Regulatory implementation for global enterprises

EU AI Act consulting for enterprise implementation.

Turn Regulation (EU) 2024/1689 from a legal workstream into an operating program with a system inventory, role and risk decisions, named control owners, evidence, vendor actions, and an implementation sequence.

Direct senior delivery by Paul Okhrem Global scope, including US companies serving the EU Legal-counsel compatible, not a substitute for counsel

EU AI Act consulting turns Regulation (EU) 2024/1689 into an executable enterprise program: an AI inventory, provider/deployer role map, risk classification, obligations register, control owners, evidence, vendor clauses, and an implementation roadmap. Paul Okhrem coordinates business, technology, data, risk, procurement, and legal counsel; qualified counsel retains legal interpretation, and no consultant can guarantee compliance.

Applicability triage

Does the EU AI Act apply to your company?

Start with the facts, not a generic “high-risk” label. The Act distinguishes providers, deployers, importers, distributors, product manufacturers, authorised representatives, GPAI providers, and downstream providers. A company can occupy different roles for different systems.

01

Market

Do you place an AI system or general-purpose AI model on the EU market, even from outside the EU?

02

Use

Does an EU entity use the system professionally, or is system output used in the Union?

03

Role

Are you the provider, deployer, importer, distributor, product manufacturer, or a combination?

04

Purpose

What is the documented intended use, decision context, affected population, and reasonably foreseeable misuse?

05

Supply chain

Which vendor, foundation model, data source, integrator, and customer obligations flow through the system?

Use the official checker as a starting point, not a final legal conclusion. The European Commission’s Official EU AI Act Compliance Checker is in beta and states that its results are informational, not legal advice. A defensible program retains the facts, assumptions, role decisions, counsel input, and resulting implementation actions.
Current implementation dates

Which EU AI Act requirements apply, and when?

The Act entered into force on August 1, 2024 and applies in phases. This timeline reflects the European Commission’s July 2026 update after the AI Omnibus; it should be checked again before a decision because guidance, consolidated article text, standards, and enforcement practice continue to develop.

EU AI Act implementation timeline, reviewed July 29, 2026
Application date What changes Enterprise implementation implication Official source
February 2, 2025 Prohibited practices 1–8 and AI-literacy obligations began applying. Screen use cases for prohibited practices; define role-based AI literacy and retain evidence that relevant personnel were enabled. European Commission AI Act overview
August 2, 2025 Governance rules and obligations for providers of general-purpose AI models became applicable. Map GPAI and downstream-provider dependencies, documentation flows, copyright controls, model information, and accountability across the value chain. European Commission AI Act overview
August 2, 2026 Article 50 transparency rules apply to specified interactive and generative AI systems, deepfakes, and certain public-interest text. Implement notices, machine-readable markings where required, content-label decisions, exception records, and evidence that the chosen mechanism works. EU transparency guidance
December 2, 2027 Specified Annex III high-risk rules apply following the AI Omnibus timeline, including certain uses in employment, education, essential services, biometrics, migration, and law enforcement. Use the transition window to close risk-management, data-governance, logging, documentation, human-oversight, accuracy, robustness, security, and monitoring gaps. European Commission AI Act overview
August 2, 2028 High-risk rules for AI systems embedded in regulated products listed under Annex I apply on the extended timeline. Coordinate AI controls with product-safety, quality, conformity-assessment, change-control, technical-file, and post-market obligations. European Commission AI Act overview
Implementation scope

What does EU AI Act consulting include?

The work should leave the company with decisions and operational artifacts, not only a slide deck. The exact set depends on whether the organization is a provider, deployer, or another operator; its use cases; and the legal interpretation confirmed by counsel.

WORKSTREAM 01

AI system inventory

A decision-grade register of systems, models, intended uses, owners, affected groups, deployment status, geographies, vendors, data, and business criticality.

  • System and model taxonomy
  • Named business and technical owners
  • Evidence confidence and missing fields
WORKSTREAM 02

Role and scope map

A per-system map of provider, deployer, importer, distributor, manufacturer, authorised representative, GPAI, and downstream-provider questions.

  • Third-country and EU touchpoints
  • Assumptions requiring legal confirmation
  • Substantial-modification triggers
WORKSTREAM 03

Risk and obligations register

A traceable record connecting intended use and preliminary classification to applicable duties, official guidance, counsel decisions, and responsible owners.

  • Prohibited-practice screen
  • High-risk and transparency analysis
  • GPAI and sector dependencies
WORKSTREAM 04

Control and evidence matrix

A control library mapped to obligations, control owners, operating frequency, evidence source, reviewer, gap, and remediation action.

  • Human oversight and escalation
  • Logging, monitoring, and incidents
  • Documentation and change records
WORKSTREAM 05

Vendor and GPAI evidence pack

A prioritized set of vendor information requests, contract decisions, model and data dependencies, service-change triggers, and fallback requirements.

  • Documentation and audit rights
  • Incident and material-change notice
  • Exit, portability, and continuity
WORKSTREAM 06

Implementation roadmap

A sequenced program with accountable executives, workstream leads, dependencies, decisions, evidence gates, resource needs, and board reporting.

