“Legal says no to every AI project”
Because nobody in the room can answer the AI Act question with confidence, and “no” feels safer than “maybe”.
Mentis · Services · EU AI Act compliance & governance
Risk-classify every AI system you run or plan, close the documentation and oversight gaps, and put proportionate governance in place before a supervisor, auditor or client asks — guided by an Independent AI Expert for the European Commission.
When to call us
Because nobody in the room can answer the AI Act question with confidence, and “no” feels safer than “maybe”.
Vendor tools, a credit model, a chatbot someone bought — nobody knows what is classified how, or who owns it.
A client questionnaire, an auditor, a works council, a regulator — and the answer is currently a shrug.
What you get
One register of every AI system, its AI Act risk class, its owner and its gaps — the document the board and the regulator both want.
Proportionate obligations mapped to each system, so low-risk work moves fast and high-risk work gets the real controls.
Classification and documentation reviewed by someone who advises the Commission on AI — practice, not a reading of the text.
What we deliver
Every current and planned system — built or bought — mapped to prohibited / high-risk / limited / minimal, with your provider-vs-deployer role per system.
Obligations per system (risk management, data governance, documentation, logging, transparency, human oversight) against what exists today.
Annex-style technical files and transparency notices started from our templates and your systems, so your teams finish them rather than face a blank page.
Decision rights, approval workflow for new AI, an acceptable-use policy staff can read, and a register process that stays alive.
Where a human must be in the loop, what they see, what gets logged — designed into the workflow, not bolted on.
Quarterly review of new systems, vendor changes and regulatory updates as the Act phases in — a retainer, not a one-off.
Fixed scope, fixed price per phase — you decide at each step.
Interviews, tool audit, vendor contracts — we find the AI you forgot you had.
Risk classes, roles, obligations, and the gap against today — in one register.
Templates pre-filled, charter adopted, oversight designed, owners named.
New systems, vendor updates and deadlines tracked — compliance that stays current.
Regulation & sovereignty
Prohibited practices and AI-literacy duties already apply; general-purpose AI obligations and the bulk of high-risk requirements phase in through 2026–2027, with national supervisory authorities in Belgium and Luxembourg being set up. GDPR governs the personal data inside your systems, DORA treats AI vendors as ICT risk in finance, NIS2 adds cyber duties for essential entities. We map all of it per system — and we keep the register alive as deadlines land.
Very likely yes — as a deployer. Using an AI system in a high-risk context (HR decisions, credit, essential services) brings obligations even when a vendor built it. The inventory tells you exactly where.
Usually no — you are a deployer of a general-purpose AI system, with transparency and AI-literacy duties. It changes if you build your own system on top of it for a high-risk purpose; we check that case by case.
For a mid-market organisation, two to four weeks for inventory and classification; documentation depends on how many high-risk systems you run. Fixed price, scoped after a 30-minute debrief.
Yes — the Assessment + AI Act Compliance Pack tier bundles both. If you only need the compliance work, this service stands alone.
A 4-week, fixed-price diagnostic across six dimensions: maturity radar, scored opportunity portfolio, AI Act exposure register and a 90-day plan — the entry point for most clients.
Learn more →ServiceGenerative AI that answers from your documents — inside your walls
Learn more →ServicePredictions you can explain, defend and act on
Learn more →ServiceAI infrastructure your data never has to leave
Learn more →ServiceOptimization that moves the P&L — routes, schedules, resources
Learn more →ServiceFrom a model that works to a product your people actually use
Learn more →Tell us the problem, not a spec. You get an honest read on feasibility, data, compliance exposure and a first step — within one business day.