(C) · AI GOVERNANCE

RAVENTRYX LLC

EU AI Act readiness, before the deadlines land.

Most organizations have never built the one thing the EU AI Act turns on: a classified inventory of the AI they build and deploy. We map the deployer and provider obligations most firms do not know already bind them, classify every system, and assemble an evidence base a regulator will actually read while the timelines are still ahead of you. Where requirements overlap, controls and evidence can be mapped and reused. Where requirements differ, framework-specific obligations remain separately identified and managed.

When you need this

Article 50 is live 2 August 2026 and your AI is already in production. You buy a third-party high-risk model and inherit Article 26 deployer obligations regardless of the provider conformity status, and no one has built the inventory, the classification, or the technical documentation yet. AI governance is one of five capabilities at RAVENTRYX, and the one most clients arrive through; EU AI Act readiness is where that work starts.

We map every AI system you deploy, classify it under Annex III or Article 26, and build the evidence base before the next deadline lands.

How we work it

How this actually goes.

  1. 01

    Inventory and classify every system

    We build the AI system inventory more than half of organizations still do not have: every model and feature you operate, classified under Annex III where you are the provider and Article 26 where you deploy someone else's. You get a plain read on which systems carry real regulatory weight and which a regulator looks at first.

  2. 02

    Map the obligations you actually carry

    Provider duties and deployer duties are separate, and a conformant provider does not discharge yours. We map Article 26 deployer obligations (human oversight, use per instructions, input-data relevance, logging, monitoring) against each system, alongside the Annex IV technical documentation and the Article 9 risk file where you are the provider.

  3. 03

    Build the evidence base and keep it current

    We produce the deliverables enterprise buyers and notified bodies demand. Where the EU AI Act, ISO 42001, ISO 27001, SOC 2, and NIST AI RMF overlap, controls and evidence are mapped once and reused; where they differ, the obligations stay separately identified. Then we embed the ownership and review cadence that keeps it live as the Omnibus dates settle in the Official Journal.

What's included

The capability, in full.

Never built, already required

Every system you operate, classified under Annex III.

Most organizations have never built the one thing the EU AI Act turns on: a classified inventory of the AI they build and deploy. We identify every model and feature in scope, apply the Annex III classification against each system (distinguishing where you are the provider from where you are the deployer) and produce a register that gives a clear read on which systems carry real regulatory weight and which a regulator looks at first.

Start a conversation

What you get

A classified AI inventory, the deployer and provider obligations mapped, and an evidence base a regulator will read.

01

You know exactly which systems carry regulatory weight.

The inventory most organizations have never built becomes the source of truth: every model classified, every deployer obligation named, and a clear read on what a regulator examines first. No scramble at the eleventh hour.

Classified, not guessed

02

A position you can stand behind in diligence.

When a board, investor, acquirer, or enterprise buyer asks where you stand on the EU AI Act, you have an answer on record (covering the deployer obligations most firms do not know already bind them) rather than a folder you hope nobody opens.

On record

03

One evidence base where the requirements overlap.

Where the EU AI Act, ISO 42001, ISO 27001, SOC 2, and NIST AI RMF overlap, controls are mapped once and reused; where they differ, the obligations are held separately. The next questionnaire or auditor gets answered from work already on the shelf, not assembled under deal pressure.

Mapped once

What the EU AI Act requires of you as a deployer

The EU AI Act draws a clear line between providers (organizations that develop or place AI systems on the market) and deployers: organizations that put AI into use in a professional context. If you run a third-party high-risk system affecting your employees, customers, or other persons located in the EU, you are a deployer under Article 26, and a conformant CE-marked model from a credible vendor does not discharge what the Act requires of you. Your obligations run independently: monitor the system in operation, ensure it is used only within its stated purpose, conduct input-data relevance checks, maintain logs, and appoint a human overseer.

Most US and EU operators have not built the classified AI inventory the Act turns on, and most have not mapped Article 26 obligations against the systems they already run. That gap is the starting point of EU AI Act readiness work. AI governance is one of five capabilities we operate at RAVENTRYX (the work detailed at /services/ai-governance) and EU AI Act readiness is the entry point most organizations come through. The deployer obligation map, the inventory, and the Annex IV documentation we produce here are the same foundation the ISO 42001 Implementation spoke builds its management system on top of.