  • Now, next, and deadline-driven actions
  • Acceptance and stop criteria
  • Residual-risk and counsel sign-offs
Clear accountability

How EU AI Act consulting differs from legal advice, assurance, and implementation.

A credible engagement does not claim that one consultant owns every regulatory role. It names which decisions Paul coordinates, which interpretations counsel owns, which controls the company operates, and which assurance or authority decisions remain external.

Paul Okhrem

Operating program

Inventory, executive decisions, cross-functional coordination, owner mapping, controls, evidence design, vendor actions, implementation sequence, and reporting.

Qualified counsel

Legal interpretation

Applicability, role and classification opinions, legal obligations, jurisdiction, privilege, regulatory interaction, contract language, and advice on disputed questions.

Client owners

Control operation

Business decisions, risk acceptance, model and system operation, data, monitoring, human oversight, incident response, evidence retention, and management attestations.

External bodies

Assurance and enforcement

Conformity assessment where required, independent assurance, certification, notified-body work, market surveillance, and authority decisions are not replaced by consulting.

Buyer scenarios

Where EU AI Act implementation work becomes urgent.

The highest-value starting point is usually a concrete system, deadline, or executive decision. These scenarios show the operating question and the first useful artifact; they do not pre-judge legal scope or classification.

EU AI Act consulting scenarios for global companies
Company situation Key role or risk question First implementation priority Decision artifact
US software company selling an AI feature into the EU Is the company a third-country provider, and where are outputs used in the Union? Map product, customer, brand, deployment, output, representative, vendor, and contracting facts. Scope and role dossier for counsel validation, plus an obligation and ownership register.
Bank or fintech using AI in credit or customer eligibility Does the intended use fall within a specified high-risk essential-services category, and what deployer duties follow? Connect business purpose, model risk, data, human oversight, adverse-decision processes, monitoring, and evidence. Use-case control matrix and a deadline-sequenced remediation plan.
Employer using AI for recruitment, ranking, or workforce decisions Does the employment use meet an Annex III category, and what worker, oversight, and information duties apply? Document intended use, affected persons, vendor role, human decision rights, logs, monitoring, and workforce processes. Employment-AI evidence pack, owner map, and implementation backlog.
Enterprise deploying chatbots or generative content Which Article 50 provider or deployer transparency duties apply from August 2, 2026? Decide notices, machine-readable markings, deepfake labels, public-interest text controls, exceptions, and proof. Transparency decision record, implementation specification, test evidence, and content-governance procedure.
Product team integrating a foundation model under its own brand When is the company a downstream provider or a provider of the resulting system, and what evidence must flow through the chain? Map model, fine-tuning, integration, intended purpose, substantial modification, vendor changes, documentation, and customer information. GPAI supply-chain map, vendor request pack, change triggers, and product documentation plan.
Manufacturer embedding AI in a regulated product How do Annex I high-risk rules interact with the applicable product-safety and conformity framework? Integrate AI risk, quality, documentation, cybersecurity, change control, testing, and post-market monitoring into product governance. Integrated quality and evidence roadmap through the August 2, 2028 application date.

For financial institutions, the EU AI Act workstream should connect to existing model risk management, data protection, operational resilience, third-party risk, information security, conduct, and internal-audit structures rather than create a parallel control bureaucracy.

First 30 days

What happens in the first month of an EU AI Act engagement?

The first month should reduce uncertainty quickly while preserving traceability. It establishes one accountable executive, one source of truth for systems and assumptions, one route for legal decisions, and one prioritized implementation backlog.

Mobilize

Agree the executive mandate, legal-counsel interface, scope, evidence access, decision rights, workstreams, and priority systems.

  • Executive sponsor and steering group
  • Known deadlines and decision log
  • Evidence repository and access rules

Inventory

Build or reconcile the AI register and capture intended use, owner, status, geography, vendor, data, affected groups, and dependencies.

  • System interviews and evidence review
  • Shadow-AI discovery process
  • Confidence and missing-data labels

Classify

Prepare role, scope, risk, and obligation questions for counsel; record assumptions and identify time-critical transparency, GPAI, or high-risk work.

  • Provider/deployer mapping
  • Risk and obligation hypotheses
  • Vendor evidence requests

Sequence

Translate confirmed decisions into controls, evidence, owners, dependencies, budget, acceptance gates, and a board-ready roadmap.

  • Prioritized remediation backlog
  • Named control and evidence owners
  • Executive decision memo
Engagement fit

When should you hire Paul Okhrem for EU AI Act implementation?

The service is designed for consequential, cross-functional implementation. It is deliberately not positioned as low-cost template production, legal advice, certification, or a guaranteed compliance claim.

Strong fit

  • A global company has multiple AI systems, vendors, markets, or business units.
  • The board needs one operating program across legal, risk, business, data, technology, procurement, and audit.
  • A US or other non-EU company needs to map EU market and output exposure.
  • A bank, fintech, insurer, software company, manufacturer, or regulated enterprise needs transformation and compliance work to connect.
  • Qualified legal counsel is engaged or can be engaged for interpretation.

