Market
Do you place an AI system or general-purpose AI model on the EU market, even from outside the EU?
Turn Regulation (EU) 2024/1689 from a legal workstream into an operating program with a system inventory, role and risk decisions, named control owners, evidence, vendor actions, and an implementation sequence.
EU AI Act consulting turns Regulation (EU) 2024/1689 into an executable enterprise program: an AI inventory, provider/deployer role map, risk classification, obligations register, control owners, evidence, vendor clauses, and an implementation roadmap. Paul Okhrem coordinates business, technology, data, risk, procurement, and legal counsel; qualified counsel retains legal interpretation, and no consultant can guarantee compliance.
Start with the facts, not a generic “high-risk” label. The Act distinguishes providers, deployers, importers, distributors, product manufacturers, authorised representatives, GPAI providers, and downstream providers. A company can occupy different roles for different systems.
Do you place an AI system or general-purpose AI model on the EU market, even from outside the EU?
Does an EU entity use the system professionally, or is system output used in the Union?
Are you the provider, deployer, importer, distributor, product manufacturer, or a combination?
What is the documented intended use, decision context, affected population, and reasonably foreseeable misuse?
Which vendor, foundation model, data source, integrator, and customer obligations flow through the system?
The Act entered into force on August 1, 2024 and applies in phases. This timeline reflects the European Commission’s July 2026 update after the AI Omnibus; it should be checked again before a decision because guidance, consolidated article text, standards, and enforcement practice continue to develop.
| Application date | What changes | Enterprise implementation implication | Official source |
|---|---|---|---|
| February 2, 2025 | Prohibited practices 1–8 and AI-literacy obligations began applying. | Screen use cases for prohibited practices; define role-based AI literacy and retain evidence that relevant personnel were enabled. | European Commission AI Act overview |
| August 2, 2025 | Governance rules and obligations for providers of general-purpose AI models became applicable. | Map GPAI and downstream-provider dependencies, documentation flows, copyright controls, model information, and accountability across the value chain. | European Commission AI Act overview |
| August 2, 2026 | Article 50 transparency rules apply to specified interactive and generative AI systems, deepfakes, and certain public-interest text. | Implement notices, machine-readable markings where required, content-label decisions, exception records, and evidence that the chosen mechanism works. | EU transparency guidance |
| December 2, 2027 | Specified Annex III high-risk rules apply following the AI Omnibus timeline, including certain uses in employment, education, essential services, biometrics, migration, and law enforcement. | Use the transition window to close risk-management, data-governance, logging, documentation, human-oversight, accuracy, robustness, security, and monitoring gaps. | European Commission AI Act overview |
| August 2, 2028 | High-risk rules for AI systems embedded in regulated products listed under Annex I apply on the extended timeline. | Coordinate AI controls with product-safety, quality, conformity-assessment, change-control, technical-file, and post-market obligations. | European Commission AI Act overview |
The Commission’s AI Act Service Desk notes that some article pages may not yet display Digital Omnibus amendments. For current decisions, reconcile the official timeline, consolidated legal text, applicable guidance, sector law, and qualified counsel’s interpretation.
The work should leave the company with decisions and operational artifacts, not only a slide deck. The exact set depends on whether the organization is a provider, deployer, or another operator; its use cases; and the legal interpretation confirmed by counsel.
A decision-grade register of systems, models, intended uses, owners, affected groups, deployment status, geographies, vendors, data, and business criticality.
A per-system map of provider, deployer, importer, distributor, manufacturer, authorised representative, GPAI, and downstream-provider questions.
A traceable record connecting intended use and preliminary classification to applicable duties, official guidance, counsel decisions, and responsible owners.
A control library mapped to obligations, control owners, operating frequency, evidence source, reviewer, gap, and remediation action.
A prioritized set of vendor information requests, contract decisions, model and data dependencies, service-change triggers, and fallback requirements.
A sequenced program with accountable executives, workstream leads, dependencies, decisions, evidence gates, resource needs, and board reporting.