A coordinated control architecture across the framework cluster

Mapping controls once across EU AI Act, ISO 42001, ISO 27001, SOC 2, and NIST AI RMF (the framework cluster within the AI governance capability) is the structural discipline that makes an evidence base durable. Each framework asks similar questions in different registers: what systems do you run, who is accountable, how do you assess and treat risk, and what documentation supports your claims? Where requirements overlap, controls and evidence can be mapped and reused. Where requirements differ, framework-specific obligations remain separately identified and managed. The alternative (five parallel programs with separate owners, separate documentation, and separate review cadences) collapses the first time an auditor asks for something that was filed differently across binders.

The EU AI Act readiness work (the system inventory, the Annex III classification, the Article 26 deployer map, and the Annex IV technical documentation) is the evidence base that the ISO 42001 Implementation spoke at /services/ai-governance builds its management system on top of. The two spokes share a coordinated control architecture designed to be maintained as one artifact rather than two separate programs. When a board, an enterprise buyer, or an auditor asks where you stand across both frameworks, you answer from one register, not from two binders assembled in parallel.

Frequently asked questions

Which EU AI Act deadlines actually bind us, and when?

Article 50 transparency obligations (covering AI systems that generate synthetic content, chatbots, and deep fakes) went live 2 August 2026, binding regardless of where you are incorporated. High-risk system requirements under Annex III follow the full application schedule from that date onward. If you deploy AI affecting people in the EU, the compliance clock is already running.

We buy a third-party model: why do we carry the Article 26 deployer obligations?

Purchasing a conformant model transfers the provider's CE marking to the vendor, not your deployer duties to them. Article 26 obligates you, as the organization putting the system into use, to apply human oversight, confirm use within the stated purpose, conduct input-data relevance checks, maintain logs, and monitor in operation. Provider conformity is necessary but does not substitute for your independent obligation to operate the system correctly.

Does a US company with EU users fall in scope of the EU AI Act?

Yes. The EU AI Act applies based on where the system's outputs are received, not where the organization is incorporated. A US company deploying AI to users, employees, or affected persons located in the EU is bound as a deployer under Article 26. The same applies to US providers who place high-risk systems on the EU market. Jurisdiction follows the AI's impact, not the company's registered address.

Regulatory information only. The frameworks, timelines, and standards referenced here reflect our reading of the EU AI Act (Regulation 2024/1689) and related instruments (including GPAI / Article 53 and the Digital Omnibus deferral) as of the review date below. Regulatory guidance and implementation timelines continue to evolve and may change. Nothing here is legal advice, and reading it does not create an advisory relationship. For guidance specific to your organization, consult qualified legal or compliance counsel. Last reviewed: July 28, 2026.

Engage

Starting is the easy part.

How starting works

  1. 01

    Book it

    Pick the assessment, or start with a short call if you want to pressure-test the fit first. No long intake form, no gatekeeping.

  2. 02

    We assess

    An honest read on exactly where you stand, fast. You get a written diagnostic and a prioritized plan, not a sales deck.

  3. 03

    You decide

    Keep going with us, or take the plan and run it yourself. Either way you leave with something you can act on Monday.

What’s in the room with you

  • A senior operator who owns your engagement end to end: no junior hand-off, no rotating cast.

  • A written diagnostic you can circulate internally and defend in front of a board.

  • A prioritized plan with the trade-offs made explicit, costed, and ready to execute.

No retainer to start. No automated drip sequence. A real person, not a bot, replies within one business day. And if we’re not the right fit, we’ll tell you who is.

Proof

We had deployed three third-party models before anyone ran the Article 26 analysis. Within eight weeks we had the inventory classified, the deployer obligations mapped, and a documentation package we could put in front of an auditor or an enterprise buyer. We did not expect to be that far behind.

Chief Risk Officer · EU Fintech Platform

Anonymized. Representative engagement archetypes drawn from real mandates; client identities withheld.

Where to start.

  • AI Readiness Assessment$950one-time
Secure Stripe checkout
  • Typical timeline: 2–3 weeks
  • You leave with a written report + plan
  • A person replies within one business day

A classified AI inventory, the deployer and provider obligations mapped, and an evidence base a regulator will read.