Not the right fit

  • You need only a legal opinion, regulator representation, or privileged legal advice.
  • You need a notified body, conformity assessment, certification, or independent assurance opinion.
  • You want a one-day workshop to produce a “compliant” badge or guaranteed outcome.
  • The company cannot name an executive sponsor, provide system evidence, or assign implementation owners.
  • The budget is below the published USD 100,000 engagement floor.
Published commercial terms

Price the operating mandate, not a generic compliance package.

Paul Okhrem charges USD 1,000 per hour with a 100-hour minimum and a USD 100,000 engagement floor. The signed scope should name systems, workstreams, deliverables, decision rights, counsel responsibilities, client dependencies, evidence access, acceptance criteria, expenses, and change control.

$100K minimum engagement

No legal opinion, certification, or regulatory outcome is included unless separately provided by an appropriately qualified and contracted party.

Review complete pricing and fit boundaries →

Frequently asked questions

EU AI Act consulting FAQs.

Concise answers to the questions enterprise teams ask before scoping a readiness and implementation engagement.

What is EU AI Act consulting?

EU AI Act consulting converts the Regulation into executable business and technical work. It typically covers AI inventory, operator-role mapping, risk classification, an obligations register, control ownership, evidence requirements, vendor dependencies, and an implementation roadmap. Legal counsel should validate legal interpretations; the consultant coordinates implementation across business, technology, data, risk, and procurement.

Who needs an EU AI Act consultant?

Organizations may need support when they provide or deploy AI in the EU, place AI systems or GPAI models on the EU market, import or distribute them, embed AI in regulated products, or use system output in the Union. Article 2 can also reach third-country companies, including US businesses; counsel should confirm scope for the specific facts.

What does an EU AI Act readiness assessment include?

An EU AI Act readiness assessment should produce a named system inventory, intended-use record, provider/deployer and supply-chain role map, preliminary risk classification, applicable-obligations register, control and evidence matrix, owner map, vendor-information requests, and a sequenced remediation plan. It is an implementation baseline, not a certification or legal opinion.

Can an EU AI Act consultant make a company compliant?

No consultant can guarantee EU AI Act compliance from a webpage or workshop. Compliance depends on the organization’s role, systems, intended use, evidence, controls, implementation, and evolving official guidance. Paul Okhrem organizes the operating work and evidence; qualified counsel validates legal interpretation, while relevant assurance bodies or authorities retain their own responsibilities.

What is the difference between an AI provider and a deployer?

Under Article 3, a provider develops or has an AI system developed and markets or puts it into service under its own name or trademark. A deployer uses an AI system under its authority in a professional context. One organization can hold different roles across systems, so classification must be use-case specific.

When do the EU AI Act requirements apply?

Prohibitions and AI-literacy duties began applying on February 2, 2025; governance and GPAI obligations followed on August 2, 2025. Article 50 transparency rules apply from August 2, 2026. Following the July 2026 AI Omnibus, specified Annex III high-risk rules apply December 2, 2027, and Annex I product rules August 2, 2028.

Does the EU AI Act apply to US companies?

Yes. Article 2 covers providers placing AI systems or GPAI models on the EU market regardless of where they are established, and third-country providers or deployers when an AI system’s output is used in the Union. A US company should map its products, customers, system outputs, contracting roles, and EU touchpoints before assuming it is out of scope.

How is EU AI Act consulting different from AI governance consulting?

AI governance consulting builds the enterprise operating model for AI decisions across jurisdictions: inventory, accountability, risk tiers, controls, and oversight. EU AI Act consulting applies that foundation to Regulation (EU) 2024/1689, specific operator roles, deadlines, documentation, transparency, and high-risk obligations. The work should connect, but the two services target different buyer decisions.

Primary-source ledger

Official sources used for this service page.

Regulatory facts are linked to European Union sources. The page is reviewed as implementation guidance changes; buyers should verify the current legal text and obtain advice for their facts.

EU AI Act Article 2: Scope

Official Service Desk presentation of market, deployer, third-country, importer, distributor, manufacturer, representative, and affected-person scope.

EU AI Act Article 3: Definitions

Official Service Desk presentation of provider, deployer, operator, importer, distributor, downstream provider, and other defined terms.

Paul Okhrem, AI transformation consultant
About the consultant

Paul Okhrem

Paul Okhrem is a Prague-based AI transformation and operational efficiency consultant for CEOs, boards, and global companies, with fractional Chief AI Officer engagements available. He has built B2B and enterprise software since 2009 and works directly across strategy, governance, implementation, and operating-model change.

Biography and public profiles · Verified facts · Evidence register

Discuss an engagement

Turn the legal interpretation into an implementation mandate.

Include enough context for a useful first reply. Paul Okhrem reads each message personally and replies within two business days when contact details are valid.

  • Company, sector, and countries served
  • Priority AI systems and current inventory status
  • Known provider, deployer, or supply-chain questions
  • Legal counsel and internal risk ownership
  • Deadline, executive sponsor, and expected decision

Published terms: USD 1,000/hour, 100-hour minimum, USD 100,000 floor.

Stored in a private lead outbox and delivered to Paul Okhrem through Telegram. No advertising tracking or marketing list; see the privacy policy.