Skip to content
EU AI Stack

Solutions

Three engagements, each ending in an artefact you can hand to a reviewer

We do not sell compliance programmes. We produce the specific evidence that unblocks a deal or an audit, and document how it was verified.

Diagram of three engagements: AI Act readiness, NIS2 supplier audit and sovereign deployment, joined on one baseline
01

AI Act readiness

Article 50 has applied since 2 August 2026. The high-risk obligations moved: Annex III to 2 December 2027, Annex I to 2 August 2028. Most readiness projects on the market are still priced against the old calendar. We scope yours against the current one.

What you get

  • Classification workshop
  • Article 50 implementation pack
  • Evidence file

AI Act Art. 50, Annex I and Annex III

Read the detail: AI Act readiness
02

NIS2 supplier audit

Your customer is in scope for NIS2, so you are audited as part of their supply chain. That audit asks for artefacts, not intentions: asset inventory, patch windows, incident timelines, subcontractor list, exit plan.

What you get

  • Gap review against ISO 27001
  • Incident runbook
  • Audit rehearsal

NIS2 supply chain, CRA reporting, ISO 27001

Read the detail: NIS2 supplier audit
03

Sovereign deployment

Sovereignty is a buyer's problem stated as a hosting question. We answer it as an architecture decision: which layer must stay in your jurisdiction, what that costs over three years, and what an auditor accepts as proof.

What you get

  • Sizing and TCO model
  • Isolation architecture
  • Exit clause review

Data Act egress, audit evidence, TCO

Read the detail: Sovereign deployment

Which engagement clears which blocker

EngagementUse it whenYou hand overRegulations in scope
AI Act readinessMap your AI system against Article 50 transparency duties and the deferred high-risk obligations, with dates verified in EUR-Lex.A written classification of each AI system you ship or operate, with the article it falls underAI Act Art. 50, Annex I and Annex III
NIS2 supplier auditSupply-chain security evidence for AI vendors audited by essential and important entities under NIS2, including CRA incident timelines.An evidence pack mapped to the supply-chain articles your customer will citeNIS2 supply chain, CRA reporting, ISO 27001
Sovereign deploymentChoose between on-prem, air-gapped, network-isolated and private-cloud AI with the numbers and the audit consequences of each option.A deployment recommendation with a three-year cost model, not a vendor preferenceData Act egress, audit evidence, TCO

Frequently asked questions

Do high-risk obligations apply from August 2026?
No. The Digital Omnibus that entered into force on 27 July 2026 moved Annex III systems to 2 December 2027 and Annex I to 2 August 2028. Only Article 50 applies from 2 August 2026.
What still has a 2026 deadline?
2 December 2026: the end of the grace period for marking synthetic content, and the prohibition covering CSAM and non-consensual intimate imagery.
Does NIS2 apply to us if we only sell software?
Often indirectly. If your customer is an essential or important entity, its supply-chain obligations become contractual requirements on you, whatever your own scope status is.
Is ISO 27001 enough?
It carries a large part of the control evidence and none of the reporting duties. The overlap is real but partial.
Is on-prem always cheaper?
Only above a sustained utilisation threshold. Below it, private cloud wins on three-year TCO even with sovereignty premiums included.
Do auditors require an air gap?
Rarely. Documented network isolation with enforced egress controls is accepted far more often than a true air gap, which most teams cannot operate consistently.

Next step

Not sure which one you need?

Describe the blocker in two sentences. We will tell you which engagement fits, or that you do not need one.

Get in touch