Services

EU AI Act Compliance Consulting for SaaS, AI Vendors and US Companies Selling Into the EU

Regulation (EU) 2024/1689 is now law. Prohibited practices apply since February 2025, GPAI obligations since August 2025, and the full high-risk regime lands 2 August 2026. We classify your AI systems against Annex III and Annex I, write the Annex IV / Annex XI technical documentation, stand up the Article 9 risk management and Article 17 quality management systems, and run post-market monitoring per Article 72 — integrated with your existing GDPR, ISO 27001 and SOC 2 controls instead of duplicated alongside them. Engineering-grade evidence, lawyer-readable memos, board-ready risk register. Every engagement is scoped and budgeted before work starts — no enterprise markup.

EU AI Act compliance consulting for SaaS and AI product teams

The EU AI Act has extraterritorial reach — if your AI output is used in the EU, you are in scope regardless of where your company is incorporated. Fines reach up to 7 percent of global turnover for prohibited practices and up to 3 percent for high-risk violations. But most SaaS products are not high-risk; the value is a defensible classification memo, a clean documentation pack, and an evidence library that does double duty as your ISO 42001 and SOC 2 inputs. We have done this for SaaS vendors, AI-native startups, and US companies entering the EU market — the deliverable is operational, not theatrical.

What we deliver

Risk classification memo

System-by-system mapping against Annex III (eight high-risk areas), Annex I (regulated products), Article 5 prohibitions, and Article 50 limited-risk obligations. Written with article-level citations so your counsel can sign off without re-doing the work.

Annex IV technical documentation

The full pack for high-risk systems: system description, intended purpose, risk management, data governance, human oversight design, accuracy/robustness/cybersecurity metrics, logging, post-market monitoring plan. Versioned Markdown in your repo, not a one-time PDF.

GPAI model documentation

If you fine-tune a GPAI model you may inherit provider duties under Article 25(1)(c). We deliver the Annex XI pack — model card, training data summary, energy reporting, and the Article 53(1)(c) copyright policy aligned to the EU AI Office template.

Risk management system

Article 9 RMS as a living system, not a binder. Hazard identification, residual risk evaluation, mitigation tracking, and integration with your ISO 27001 register so the same control evidences both regimes.

Post-market monitoring

Article 72 PMM plan, Article 73 serious-incident reporting workflow, drift and accuracy dashboards, and the playbook for notifying competent authorities within the statutory 15 days when needed.

Deployer-facing artefacts

Instructions for use per Article 13, transparency notices per Article 50, deployer FIA (fundamental rights impact assessment) template per Article 27 — ready to ship to enterprise customers asking AI Act questions in their procurement RFPs.

What we cover

Annex III Classification Annex I Mapping Article 5 Prohibitions Article 50 Transparency GPAI Article 53 Article 9 Risk Mgmt Article 10 Data Governance Article 14 Human Oversight Article 15 Accuracy/Cyber Article 17 QMS Annex IV Tech Doc Annex XI GPAI Doc Article 27 FRIA Article 72 PMM Article 73 Incidents CE Marking Support Notified Body Liaison ISO/IEC 42001 Alignment ISO 27001 Integration GDPR Article 35 DPIA NIS2 / DORA Crossmap CRA Crossmap CEN-CENELEC JTC 21 EU AI Office Liaison

How an engagement runs

  1. 01

    Scope & classify

    Week 1: inventory every AI system and GPAI model in your stack, classify against Annex III/I, identify prohibited practices, and write the classification memo. Most clients discover that two-thirds of their AI is limited-risk or out of scope — defensibly.

  2. 02

    Gap analysis

    Week 2: gap each in-scope system against the relevant articles, score each gap by deadline and effort, and produce a remediation roadmap aligned with the 2 February 2025, 2 August 2025, 2 August 2026 and 2 August 2027 milestones.

  3. 03

    Build the pack

    Weeks 3–8: stand up the Article 9 RMS and Article 17 QMS, write the Annex IV (or Annex XI for GPAI) documentation in your repo, implement logging per Article 12, and ship the Article 13 instructions for use and Article 50 transparency notices.

