EU AI Act compliance for companies
We map your AI use against the EU AI Act, classify it by risk, put the controls and the registry in place, and leave you with documentation that stands up to an audit. Advisory throughout, built on how your teams actually use AI.
The EU AI Act is the first horizontal law on artificial intelligence, and it applies by risk rather than by company size. If your people use AI at work, at least one obligation already applies to you: since 2 February 2025, Article 4 requires providers and deployers to ensure their staff have a sufficient level of AI literacy. Higher-risk uses, such as AI in recruitment or employment decisions, carry heavier duties around documentation, human oversight, and record-keeping.
You do not need a legal department to get this right. What the Act rewards is order: a clear inventory of where AI is used, an honest classification of the risk, a short list of controls, and a way to keep them current.
What the service covers
- AI inventory. We find where AI already touches your work, including the tools teams adopted on their own.
- Risk classification. Each use is placed against the Act's categories, from minimal risk to high-risk under Annex III and the prohibited uses.
- Governance controls. Human-oversight rules, acceptable-use policy, data and confidentiality boundaries, and who signs off on what.
- AI registry. A living record of your AI systems, their purpose, owner, risk level, and status.
- Article 4 AI literacy. A training plan so your staff meet the literacy obligation, delivered through the TVL Academy program if you want it.
- Audit-ready documentation. The evidence you can show to a customer, an auditor, or a regulator.
How the engagement runs
- DiscoveryWe interview the teams and list every place AI is used, sanctioned or not.
- ClassificationWe rate each use against the Act and flag anything high-risk or prohibited.
- Controls and registryWe draft the policy, the oversight rules, and the AI registry.
- Literacy planWe set the Article 4 training so your people know what they can and cannot do.
- HandoverYou get the documentation and a short roadmap for keeping it current.
EU AI Act readiness checklist
- You have a written inventory of every AI system and tool in use across the company.
- Each system is classified by risk: prohibited, high-risk, limited, or minimal.
- Any high-risk use under Annex III (such as recruitment or employment decisions) is identified and has human oversight.
- You have an acceptable-use policy that sets data, confidentiality, and disclosure rules.
- Staff who use AI have documented AI literacy training, satisfying Article 4.
- An AI registry records each system's purpose, owner, risk level, and review date.
- You can produce this evidence on request from a customer, auditor, or regulator.
Who this is for
Mid-market and corporate teams in Romania and the EU that already use AI and want to do it correctly, and companies that have to answer AI questions in procurement, security reviews, or customer due diligence. If you sell to larger organizations, the registry and the documentation are often what a security or procurement review asks for before it signs off.
Frequently asked questions
Does the EU AI Act apply to my company?
If your company develops, sells, or uses AI systems and operates in the EU, or your output reaches people in the EU, the Act applies. Most obligations scale with risk, so the first step is to classify what you use.
What is the Article 4 AI literacy obligation?
Article 4 requires providers and deployers of AI systems to ensure their staff have a sufficient level of AI literacy. It has applied since 2 February 2025 and covers any company whose people use AI at work, not only high-risk cases.
What counts as a high-risk AI system?
Annex III lists high-risk uses, including AI used in recruitment and employment decisions, access to essential services, credit scoring, and similar areas. High-risk systems carry the heaviest obligations, so classifying your use correctly matters.
Do you implement the changes in our systems?
Our work is advisory. We tell you what to classify, document, and control, and your own team applies the settings. We never ask for system access or credentials, so you keep control of your data.
What do we get at the end?
A classified inventory of your AI use, an AI registry, documented governance controls and human-oversight rules, an AI literacy plan for Article 4, and audit-ready documentation you can show to a customer, an auditor, or a regulator.
Find out where you stand with the EU AI Act
Book 30 minutes. We will look at where AI is used in your company, which obligations apply, and what the first step should be.
Book 30 minutes