Skip to main content

EU AI Act: compliance by design

For high-risk AI systems in finance, healthcare, government and critical infrastructure, the EU AI Act is already an operational reality. The regulation introduces concrete technical requirements that need to be built into your architecture from day one, not added afterwards. We translate those requirements into working auditable systems. 

  • Risk classification: we help determine where your system sits, from prohibited AI to minimal risk

  • Technical documentation: structured as an architecture component, not a standalone compliance exercise

  • Audit trails and observability: built into Infrastructure as Code and traceable for regulators

  • Human oversight: mechanisms that work reliably in production, not just on paper

  • Compliance by design: requirements become part of the architecture, not a layer added afterwards

Our EU AI Act compliance services

AI system risk classification

The EU AI Act uses four risk levels: prohibited AI, high risk, limited risk and minimal risk. Correctly classifying your system determines which operational and documentation requirements apply. We help you make that classification based on the regulation, delegated acts and your specific use case and sector.

Conformity assessment and technical documentation

High-risk AI systems require a conformity assessment and extensive technical documentation before deployment. We structure that documentation as an architecture artefact: integrated in the build process, not an afterthought.

Audit trails and traceability

The regulation requires high-risk AI systems to log decisions, input data and system behaviour in a way that is verifiable by regulators. We implement audit trails via Infrastructure as Code: every decision traceable and every model change documented.

Bias detection and fairness evaluation

AI systems making decisions that affect people (in access to services, credit decisions, employment or healthcare) must demonstrably be free from unacceptable bias. We build the measurement methods and evaluation infrastructure that make bias and fairness visible.

Human oversight mechanisms

The EU AI Act requires high-risk AI systems to enable human oversight, and that oversight must be more than a button you can turn off. We design the interfaces, escalation routes and override mechanisms that make human oversight meaningful.

Data governance for training data

Quality, representativeness and provenance of training data are mandatory documentation requirements for high-risk systems. We help you establish the data governance structure that fulfils those requirements and scales as your AI landscape grows.

Let's discuss your EU AI Act compliance needs

Joeri Timmermans

Joeri Timmermans

Business director Technology​

Our approach to EU AI Act compliance

The EU AI Act describes obligations in legal terms. But implementing them is a technical discipline — one that starts at the first design decision and runs through to after go-live.

From regulation article to architecture requirement

A technical leader needs to know what the regulation means in code. What logging is required, in what format, how long retained? How do you demonstrate human oversight to a regulator? We translate legal requirements into concrete architecture requirements, so engineering teams know exactly what to build.

Governance that scales with your AI portfolio

One high-risk AI system is manageable operationally. Ten AI systems across different risk classes, each with its own documentation requirements, oversight mechanisms and evaluation cycles, is a different challenge. We help you establish a governance structure that fits your current AI portfolio and scales as it expands.

Compliance embedded in delivery, not added afterwards

In AI programmes for Etex, SBB and Worldline, compliance-relevant elements are already part of the architecture: guardrails, observability via standardised monitoring, auditable IaC deployment, security at the AI-system boundary. We don't bolt a compliance layer on top of an existing system: we start with compliance as an architecture principle.

Why work with iO?

Technical depth, not just legal mapping

Law firms advise on the EU AI Act. Technical firms build AI systems. We do both, and that's exactly what the regulation requires. Langfuse observability, automated bias detection, auditable decision logs: these aren't extra features, that's how we build by default.

Relevant high-risk sector experience

The EU AI Act places the toughest requirements on high-risk systems in finance, healthcare, government and critical infrastructure. We work across all those sectors, from Worldline (payment provider) to public sector organisations and healthcare providers. That experience is relevant when you determine your risk classification and which regulator your documentation must satisfy.

Bridging the gap between technical leadership and the board

The EU AI Act has become a boardroom topic, but the technical requirements sit on the CTO's desk. We help you build the architecture and make the business case: what's the risk of non-compliance, what does compliant architecture cost, and how do you position AI Act compliance as an advantage rather than overhead.

Compliance already embedded into our delivery practice

In AI programmes for Etex and Worldline, compliance-relevant elements are already part of the architecture: guardrails, observability via standardised monitoring, auditable IaC deployment, security at the AI-system boundary. We don't bolt a compliance layer on top of an existing system: we start with compliance as an architecture principle.

Want to assess whether your AI system complies with the EU AI Act?