  4. 04

    Operate

    From month three: quarterly evidence refresh, regulatory monitoring (EU AI Office guidance, harmonised standards as they publish, national competent authorities), Article 73 incident drills, and an annual third-party-ready audit dry run.

Industries we work in

Where AI systems land in Annex III or Annex I, classification and documentation carry the most weight. These are the product domains we know at engineering level.

FinTech

Credit scoring and life/health insurance pricing are named Annex III high-risk areas. We classify the models, document the Article 10 data governance, and align the evidence with the GDPR DPIA you already run.

FinTech engineering →

HealthTech

AI as a safety component in a medical device falls under Annex I, with high-risk duties applying from 2 August 2027. We map the AI Act pack onto your MDR/IVDR technical file so one evidence set serves both.

HealthTech engineering →

Logistics & Mobility

AI in critical infrastructure and safety-relevant control is high-risk under Annex III/I. We stand up the Article 9 risk management and Article 14 human-oversight design your operations and safety teams can own.

Logistics engineering →

EdTech

Education is a named Annex III area: AI that determines admission, scores exams, or runs proctoring is high-risk. We classify the models, document the Article 10 data governance and Article 14 human oversight, and write the transparency notices students and institutions are entitled to.

EdTech engineering →

GovTech & Public Sector

Essential public services, migration and border control, and law-enforcement use are among the strictest Annex III categories, and public deployers carry an Article 27 fundamental-rights impact assessment. We deliver the classification, the FRIA, and the audit trail procurement and oversight bodies expect.

GovTech engineering →

LegalTech

AI intended to assist judicial authorities in researching and interpreting the law falls under Annex III administration of justice. We separate genuinely high-risk features from ordinary document automation, then document only what is in scope so the classification survives counsel review.

LegalTech engineering →

Engagement packages

Readiness Assessment

Two weeks, fixed scope. Classification memo, gap analysis against the applicable articles, remediation roadmap mapped to AI Act deadlines, and a 60-minute executive briefing with the founder and counsel. Fixed scope, budget agreed up front.

Documentation Pack

Six to eight weeks. Full Annex IV or Annex XI technical documentation, Article 9 RMS, Article 10 data governance policy, Article 72 post-market monitoring plan, Article 13 instructions for use, Article 50 transparency notices, and the public model card. Fixed scope, budget agreed up front.

Compliance Operations

Ongoing monthly retainer. Quarterly evidence refresh, regulatory monitoring, Article 73 incident reporting support, annual audit dry run, deployer/customer RFP answer pack maintenance. Monthly retainer, transparent scope.

Conformity assessment with a notified body (Article 43, route via Annex VII) is quoted separately when the system requires third-party assessment. Three-month minimum on Compliance Operations, month-to-month thereafter with 30 days notice. NDA, DPA and IP assignment signed before kickoff.

Why founders and counsel pick YuSMP for AI Act work

GDPR-aligned · ISO 27001 ready · SOC 2 Type II in progress · HIPAA-capable · ISO/IEC 42001-aligned

Engineers, not policy consultants

We read the model code, the data pipeline, and the eval suite before we write a memo. Our deliverables hold up because they reflect what the system actually does, not what a slide deck claims it does.

One evidence library, many regimes

AI Act, GDPR, ISO 27001, ISO 42001, SOC 2, NIS2, CRA — the underlying controls overlap. We build a single versioned evidence library that discharges duties across all of them instead of running parallel binders.

Inside your operating cadence

DPA and NDA signed before kickoff, repo access, attendance in your engineering staff meeting and your board legal update. The documentation lives in your stack and is owned by your team after handover.

For conformity assessment we work directly with EU notified bodies (Annex VII route 2) and prepare the submission to the standard the body expects — not the standard a generalist consultant assumes.

