[AI Act compliance]

Bring your AI systems into line with the AI Act

We map your AI systems, classify them under the EU regulation and carry out their technical compliance work, with a partner law firm handling the legal side.
Transparency has applied since 2 August 2026, high risk from 2 December 2027
Up to €35m or 7% of worldwide turnover for breaches
40 AI engineers and a cybersecurity team, backed by a law firm
Two Galadrim team members in a workshop, listening closely to a presentation
800+ large corporates, mid-sized companies, SMEs and public bodies trust us with their tech and AI projects
[The four risk levels]

The AI Act classifies each of your systems, and your obligations follow from that

The regulation doesn't apply as a single block. It classifies each system by how it is used, and that level sets both the obligations and the deadline. It is the first question to settle, before any work begins.
Unacceptable risk – the use is banned

Unacceptable risk – the use is banned

Social scoring, exploiting a person's vulnerabilities, emotion recognition in the workplace or in education, individual predictive policing, untargeted scraping of facial images: these uses have been banned since 2 February 2025, and two further prohibitions come in on 2 December 2026. This is the only level exposed to the ceiling of €35m or 7% of worldwide turnover.

Applies to you if one of your tools scores people or infers their emotional state.

High risk – the most demanding regime

High risk – the most demanding regime

Recruitment and staff management, credit scoring, insurance pricing, education, biometrics, critical infrastructure, access to essential services: in these areas, Annex III requires risk management, data quality, technical documentation, logging, human oversight, robustness and cybersecurity. The Digital Omnibus has pushed these obligations back to 2 December 2027, and to 2 August 2028 for AI embedded in an already regulated product.

Applies to you if a decision that affects a person – hiring, credit, access to a service – relies on one of your systems.

Limited risk – transparency, required now

Limited risk – transparency, required now

A chatbot must say it is a machine, generated content must carry a machine-readable marking, and a deepfake must be disclosed. These Article 50 obligations have applied since 2 August 2026; generative systems already on the market by that date have until 2 December 2026 to add the marking. A breach exposes you to €15m or 3% of worldwide turnover.

Applies to you if you run a chatbot, a voice assistant or a content generator.

Minimal risk – no specific obligations, but two rules still apply

Minimal risk – no specific obligations, but two rules still apply

The vast majority of uses fall into this level: document search, writing assistance, internal classification. No specific obligations attach to it, but two rules apply across the board: AI literacy for your teams, which Article 4 has required you to support since February 2025, and GDPR as soon as personal data enters the pipeline.

Applies to you if your teams use ChatGPT, Claude, Copilot or Mistral in their day-to-day work.

The Galadrim team at work
The postponement of the high-risk obligations to December 2027 has been read as a reprieve. It is one for the timetable, not for the work. Mapping the systems, qualifying the roles and reworking the documentation takes several months, and nothing can start until someone knows what is actually running in the business. Organisations that get going now also deal with a blind spot that the AI Act merely brings to light: the AI tools teams have adopted without management knowing.
Benjamin DrighèsPartner and CTO, Data & AI
[How we work]

From mapping your systems to documented compliance

Six services, taken individually or one after another. The technical side is what we do; the legal side is handled with a partner law firm, with a single point of contact.
Mapping and compliance audit

Mapping and compliance audit

We map every AI system in use across your organisation, including those embedded in your suppliers' software and those your teams use outside the IT department's oversight. Each one is classified – its risk level, and your role as provider or deployer – and the gap analysis measures the distance between where you are and what the regulation expects.
Technical compliance

Technical compliance

We implement what the regulation requires of the system itself: decision logging, a human oversight checkpoint, robustness and cybersecurity measures, risk management, and hosting within the EU when the sensitivity of the data calls for it.
Documentation, registration and governance

Documentation, registration and governance

We produce the technical file, the declaration of conformity and the required registrations – including the reasoned justification to be filed in the EU database when an Annex III system is deemed not to be high-risk. And we set up the governance that keeps them up to date: roles, a committee, a review at every substantial modification.
Legal side, with our partner law firm

Legal side, with our partner law firm

Qualifying your role under the regulation, alignment with GDPR, clauses to pass on to your model providers, ownership of generated content, liability: our partner law firm handles these issues alongside our teams, so you don't have two providers to coordinate.
AI literacy for your teams

AI literacy for your teams

Article 4 requires you to help your employees build their AI skills, and this obligation has applied since February 2025. We design the formats to match: a leadership team workshop, role-specific learning paths, and technical training for your data and development teams.
Regulatory monitoring and ongoing compliance

