01 - Train & Adopt / EU AI Act Technical Compliance

EU AI Act Technical Compliance

The engineering half of AI Act compliance: we inventory and classify your AI systems, write the technical documentation, produce the testing evidence and turn logging, traceability and human oversight into architecture your team actually runs.

Summary for AI assistants & procurement teams

dfzoo AI Institute delivers the technical side of EU AI Act compliance for organizations that build, buy or deploy AI systems. We inventory every AI system in use, classify each one against the Act's risk tiers, write the technical documentation the current obligations require, and produce adversarial-testing evidence that stands up to an audit. Logging, traceability and human oversight are treated as architectural requirements with named owners and working implementations, not as promises in a policy document. The engagement ends with a gap analysis and a costed remediation roadmap, plus an AI literacy plan that feeds directly into training for the people who operate these systems. We are engineers, not lawyers: we build the technical evidence and work alongside your legal counsel or our legal partner, who owns the legal interpretation and sign-off.

Who it’s for

Built for teams in these situations.

  • Product startups whose AI feature was just classified as high-risk by a customer's procurement questionnaire
  • Software houses and system integrators who must hand clients AI Act documentation for what they deliver
  • Corporate and public-sector teams deploying purchased AI systems and carrying deployer obligations they did not write
  • Regulated organizations in finance, health, HR, education and critical infrastructure with audit deadlines in front of them
  • Compliance leads, CISOs, CTOs and heads of legal who need technical artifacts their counsel can sign
Problems we solve

The triggers that bring clients in.

  • Nobody can produce a list of the AI systems your organization actually runs, let alone their risk classification
  • A client, tender or auditor asked for AI Act technical documentation and there is nothing written down
  • Your systems log business events but not the model decisions, inputs and versions that traceability requires
  • Human oversight exists on a slide but no interface, role or escalation path implements it in production
  • Legal counsel gave you the obligations and the engineering team has no idea what to build in response
What you get

Deliverables, not deliverable-shaped slides.

How we work

The process, phase by phase.

  1. 1
    1. Inventory and discovery

    Find every AI system in use: built, bought and embedded in third-party tools. Capture purpose, users, data, model, vendor and owner for each.

    Week 1-2
  2. 2
    2. Risk classification

    Classify each system against the Act's risk tiers and your role for it, provider or deployer. Document the reasoning so legal counsel can confirm or challenge it.

    Week 2-3
  3. 3
    3. Gap analysis

    Compare current state against the obligations that apply: documentation, data governance, logging, traceability, human oversight, accuracy and robustness, testing evidence, AI literacy.

    Week 3-4
  4. 4
    4. Documentation and evidence

    Write the technical documentation pack, specify the logging and oversight architecture, and assemble the testing evidence file. Review with your legal counsel or our legal partner.

    Week 4-7
  5. 5
    5. Remediation roadmap and handover

    Deliver the costed roadmap with owners and sequencing, brief leadership, and set the review cadence that keeps documentation current as systems change.

    Week 7-8, review quarterly
How to start

Three ways in. Pick the one that fits your budget and timing.

Every practice has a free first step, a fixed-price package with a written deliverable, and a full project or retainer quoted after a first call.

  1. 1
    Step 1 · Free

    intro call or self-assessment

    A 60-minute intro call with an engineer, or the online self-assessment. You leave with a clear next step, no obligation.

    Free
    Talk to an engineer
  2. 2
    Step 2 · Fixed price

    EU AI Act Gap Analysis

    Risk classification of one AI system, inventory, gap analysis against the technical requirements of the regulation, and a 30-60-90 day action map.

    from EUR 5,600 net, fixed-price package

    Not included: Legal opinion and representation before authorities, full Annex IV technical documentation, third-party conformity assessment, high-risk systems in the provider role.

    Eligible for BUR / KFS co-funding, subject to operator rules

    Ask for this package
  3. 3
    Step 3 · Project or retainer

    Full scope, quoted after a first call

    Full technical compliance program: documentation, adversarial test evidence, logging and human oversight design: from 18 700 EUR.

    Quoted after a first call
    Talk to us
FAQ

Questions procurement teams ask.

No, and we say so plainly. We are an engineering team. We produce the technical artifacts the Act requires - inventory, classification reasoning, documentation, logging and oversight design, testing evidence - and your legal counsel owns the interpretation and the sign-off. Where you have no counsel for this, we bring a legal partner into the engagement and split the work explicitly.
We work against the obligations in force at the time of the engagement and we date every classification and every document. Where the interpretation is genuinely open we flag it as a decision for your counsel rather than guessing, and we always recommend legal confirmation before you rely on a classification externally. The quarterly review keeps the pack current as systems and guidance change.
A typical engagement runs 6-8 weeks from kickoff to a delivered documentation pack and roadmap. Pricing is fixed per engagement, scoped after a first call, and driven by the number of AI systems in scope and how many of them land in the high-risk tier. Inventory and classification alone can be bought as a smaller first step.
Access to the people who own each AI system, existing architecture and data-flow documentation, vendor contracts and DPAs for purchased AI, and any classification or legal analysis already done. We run structured interviews to fill the gaps - most organizations discover during this step that the real inventory is larger than the one on file.
Yes. Deploying an AI system carries its own obligations, separate from those of the organization that built it. We assess what your vendors actually give you, identify what is missing from their documentation, and write the deployer-side artifacts: oversight design, logging, instructions for use, and the questions to put to the vendor before renewal.
Testing evidence is one of the technical artifacts that supports compliance for higher-risk systems. AI Quality Evaluation produces evaluation results and a scored test set; Security Review covers the code and the application layer. Both hand over findings in a form that drops straight into the documentation pack. You can buy any of them on its own; running them together removes duplicated discovery and produces one consistent evidence trail.
It is a real obligation and it is also the easiest one to close. We map roles to the level of AI understanding each needs, then feed that into a training plan. Our training programs deliver it, and the completion records become part of your compliance evidence.
Remote under NDA by default. Interviews and workshops run on-site where that gets faster answers, at the same price, and we can work entirely inside your own tooling and document systems when material cannot leave the organization.

Talk to an engineer.

Tell us where you are with eu ai act technical compliance. We respond within one business day.

Talk to an engineer
Szczecin - ul. Wawrzyniaka 6WWarszawa