What clients say

Remote document signing is a legal minefield. YuSMP built both the mobile signing flow and the Symfony CRM in a single engagement, handled KYC onboarding, and delivered API docs that our compliance team cleared in days.
David Mercer, CEO, Signatory ProView case →
A loan decision engine that takes ten times less time to approve does not happen by accident. YuSMP built the scoring pipeline, integration with credit bureaus, and a back-office that our underwriters actually enjoy using. Approval turnaround went from two days to under four hours.
Gregory Lawson, CTO, LoanFlowView case →

Frequently asked questions

When does the EU AI Act actually apply to my product, and what are the deadlines I should plan around?

The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in tranches. Prohibited AI practices (Article 5) became applicable 2 February 2025. Obligations for general-purpose AI models (Chapter V) apply from 2 August 2025, including transparency, technical documentation, and copyright policy. Most obligations for high-risk AI systems (Chapter III) apply from 2 August 2026. Obligations for high-risk AI systems embedded in regulated products under Annex I (medical devices, machinery, toys, in-vitro diagnostics, etc.) apply from 2 August 2027. If you sell into the EU, EEA, or your output is used in the EU, you are in scope even if your company is incorporated in the US — Article 2 has extraterritorial reach.

How do I know whether my AI system is high-risk, limited-risk, or out of scope?

We classify against Annex III (eight high-risk areas: biometrics, critical infrastructure, education, employment, essential services including credit scoring and life/health insurance pricing, law enforcement, migration/asylum/border control, administration of justice and democratic processes) and Annex I (AI as a safety component in regulated products). Limited-risk systems under Article 50 (chatbots, emotion recognition, biometric categorisation, deepfakes) only have transparency duties. Minimal-risk systems have voluntary codes. We deliver a written classification memo with article citations and a risk register the board can read. About 60 percent of SaaS products we classify end up limited-risk and only need transparency notices and watermarking — that decision alone saves six-figure compliance cost.

We build on OpenAI, Anthropic, or Mistral — does the EU AI Act make us a GPAI provider?

No, you remain a downstream provider or deployer, not a GPAI provider. GPAI provider obligations (Article 53) apply to the model creator — OpenAI, Anthropic, Google DeepMind, Mistral. But you inherit downstream duties: maintain instructions for use, monitor for systemic risks, and if you fine-tune a GPAI model on your data, you can become the provider of a derived GPAI model under Article 25(1)(c). We map the upstream/downstream boundary, document it in your contract with the model provider, and write the fine-tuning policy that keeps you out of provider-class obligations unless you genuinely want to be a provider.

What does a complete EU AI Act technical documentation pack contain?

Annex IV defines it for high-risk systems: a general description of the system and intended purpose; a detailed description of components and development process; monitoring, functioning and control; risk management system per Article 9; training, validation and test data per Article 10; technical means for human oversight per Article 14; accuracy, robustness and cybersecurity metrics per Article 15; the quality management system per Article 17; logs and the post-market monitoring plan per Article 72. For GPAI models, Annex XI applies — model card, training data summary, energy consumption, and copyright compliance policy. We deliver the full pack as versioned Markdown in your repo, plus a public-facing model card and a deployer-facing instruction sheet.

How does the EU AI Act overlap with GDPR, the Data Act, and ISO 42001 — and how do we avoid duplicating work?

Heavily, and the trick is one integrated controls map. The Article 9 risk management system can reuse your ISO 27001 risk register. The Article 10 data governance requirements align tightly with GDPR Articles 5, 25 and 32 — same DPIA framework with extra fairness and bias documentation. ISO/IEC 42001:2023 AI management system covers about 70 percent of Article 17 quality management requirements; if you are pursuing ISO 42001 certification we sequence it to discharge AI Act duties at the same time. The Data Act, NIS2, and the Cyber Resilience Act add adjacent obligations that share evidence — we deliver a unified evidence library, not five duplicate ones.

What does pricing look like, and what is in versus out of scope?

