Map les systèmes d’IA par niveau de risque.
Identify the AI systems developed or used by the organisation and classify them according to the risk categories defined by the Regulation.
AI Act compliance is not a one-off exercise.
Map AI systems by risk level, integrate requirements into existing compliance frameworks and prepare for audits: build a sustainable compliance roadmap, deadline by deadline.
Talk to an expert →Aevum Advisory helps organisations comply with the European artificial intelligence framework and digital regulation. We structure your obligations, align your practices and secure your decisions at every stage.
AI Act compliance is not a one-off exercise.
Map AI systems by risk level, integrate requirements into existing compliance frameworks and prepare for audits: build a sustainable compliance roadmap, deadline by deadline.
Talk to an expert →Aevum Advisory helps organisations comply with the European artificial intelligence framework and digital regulation. We structure your obligations, align your practices and secure your decisions at every stage.
The European Artificial Intelligence Act does not take effect all at once. Its requirements are phased in through successive waves, according to the risk level of the systems concerned. The amending Digital Omnibus Regulation, which entered into force on 27 July 2026, extended the timetable for high-risk systems without affecting obligations already in force.
In practice, prohibited AI practices and AI literacy obligations have applied since February 2025; providers of general-purpose AI models have been subject to mandatory compliance since August 2025; and the Regulation’s general application, including transparency requirements, has applied since 2 August 2026.
The Digital Omnibus, however, postpones requirements for stand-alone high-risk systems—recruitment, credit, education and critical infrastructure—from 2 August 2026 to 2 December 2027, and for high-risk systems embedded in already regulated products, such as medical devices, from 2 August 2027 to 2 August 2028.
For an organisation, the challenge is not understanding the text once, but following this differentiated timetable over time and aligning it with obligations already in place: GDPR, CSRD and ESG criteria.
Each system, risk level and position in the value chain calls for different obligations and evidence.
Guillaume Lambert has followed the development of the European Artificial Intelligence Regulation since its adoption and has published several analyses of the AI Act and the Tech Sovereignty Package around it.
This work pays particular attention to the relationship between the European text and the technological sovereignty issues around it: who controls the AI systems used in Europe, which infrastructure they rely on, and how the regulatory framework shapes this question of control.
Identify the AI systems developed or used by the organisation and classify them according to the risk categories defined by the Regulation.
Integrate the new obligations into existing compliance frameworks: GDPR for data, and CSRD and ESG criteria for non-financial reporting.
Track the deadlines for each risk level: AI literacy and prohibited practices since February 2025, GPAI obligations since August 2025, general transparency since August 2026, stand-alone high-risk systems in December 2027 and high-risk systems embedded in regulated products in August 2028.
Document classification choices and measures taken so that they can be justified during an inspection.
The same Regulation distinguishes the responsibilities of those who design or market a system from those who deploy it in their own operations.
Support organisations that develop or market AI systems in assessing their risk level and preparing the documentation required by the Regulation.
ProvidersSupport organisations that use high-risk AI systems in their own processes, with their specific monitoring and traceability obligations.
DeployersThe pathway links system classification, existing compliance frameworks, measures to deploy and evidence to maintain.
Map les systèmes d’IA de l’organisation et les classer selon les niveaux de risque du règlement.
Build the compliance pathway and align it with existing GDPR, CSRD and ESG frameworks.
Deploy the required compliance measures: technical documentation, data governance and human oversight mechanisms.
Audit compliance against the actual implementation timetable and adjust the framework as the Digital Omnibus clarifies the text.
Sustainable compliance remains understandable, documented and adaptable as systems and the regulatory framework evolve.
Talk to an expert →AI compliance starts with a clear view of the situation. Which systems are being used? What decisions do they influence? Who controls them?
We connect these answers to the applicable requirements so that every team knows what to do and can explain its decisions.
Understand how the system is used, verify its data, organise human oversight and retain the necessary evidence.
We examine the real situation rather than relying on the technical description alone. The same tool may require very different controls depending on the decision it influences.
Data that is understood and monitored makes the system’s results easier to explain. Poorly controlled data weakens both performance and compliance.
Human oversight must provide genuine authority. We define who decides, what information they receive and how they can intervene before an error has consequences.
Evidence is produced as the work progresses. It is not reconstructed in a rush before an audit and remains available when the system or the rules change.
The assessment does more than classify AI systems. It clearly identifies who must act, what must be corrected or controlled and how to demonstrate that the measure works.
Bring together systems that are developed, purchased, embedded in software or used without approval.
Scope establishedAssess the use, the people affected and the possible consequences rather than classifying a tool in the abstract.
Risk explainedGive every measure an owner, a deadline and a verifiable outcome.
Action assignedReassess the system when its model, data or use changes.
Sustained controlGuillaume Lambert analyses the European framework and translates its requirements into organisational compliance assessments. This work connects every obligation to one central question: who controls the AI systems in use, the infrastructure they rely on and the decisions they influence?
Our assessment gives every team a clear next action. It establishes the level of compliance, the gaps to address and the evidence that must be maintained over time.
Identify the systems, their uses and the people accountable for them.
You know what is in use.Set decision rules, controls and required evidence.
You know what to do.Connect these rules to existing tools, processes and responsibilities.
Teams can act.Test the framework and adjust it when the system or its use changes.
Control remains demonstrable.Regulation will continue to evolve. Your ability to understand, decide and demonstrate must remain stable.
Talk to an expert →