EU AI ACT  •  Regulation (EU) 2024/1689

Are you ready for the EU AI Act?

The deadline is here. The average enterprise runs dozens of AI systems in production — almost none have a compliance framework. AEGIS engineers map your AI landscape, classify every system against the EU AI Act risk framework, and deliver an architectural readiness report backed by an audit-ready evidence chain.

Stage
Obligations apply in phased stages
Risk
Systems classified across 4 tiers
N/A
Governance & evidence mandated for high-risk
TBD
Custom gap-based timeline

Compliance is architectural, not bolted on.

The EU AI Act requires risk classification for every AI system, transparency for general-purpose AI models, human oversight, and tamper-proof audit trails. ISO 42001 requires an AI management system. NIST AI RMF requires governance across the full lifecycle. Documentation alone is not evidence — AEGIS produces the operational, runtime evidence regulators expect.

Risk Classification

Every AI system mapped against prohibited, high-risk, limited, and minimal-risk categories under the Act and its Annexes.

Evidence Generation

Every AI-generated action, decision, and output timestamped and hash-chained (SHA-256) into a tamper-proof evidence ledger.

Human Oversight

Granular human approval gates placed where regulators and your own risk tolerance require them — no gate bypassed.

Classifying your AI systems

The assessment classifies each of your AI systems and reveals what compliance demands of it. This is the foundation of your readiness report.

PROHIBITED

Unacceptable Risk

Social scoring and manipulative or exploitative practices. Banned outright — even partial deployment is a violation.

HIGH RISK

High-Risk Systems

Annex III use cases: critical infrastructure, education, employment, essential services, law enforcement, justice. Requires a full governance and evidence chain.

LIMITED / MINIMAL

Limited & Minimal Risk

Transparency obligations (chatbots must disclose they are AI) and lighter, voluntary codes of conduct.

High-risk is the urgent deadline. High-risk systems carry the strictest obligations — rigorous training data management, technical documentation, human oversight, risk management, and continuous logging and traceability. AEGIS uses a regulation mapping matrix covering the EU AI Act, ISO 42001, NIST AI RMF, and IEC 62443, scored across 12 dimensions.

From inventory to evidence

A structured engagement that begins with an architectural evaluation and ends with a deployable governance and evidence chain on your own infrastructure.

  1. 1

    Inventory & Mapping

    Discover every AI tool, model, endpoint, and use pattern across your organization. Build a complete, current AI landscape.

  2. 2

    Risk Classification

    Classify each system against the EU AI Act and Annex III, plus ISO 42001, NIST AI RMF, and your own compliance stack (GDPR, KVKK, PDPL, SOC 2).

  3. 3

    Gap Analysis

    Identify governance, oversight, documentation, and evidence gaps for every in-scope system across 12 scored dimensions.

  4. 4

    Readiness Report

    Receive an architectural readiness report: prioritized findings and a remediation roadmap with clear milestones.

  5. 5

    Deploy AEGIS

    Operate compliantly with runtime governance, human oversight gates, and a tamper-proof evidence chain on-premise, hybrid, air-gapped, or edge.

What you receive

AI Landscape Map

A complete inventory of every AI system in your organization — nothing undiscovered.

Risk Register

Every system classified with its obligations, one by one, against the Act.

Gap Analysis

Concrete governance and evidence gaps, prioritized by urgency and risk.

Readiness Report

An architectural readiness report with a remediation roadmap.

Evidence Chain

An audit-ready, tamper-proof evidence ledger — proof, not promises.

Deployment Plan

A phased path to compliant operation on your own infrastructure.

Ready to prove your readiness?

Start with an architecture assessment. AEGIS runs on your infrastructure, behind your policies, with your keys and your evidence — no vendor lock-in.

Request Architecture Assessment