Three packages, each scoped and budgeted before any work starts, with no enterprise markup. Readiness Assessment is a fixed-scope two-week engagement: classification memo, gap analysis against the relevant articles, remediation roadmap, and an executive briefing. Documentation Pack is a fixed-scope six-to-eight-week engagement: full Annex IV or Annex XI documentation, risk management system, data governance policy, post-market monitoring plan, instructions for use, and the public model card. Ongoing Compliance Operations is a monthly retainer with transparent scope: quarterly evidence refresh, regulatory monitoring (EU AI Office, national competent authorities, harmonised standards from CEN-CENELEC JTC 21), incident reporting support per Article 73, and one annual third-party-ready audit dry run. Larger phases can run as fixed-scope-per-phase or transparent time-and-materials. Conformity assessment with a notified body is quoted separately when required.

What are the penalties for non-compliance, and who enforces the EU AI Act?

Fines are tiered under Article 99. Prohibited AI practices (Article 5) carry the top penalty: up to €35 million or 7 percent of total worldwide annual turnover, whichever is higher. Most high-risk and GPAI obligation breaches are up to €15 million or 3 percent of turnover. Supplying incorrect, incomplete, or misleading information to authorities is up to €7.5 million or 1 percent. Enforcement is split: the EU AI Office supervises general-purpose AI models directly, while national market surveillance authorities in each Member State enforce high-risk and prohibited-practice rules for products sold in their territory. SMEs and startups face proportionally capped fines, but the reputational and procurement fallout usually outweighs the fine itself — enterprise buyers now ask for AI Act evidence in RFPs.

Do we need a notified body, or can we self-assess conformity?

It depends on the system. For most stand-alone high-risk AI systems under Annex III, conformity assessment is based on internal control (Annex VI) — you self-assess, sign the EU declaration of conformity, and affix the CE marking, provided you have the full Annex IV documentation and quality management system in place. A notified body (third-party assessment via Annex VII) is required mainly for certain biometric systems and for AI that is a safety component of a product already subject to third-party assessment under Annex I sectoral law (e.g. many medical devices). We tell you up front which route applies, prepare the technical documentation to the standard the assessor expects, and liaise with the notified body only when it is genuinely required — so you neither skip a mandatory assessment nor pay for one you do not need.

We are a US company with no EU entity — do we need an EU authorised representative?

If you are a provider of a high-risk AI system or a GPAI model and you place it on the EU market without an establishment in the Union, Article 22 requires you to appoint, by written mandate, an authorised representative established in the EU before making the system available. That representative holds the technical documentation, cooperates with authorities, and is the local point of contact. Limited-risk and minimal-risk systems do not trigger this obligation. We help you determine whether you cross the threshold, and if so we structure the mandate and the documentation handover so the representative can actually discharge the role rather than being a nameplate.

What is the difference between a provider, deployer, importer, and distributor under the AI Act?

The obligations follow the role, defined in Article 3. A provider develops an AI system or GPAI model and places it on the market under its own name — it carries the heaviest duties (classification, documentation, QMS, conformity assessment). A deployer uses an AI system under its own authority in a professional context — it owes transparency to affected people, human oversight, and, for public bodies and some others, an Article 27 FRIA. An importer places a third-country provider’s system on the EU market and must verify the provider did its part. A distributor makes it available down the chain and checks the CE marking and documentation are present. A single company is often several roles at once. We map exactly which role each of your products puts you in, because misidentifying it is the most common and most expensive mistake we see.

How long does it take to get a high-risk system ready before the 2 August 2026 deadline?

For a single high-risk system with cooperative engineering access, plan on six to eight weeks for the full documentation pack once classification is confirmed — that covers the Annex IV documentation, the Article 9 risk management system, Article 10 data governance, Article 14 human-oversight design, and the Article 72 post-market monitoring plan. Classification and gap analysis take the first two weeks. If a notified body assessment is required, add lead time for their queue, which is why we start that conversation early. Multiple systems or a fine-tuned GPAI model extend the timeline. The practical takeaway: to be comfortably ready for 2 August 2026 you want to start classification no later than the first quarter of 2026, because remediation — not paperwork — is usually the long pole.

Need an AI Act classification memo before your next board meeting?

Book a readiness call

Get a proposal

Share a few details and a senior consultant will reply within one business day.