Expertise

AI compliance and digital regulation

AI Act compliance is not a one-off exercise.

Map AI systems by risk level, integrate requirements into existing compliance frameworks and prepare for audits: build a sustainable compliance roadmap, deadline by deadline.

Talk to an expert

Aevum Advisory helps organisations comply with the European artificial intelligence framework and digital regulation. We structure your obligations, align your practices and secure your decisions at every stage.

AI ActDigital Omnibus

AI, GDPR, CSRD and ESG: one governance framework

An AI system never falls under a single regulation. Its use simultaneously involves data governance, sustainability disclosure and control of social, environmental and ethical impacts.

GDPRLawful data use, purpose limitation, minimisation, individual rights and automated decisions.
CSRDImpact traceability and integration of digital uses into sustainability reporting.
ESGEnergy, bias, inclusion, governance, accountability and control over technology providers.
The key business issue: build consistent evidence that can be reused across frameworks instead of multiplying isolated compliance programmes.
Expertise

AI compliance and digital regulation

AI Act compliance is not a one-off exercise.

Map AI systems by risk level, integrate requirements into existing compliance frameworks and prepare for audits: build a sustainable compliance roadmap, deadline by deadline.

Talk to an expert

Aevum Advisory helps organisations comply with the European artificial intelligence framework and digital regulation. We structure your obligations, align your practices and secure your decisions at every stage.

AI ActDigital Omnibus

AI, GDPR, CSRD and ESG: one governance framework

An AI system never falls under a single regulation. Its use simultaneously involves data governance, sustainability disclosure and control of social, environmental and ethical impacts.

GDPRLawful data use, purpose limitation, minimisation, individual rights and automated decisions.
CSRDImpact traceability and integration of digital uses into sustainability reporting.
ESGEnergy, bias, inclusion, governance, accountability and control over technology providers.
The key business issue: build consistent evidence that can be reused across frameworks instead of multiplying isolated compliance programmes.
Understand

The AI Act takes effect in stages, not all at once.

The European Artificial Intelligence Act does not take effect all at once. Its requirements are phased in through successive waves, according to the risk level of the systems concerned. The amending Digital Omnibus Regulation, which entered into force on 27 July 2026, extended the timetable for high-risk systems without affecting obligations already in force.

In practice, prohibited AI practices and AI literacy obligations have applied since February 2025; providers of general-purpose AI models have been subject to mandatory compliance since August 2025; and the Regulation’s general application, including transparency requirements, has applied since 2 August 2026.

The Digital Omnibus, however, postpones requirements for stand-alone high-risk systems—recruitment, credit, education and critical infrastructure—from 2 August 2026 to 2 December 2027, and for high-risk systems embedded in already regulated products, such as medical devices, from 2 August 2027 to 2 August 2028.

For an organisation, the challenge is not understanding the text once, but following this differentiated timetable over time and aligning it with obligations already in place: GDPR, CSRD and ESG criteria.

The principle

Build a compliance pathway that follows the Regulation’s actual timetable.

Each system, risk level and position in the value chain calls for different obligations and evidence.

Explore the options
Experience

Tracking and analysing the AI Act since its adoption.

Guillaume Lambert has followed the development of the European Artificial Intelligence Regulation since its adoption and has published several analyses of the AI Act and the Tech Sovereignty Package around it.

This work pays particular attention to the relationship between the European text and the technological sovereignty issues around it: who controls the AI systems used in Europe, which infrastructure they rely on, and how the regulatory framework shapes this question of control.

01 — MAP

Map les systèmes d’IA par niveau de risque.

Identify the AI systems developed or used by the organisation and classify them according to the risk categories defined by the Regulation.

Why this mattersIt determines which obligations apply, who is accountable for them and which evidence must be produced for each system.
What needs to be visibleSystems developed in-house, purchased, embedded in software or used by a team without formal approval.
Decision exampleDistinguish an internal writing assistant from a system used for recruitment, credit or access to an essential service.
02 — ALIGN

Align l’AI Act avec les dispositifs existants.

Integrate the new obligations into existing compliance frameworks: GDPR for data, and CSRD and ESG criteria for non-financial reporting.

Why this mattersThe same AI system simultaneously involves data governance, impact management and organisational accountability.
What it avoidsParallel compliance programmes that request the same information repeatedly, produce conflicting decisions and scatter the evidence.
Decision exampleReuse the GDPR analysis of data and automated decisions in the AI Act file, then link significant impacts to CSRD and ESG reporting.
03 — ANTICIPATE

Anticipate le calendrier d’entrée en application.

Track the deadlines for each risk level: AI literacy and prohibited practices since February 2025, GPAI obligations since August 2025, general transparency since August 2026, stand-alone high-risk systems in December 2027 and high-risk systems embedded in regulated products in August 2028.

Why this mattersObligations do not arise at the same time or for the same systems: the pathway must therefore organise priorities, budgets and responsibilities over time.
What it avoidsFinding out too late that a system already in use requires documentation, human oversight or a technical change that is difficult to add afterwards.
Decision exampleAddress uses already in scope immediately, while starting early enough on the more substantial work required for high-risk systems.
04 — DOCUMENT

Prepare for audits de conformité.