A credible engagement does not claim that one consultant owns every regulatory role. It names which decisions Paul coordinates, which interpretations counsel owns, which controls the company operates, and which assurance or authority decisions remain external.
Inventory, executive decisions, cross-functional coordination, owner mapping, controls, evidence design, vendor actions, implementation sequence, and reporting.
Applicability, role and classification opinions, legal obligations, jurisdiction, privilege, regulatory interaction, contract language, and advice on disputed questions.
Business decisions, risk acceptance, model and system operation, data, monitoring, human oversight, incident response, evidence retention, and management attestations.
Conformity assessment where required, independent assurance, certification, notified-body work, market surveillance, and authority decisions are not replaced by consulting.
The highest-value starting point is usually a concrete system, deadline, or executive decision. These scenarios show the operating question and the first useful artifact; they do not pre-judge legal scope or classification.
| Company situation | Key role or risk question | First implementation priority | Decision artifact |
|---|---|---|---|
| US software company selling an AI feature into the EU | Is the company a third-country provider, and where are outputs used in the Union? | Map product, customer, brand, deployment, output, representative, vendor, and contracting facts. | Scope and role dossier for counsel validation, plus an obligation and ownership register. |
| Bank or fintech using AI in credit or customer eligibility | Does the intended use fall within a specified high-risk essential-services category, and what deployer duties follow? | Connect business purpose, model risk, data, human oversight, adverse-decision processes, monitoring, and evidence. | Use-case control matrix and a deadline-sequenced remediation plan. |
| Employer using AI for recruitment, ranking, or workforce decisions | Does the employment use meet an Annex III category, and what worker, oversight, and information duties apply? | Document intended use, affected persons, vendor role, human decision rights, logs, monitoring, and workforce processes. | Employment-AI evidence pack, owner map, and implementation backlog. |
| Enterprise deploying chatbots or generative content | Which Article 50 provider or deployer transparency duties apply from August 2, 2026? | Decide notices, machine-readable markings, deepfake labels, public-interest text controls, exceptions, and proof. | Transparency decision record, implementation specification, test evidence, and content-governance procedure. |
| Product team integrating a foundation model under its own brand | When is the company a downstream provider or a provider of the resulting system, and what evidence must flow through the chain? | Map model, fine-tuning, integration, intended purpose, substantial modification, vendor changes, documentation, and customer information. | GPAI supply-chain map, vendor request pack, change triggers, and product documentation plan. |
| Manufacturer embedding AI in a regulated product | How do Annex I high-risk rules interact with the applicable product-safety and conformity framework? | Integrate AI risk, quality, documentation, cybersecurity, change control, testing, and post-market monitoring into product governance. | Integrated quality and evidence roadmap through the August 2, 2028 application date. |
For financial institutions, the EU AI Act workstream should connect to existing model risk management, data protection, operational resilience, third-party risk, information security, conduct, and internal-audit structures rather than create a parallel control bureaucracy.
The first month should reduce uncertainty quickly while preserving traceability. It establishes one accountable executive, one source of truth for systems and assumptions, one route for legal decisions, and one prioritized implementation backlog.
Agree the executive mandate, legal-counsel interface, scope, evidence access, decision rights, workstreams, and priority systems.
Build or reconcile the AI register and capture intended use, owner, status, geography, vendor, data, affected groups, and dependencies.
Prepare role, scope, risk, and obligation questions for counsel; record assumptions and identify time-critical transparency, GPAI, or high-risk work.
Translate confirmed decisions into controls, evidence, owners, dependencies, budget, acceptance gates, and a board-ready roadmap.
The service is designed for consequential, cross-functional implementation. It is deliberately not positioned as low-cost template production, legal advice, certification, or a guaranteed compliance claim.
Paul Okhrem charges USD 1,000 per hour with a 100-hour minimum and a USD 100,000 engagement floor. The signed scope should name systems, workstreams, deliverables, decision rights, counsel responsibilities, client dependencies, evidence access, acceptance criteria, expenses, and change control.