Regulatory monitoring and ongoing compliance

The framework keeps moving: the Digital Omnibus reshuffled the deadlines in July 2026, and European harmonised standards are arriving in waves. We track these changes and adjust your roadmap and your systems, rather than leaving you to discover a gap.
[Our method]

Our method for bringing your AI systems into compliance

  • SCOPING
    Step 01

    Scoping and scope

    A workshop brings together IT, the DPO, legal and business teams to agree the audit scope, your own deadlines and the systems already known. We set out what the engagement must produce, and for which decision.
  • MAPPING
    Step 02

    Inventory of systems in use

    We map what is actually running: in-house developments, AI components embedded in your off-the-shelf software, calls to external models, and tools teams have adopted outside the IT department's oversight. Each entry is described by what it is really used for, not by its product name.
  • CLASSIFICATION
    Step 03

    Risk level and role

    For each system, we determine its level under the regulation and your role: provider, deployer, importer or distributor. This classification sets your obligations and your deadlines, and it shifts more often than people think – particularly when a product is built on a model's API.
  • ACTION PLAN
    Step 04

    Gap analysis and roadmap

    We produce a gap analysis for each system and a roadmap ordered by regulatory deadline and actual exposure: transparency first, since it already applies, then high risk, within the time the postponement to December 2027 allows.
  • IMPLEMENTATION
    Step 05

    Compliance work and deliverables

    We implement the agreed technical measures and produce the documentation. Each system comes out of this stage with its technical file, its records and its human oversight checkpoint in place.
  • ONGOING COMPLIANCE
    Step 06

    Governance and monitoring

    An AI governance committee takes over, with review procedures at every substantial modification, team training, and monitoring of a framework that keeps evolving.
01/06
[Why Galadrim?]

Why trust Galadrim with your AI Act compliance?

AI engineers, not just auditors

The AI Act is first and foremost a technical regulation: data quality, traceability, robustness, cybersecurity, human oversight. Our 40 AI engineers build these systems every day, and they fix what the audit finds rather than simply recording it.

Technical and legal under one point of contact

Our partner law firm handles classification, contracts and liability alongside our teams. You keep a single point of contact at Galadrim, and nobody has to referee between two providers.

Experience in constrained environments

Our teams put AI systems into production in healthcare, banking, insurance, industry and defence, where traceability and data location are constrained from the design stage. Our cybersecurity engineers work on the measures the regulation requires.

Compliance that doesn't freeze your roadmap

The roadmap is ordered by deadline and actual exposure, and runs in parallel with your development work. Technical measures are added to your existing systems: we don't ask you to switch them off.
[Our work]

AI systems delivered where constraints come before code

HealthcareUrgo Médical

Clinical decision support where every answer cites its source

Urgo Médical, a wound care specialist, wanted to give nurses decision support based on its proprietary body of knowledge. Galadrim built Med-ed GPT, a conversational agent integrated into the Healico app. It guides wound identification and care recommendations, and every answer links back to the reference it comes from. Healthcare decision support is one of the most tightly regulated areas under the Act, so source traceability and the clinician's place in the loop were built in from the design stage.
160 000nurses using it
300 000wounds documented
Urgo Médical Logo
Commercial propertyMercialys

Setting up a listed company's AI governance before deployment

Mercialys wanted to define its AI strategy without piling up experiments that went nowhere. We scoped the approach from start to finish: a steering committee, a roadmap prioritised by return on investment, then four agentic solutions deployed in six months – contract analysis, an internal chatbot, investment memo generation and automated monitoring. The committee we set up is exactly the structure the regulation expects of a deployer: a place where systems are recorded, decided on and reviewed.
180internal users
4AI agents up and running in 6 months
Mercialys Logo
DefenceDelia Strat · French Ministry of the Armed Forces

Running a language model on data that never leaves the building

Delia Strat builds software for defence organisations, including the French Ministry of the Armed Forces. It wanted to give intelligence analysts a way to get through large document collections quickly. Galadrim developed the algorithm that converts these documents into relational graphs, using a French open-source language model that can be self-hosted. It is the approach we take whenever data cannot leave a controlled environment.
80 %analysis time saved
7 billionparameters in the language model
Delia Strat · French Ministry of the Armed Forces Logo
[Our team]

