questions
Does the EU AI Act apply to us if we are not in the EU?
It applies if you place an AI system on the EU market, put one into service in the EU, or if the output of your system is used in the EU, regardless of where your company is established. That last limb catches a large number of US and Canadian companies serving European customers. The practical test is whether European users or European decisions are downstream of your system, not where your servers or your head office sit.
Is our RAG chatbot a high-risk AI system?
Usually not, but the answer depends on what it decides rather than what it is. High-risk classification under Annex III follows the use case: employment and worker management, access to education, essential private and public services including creditworthiness, law enforcement, migration, and critical infrastructure. An internal knowledge assistant for staff is normally minimal or limited risk, carrying mainly transparency obligations. The same technology screening job applicants is squarely high-risk. I classify per use case, and document the reasoning, because the reasoning is what you have to defend.
What are the deadlines?
The Act entered into force in August 2024 and applies in stages. Prohibited practices and AI literacy obligations applied from February 2025, and general-purpose AI model obligations from August 2025. The main high-risk obligations under Annex III follow from August 2026, with high-risk systems embedded in regulated products under Annex I running to August 2027. Note that the Commission has proposed adjustments to parts of this timeline, so confirm current dates with your counsel before planning around them.
Why hire engineers for compliance work rather than a law firm?
Because most of what the Act requires is engineering evidence, not legal opinion. Article 15 wants accuracy and robustness testing. Article 12 wants automatic logging. Article 10 wants documented data governance. Article 14 wants human oversight designed into the system. A law firm will correctly tell you these obligations exist; someone has to instrument the system to satisfy them. I do that part and work alongside your counsel, who should own the legal interpretation.
Get a straight answer on your AI roadmap
A 30-minute call with the engineer who would do the work, not a salesperson. You will get an honest read on what is worth building, what is not, and roughly what it costs.
No NDA needed to talk. EU and UK hours in full, with afternoons overlapping US Eastern and Central.