EU AI Act: classification and gap analysis
Most teams start from the wrong question — «are we compliant?» The answer depends on facts you have not established yet: whether you are a provider or a deployer, what the system does in the eyes of the Regulation, and where it is placed on the market. We establish those first, then the obligations follow.

Most teams start from the wrong question — «are we compliant?» The answer depends on facts you have not established yet: whether you are a provider or a deployer, what the system does in the eyes of the Regulation, and where it is placed on the market. We establish those first, then the obligations follow.
Know exactly which rules apply to you
How the assessment runs
Four steps, two to three weeks, ending in a document your engineers and your lawyers can both act on.
01
Your role
Provider, deployer, importer or distributor. The same system carries different duties depending on which of these you are — and a company can be more than one at once.
02
Risk class
Prohibited practice, high-risk under Annex III, limited risk with transparency duties, or minimal. We record the reasoning, not just the conclusion: it is what you will be asked for.
03
Gap analysis
Applicable obligations against what exists today — documentation, data governance, logging, human oversight, post-market monitoring.
04
Plan and sequence
What has to change, in which order, and which items block a release rather than a review.
What is included
01
A written classification
With the reasoning and the article references, so the answer survives a change of team.
02
The obligations that apply
Only those. A list of everything in the Regulation is not an assessment.
03
Gap register
Each gap with an owner, a fix and a deadline tied to the applicable date.
04
Reviewed by a lawyer
The legal reading is signed off, not inferred from a blog post.