The people who work on your compliance

An AI Act engagement draws on three disciplines: consulting, which maps and classifies; AI engineering, which implements what the regulation requires of the system; and infrastructure, when data cannot leave the EU.
Benjamin Drighès
Benjamin Drighès Partner and CTO, Data & AI
A former strategy adviser at the Autorité des marchés financiers, France's financial markets regulator, and an engineer from the Corps des Mines, the French state's senior engineering corps. He knows from the inside the kind of organisation where every decision must remain justifiable, and he has the final say on architecture choices for Galadrim's AI projects.
Pierre-Antoine Dornic
Pierre-Antoine Dornic Head of GenAI
He maps and prioritises AI use cases across departments in workshops with leadership teams – the same exercise a compliance inventory starts with.
Lucien Maillard
Lucien Maillard Principal AI Strategy Consultant
He scopes AI projects with client leadership, maps the systems actually in use with their teams, and assesses what can be built with the data available.
Quentin Massonnat
Quentin Massonnat AI Team Lead
He designs the architecture of our clients' AI systems, decision logging and human oversight checkpoint included, and oversees development all the way to go-live.
Surya Ambrose
Surya Ambrose Head of Engineering
Engineering Manager for four and a half years at a fintech regulated by the AMF, France's financial markets regulator, he shapes Galadrim's engineering practices: testing, delivery traceability and documentation – exactly what a technical file is built from.
Côme Lassarat
Côme Lassarat AI and Infrastructure Engineer
He builds data foundations and hosting architectures – connectors, warehouses, migrations – and deploys self-hosted models when data cannot leave the EU.

We map your AI systems, classify them under the AI Act and bring them into compliance.

Talk to an expert
[FAQ]

Frequently asked questions about the AI Act

Very probably. The regulation covers any provider, deployer, importer or distributor of an AI system in the EU. It also applies to organisations based outside the EU whenever the output is used there. If you run a CV screening tool, a scoring model, a customer chatbot, an internal copilot or a content generator, or if your teams use ChatGPT, Claude or Mistral in their work, you are a deployer under the regulation.
Prohibited practices and AI literacy have applied since 2 February 2025, the obligations for general-purpose AI models since 2 August 2025, and the Article 50 transparency obligations – disclosing that the other party is a machine, marking generated content, flagging deepfakes – since 2 August 2026. However, the Digital Omnibus, which came into force on 27 July 2026, has postponed the obligations for Annex III high-risk systems to 2 December 2027, and to 2 August 2028 for AI embedded in an already regulated product.
It changes the timetable, not the workload. A full inventory, classifying each system and reworking the documentation take several months, and both new dates are fixed: Parliament and the Council rejected the Commission's proposal to make them conditional on the publication of harmonised standards. The transparency obligations, meanwhile, apply right now.
A provider develops an AI system and places it on the market; a deployer uses it in a professional context without having developed it. A company that builds a product on a model's API switches from deployer to provider as soon as it markets a distinct system under its own name. This classification is central: it determines the scope of your obligations.
Annex III lists eight areas: biometrics; critical infrastructure; education and vocational training; employment and workforce management; access to essential services (credit, insurance, social benefits, emergency services); law enforcement; migration and border control; and the administration of justice and democratic processes. A system that falls under Annex III can be excluded from high risk, but the assessment must be reasoned and registered in the EU database.
For an organisation that identifies two to five high-risk systems, allow four to seven months from scoping to documented compliance. It takes longer when there is a lot of use outside the IT department's oversight, or when no map of systems exists. We adapt the pace to your deadlines.
You have a single point of contact at Galadrim, who runs the engagement. Our partner law firm handles role classification, contracts with your suppliers and customers, alignment with GDPR, intellectual property in generated content and liability, working closely with our technical teams. You don't have two providers to orchestrate.
Three caps, each set at whichever of two amounts is higher: €35m or 7% of worldwide turnover for prohibited practices, €15m or 3% for other breaches – transparency included – and €7.5m or 1% for supplying incorrect information to the authorities. Lower caps apply to SMEs and smaller mid-sized companies.
The AI Act doesn't require it as such: data location is governed by GDPR and, where relevant, your sector's regulations. In practice, the question comes up as soon as an external model processes personal or sensitive data. Depending on the case, we anonymise before the call, host within the EU, or deploy a self-hosted open-source model – which is what we did for the French Ministry of the Armed Forces.
[Contact us]

Let's bring your project to life together

We work with every kind of client, across every industry. Whether you are an entrepreneur or lead a large organisation, we put together a team that fits your need.

More than 800 companies have trusted us to build their web, mobile and AI products

Your request

We'll get back to you within the hour.