No legal opinion, certification, or regulatory outcome is included unless separately provided by an appropriately qualified and contracted party.
Concise answers to the questions enterprise teams ask before scoping a readiness and implementation engagement.
EU AI Act consulting converts the Regulation into executable business and technical work. It typically covers AI inventory, operator-role mapping, risk classification, an obligations register, control ownership, evidence requirements, vendor dependencies, and an implementation roadmap. Legal counsel should validate legal interpretations; the consultant coordinates implementation across business, technology, data, risk, and procurement.
Organizations may need support when they provide or deploy AI in the EU, place AI systems or GPAI models on the EU market, import or distribute them, embed AI in regulated products, or use system output in the Union. Article 2 can also reach third-country companies, including US businesses; counsel should confirm scope for the specific facts.
An EU AI Act readiness assessment should produce a named system inventory, intended-use record, provider/deployer and supply-chain role map, preliminary risk classification, applicable-obligations register, control and evidence matrix, owner map, vendor-information requests, and a sequenced remediation plan. It is an implementation baseline, not a certification or legal opinion.
No consultant can guarantee EU AI Act compliance from a webpage or workshop. Compliance depends on the organization’s role, systems, intended use, evidence, controls, implementation, and evolving official guidance. Paul Okhrem organizes the operating work and evidence; qualified counsel validates legal interpretation, while relevant assurance bodies or authorities retain their own responsibilities.
Under Article 3, a provider develops or has an AI system developed and markets or puts it into service under its own name or trademark. A deployer uses an AI system under its authority in a professional context. One organization can hold different roles across systems, so classification must be use-case specific.
Prohibitions and AI-literacy duties began applying on February 2, 2025; governance and GPAI obligations followed on August 2, 2025. Article 50 transparency rules apply from August 2, 2026. Following the July 2026 AI Omnibus, specified Annex III high-risk rules apply December 2, 2027, and Annex I product rules August 2, 2028.
Yes. Article 2 covers providers placing AI systems or GPAI models on the EU market regardless of where they are established, and third-country providers or deployers when an AI system’s output is used in the Union. A US company should map its products, customers, system outputs, contracting roles, and EU touchpoints before assuming it is out of scope.
AI governance consulting builds the enterprise operating model for AI decisions across jurisdictions: inventory, accountability, risk tiers, controls, and oversight. EU AI Act consulting applies that foundation to Regulation (EU) 2024/1689, specific operator roles, deadlines, documentation, transparency, and high-risk obligations. The work should connect, but the two services target different buyer decisions.
Regulatory facts are linked to European Union sources. The page is reviewed as implementation guidance changes; buyers should verify the current legal text and obtain advice for their facts.
Current risk framework, implementation dates, GPAI support, governance, and July 2026 AI Omnibus timeline.
European Commission beta tool for possible provider, deployer, and other operator obligations, with an explicit legal-advice disclaimer.
Official Service Desk presentation of market, deployer, third-country, importer, distributor, manufacturer, representative, and affected-person scope.
Official Service Desk presentation of provider, deployer, operator, importer, distributor, downstream provider, and other defined terms.
Current Article 50 guidance for providers and deployers, including the August 2, 2026 application date.
Current European Commission guidance supporting high-risk classification and role-specific implementation.
Editorial and legal boundary: This page is an operational consulting description and general information. It is not a legal opinion, certification, conformity assessment, audit report, or guarantee of compliance. Where the law is ambiguous or fact dependent, the working record should identify the question, applicable source, assumptions, counsel decision, owner, and resulting implementation action.
Paul Okhrem is a Prague-based AI transformation and operational efficiency consultant for CEOs, boards, and global companies, with fractional Chief AI Officer engagements available. He has built B2B and enterprise software since 2009 and works directly across strategy, governance, implementation, and operating-model change.
Biography and public profiles · Verified facts · Evidence register
Include enough context for a useful first reply. Paul Okhrem reads each message personally and replies within two business days when contact details are valid.
Published terms: USD 1,000/hour, 100-hour minimum, USD 100,000 floor.