Document classification choices and measures taken so that they can be justified during an inspection.

Why this mattersCompliance relies not only on measures taken, but on the ability to explain decisions and demonstrate their implementation.
What to retainThe system classification, responsibilities, versions, tests, incidents, corrective actions and human approvals.
Decision exampleLink every requirement to evidence maintained during operation, rather than rebuilding the file urgently before an inspection.
Operating contexts

Different obligations according to your place in the AI value chain.

The same Regulation distinguishes the responsibilities of those who design or market a system from those who deploy it in their own operations.

01

AI system providers: obligations at source.

Support organisations that develop or market AI systems in assessing their risk level and preparing the documentation required by the Regulation.

Providers
02

User organisations: obligations as deployers.

Support organisations that use high-risk AI systems in their own processes, with their specific monitoring and traceability obligations.

Deployers
Support

From mapping to audit: our four-step approach.

The pathway links system classification, existing compliance frameworks, measures to deploy and evidence to maintain.

1

Assess

Map les systèmes d’IA de l’organisation et les classer selon les niveaux de risque du règlement.

2

Define

Build the compliance pathway and align it with existing GDPR, CSRD and ESG frameworks.

3

Embed

Deploy the required compliance measures: technical documentation, data governance and human oversight mechanisms.

4

Verify

Audit compliance against the actual implementation timetable and adjust the framework as the Digital Omnibus clarifies the text.

Sustainable compliance remains understandable, documented and adaptable as systems and the regulatory framework evolve.

Talk to an expert
AI compliance assessment

Make the compliance of every AI system clear and manageable.

AI compliance starts with a clear view of the situation. Which systems are being used? What decisions do they influence? Who controls them?

We connect these answers to the applicable requirements so that every team knows what to do and can explain its decisions.

The four assessment areas

An AI compliance assessment must answer four questions.

Understand how the system is used, verify its data, organise human oversight and retain the necessary evidence.

Explore the assessment
01 — UNDERSTAND THE USE

What does the system do, and who could be affected by an error?

We examine the real situation rather than relying on the technical description alone. The same tool may require very different controls depending on the decision it influences.

The resulting decisionDescribe the action, recommendation or generated content in plain terms.
People affectedIdentify those whose rights, work or access to a service may be affected.
Acceptable limitsDefine when the system must not be used and when a person must take back control.
02 — UNDERSTAND THE DATA

Can the organisation explain where the data comes from and why it is suitable?

Data that is understood and monitored makes the system’s results easier to explain. Poorly controlled data weakens both performance and compliance.

OriginDocument sources, usage rights and collection conditions.
QualityIdentify errors, gaps and insufficiently represented populations.
Change over timeMonitor changes that may degrade results over time.
03 — RETAIN CONTROL

Can a person understand, challenge and stop the system?

Human oversight must provide genuine authority. We define who decides, what information they receive and how they can intervene before an error has consequences.

Clear accountabilityName the business and technical owners of each system.
Useful informationPresent results and their limitations in language people can understand.
Effective actionProvide for correction, suspension and shutdown when required.
04 — BE ABLE TO DEMONSTRATE

Can the organisation show what was decided, tested and monitored?

Evidence is produced as the work progresses. It is not reconstructed in a rush before an audit and remains available when the system or the rules change.

DecisionsRetain design, validation and deployment decisions.
Checks performedRecord versions, tests, incidents and corrective actions.
Further reviewsReassess the system after a significant change to the model, data or use.
Assessment findings

Every compliance finding leads to a concrete decision.

The assessment does more than classify AI systems. It clearly identifies who must act, what must be corrected or controlled and how to demonstrate that the measure works.

01 / IDENTIFY

Identify what is actually in use.

Bring together systems that are developed, purchased, embedded in software or used without approval.

Scope established
02 / ASSESS

Understand risk in context.

Assess the use, the people affected and the possible consequences rather than classifying a tool in the abstract.

Risk explained
03 / ACT

Choose controls that make a real difference.

Give every measure an owner, a deadline and a verifiable outcome.

Action assigned
04 / MONITOR

Maintain control during operation.

Reassess the system when its model, data or use changes.

Sustained control
Experience

Assess AI compliance without losing sight of technological control.

Guillaume Lambert analyses the European framework and translates its requirements into organisational compliance assessments. This work connects every obligation to one central question: who controls the AI systems in use, the infrastructure they rely on and the decisions they influence?

Conducting the AI compliance assessment

A clear path from system inventory to audit.

Our assessment gives every team a clear next action. It establishes the level of compliance, the gaps to address and the evidence that must be maintained over time.

1

Assess

Identify the systems, their uses and the people accountable for them.

You know what is in use.
2

Define

Set decision rules, controls and required evidence.

You know what to do.
3

Embed

Connect these rules to existing tools, processes and responsibilities.

Teams can act.
4

Verify

Test the framework and adjust it when the system or its use changes.

Control remains demonstrable.

Regulation will continue to evolve. Your ability to understand, decide and demonstrate must remain stable.

Talk to an expert