[AI Act Compliance]

Bring your AI systems into compliance with the AI Act

Galadrim inventories your AI systems, qualifies them according to the European regulation, and leads their technical compliance, with a partner law firm for the legal aspects.
Transparency has been required since 2 August 2026, high-risk by 2 December 2027
Up to 35 M€ or 7 % of global turnover in case of infringement
40 AI Engineers and a cybersecurity team, supported by a law firm
Two Galadrim collaborators in a workshop, attentive to a presentation
+800 large corporations, mid-caps, SMEs, and public organisations entrust us with their tech and AI projects
[The four risk levels]

The AI Act qualifies each of your systems, and your obligations follow from this

The regulation does not apply in a block: it classifies each system according to its use, and it is this level that sets the obligations, such as the deadline. This is the first question to resolve, before any major undertaking.
Unacceptable risk - usage is prohibited

Unacceptable risk - usage is prohibited

Social scoring, exploitation of a person's vulnerability, emotion recognition in the workplace or in class, individual predictive policing, untargeted harvesting of facial images: these uses have been prohibited since 2 February 2025, with two additional prohibitions coming into effect on 2 December 2026. This is the only level exposed to the cap of 35 M€ or 7 % of global turnover.

Concerned if one of your tools scores individuals or infers their emotional state.

High risk - the most demanding regime

High risk - the most demanding regime

Recruitment and employee management, credit scoring, insurance pricing, education, biometrics, critical infrastructure, access to essential services: for these areas, Annex III imposes risk management, data quality, technical documentation, logging, human oversight, robustness, and cybersecurity. The Digital Omnibus has postponed these obligations to 2 December 2027, and to 2 August 2028 for AI embedded in an already regulated product.

Concerned if a decision that commits a person - hiring, credit, access to a service - relies on one of your systems.

Limited risk - transparency, required today

Limited risk - transparency, required today

A conversational agent must state that it is a machine, generated content must bear machine-readable marking, a deepfake must be flagged. These obligations from Article 50 apply since 2 August 2026; generative systems already on the market by this date have until 2 December 2026 for marking. An infringement exposes to 15 M€ or 3 % of global turnover.

Concerned if a chatbot, voice assistant, or content generator is in use at your organisation.

Minimal risk - no specific obligation, two rules nonetheless

Minimal risk - no specific obligation, two rules nonetheless

The vast majority of uses fall into this category: document research, writing assistance, internal classification. No specific obligations are attached to it, but two transversal rules remain - the AI literacy of your teams, which Article 4 asks you to support since February 2025, and GDPR as soon as personal data enters the chain.

Concerned if your teams use ChatGPT, Claude, Copilot, or Mistral in their daily work.

The Galadrim team at work
The postponement of high-risk obligations to December 2027 has been interpreted as a reprieve. It is one for the timeline, but not for the work: inventorying systems, qualifying roles, and reviewing documentation takes several months, and nothing can begin until no one knows what is actually running in the company. Organisations that start now are also addressing a blind spot that the AI Act merely reveals: the AI tools that teams have adopted without management's knowledge.
Benjamin DrighèsPartner and CTO Data & AI
[Our support]

From mapping your systems to their documented compliance

Six services, to be taken separately or in sequence. The technical aspect is our expertise; the legal aspect is handled with a partner law firm, under a single point of contact.
Mapping and compliance audit

Mapping and compliance audit

We inventory all AI systems in use at your premises, including those embedded in your providers' software and those your teams use outside the IT department's circuit. Each is qualified - its risk level, and your role as supplier or deployer - and the gap report measures the distance between your situation and what the regulation expects.
Technical compliance

Technical compliance

We implement what the regulation requires of the system itself: decision logging, human oversight point, robustness and cybersecurity measures, risk management, and hosting within the Union when data sensitivity requires it.
Documentation, register, and governance

Documentation, register, and governance

We produce the technical dossier, the declaration of conformity and the expected records - including the reasoned justification to be filed in the European database when a system from Annex III is exempted from high risk. And we set up the governance that keeps them updated: roles, committee, review at each substantial modification.
Legal aspect, with our partner firm

Legal aspect, with our partner firm

Qualification of your role within the meaning of the regulation, articulation with the GDPR, clauses to be borne by your model providers, ownership of produced content, liability regime: the partner law firm addresses these subjects alongside our teams, without you having to coordinate two providers.
AI Literacy for your teams

AI Literacy for your teams

Article 4 requires you to support the upskilling of your employees in AI, and this obligation has been in effect since February 2025. We design the corresponding formats: executive committee workshop, career-specific paths, technical training for your data and development teams.
Regulatory watch and compliance maintenance

Regulatory watch and compliance maintenance

The framework is evolving: the Digital Omnibus redistributed deadlines in July 2026, and European harmonised standards are arriving in waves. We monitor these developments and adjust your roadmap and systems, rather than letting you discover a discrepancy.
[Our method]

Our method for bringing your AI systems into compliance

  • SCOPING
    Step 01

    Framing and scope

    A workshop brings together CIO, DPO, legal department, and business units to define the audit scope, your specific deadlines, and already known systems. We determine what the mission must produce, and for which decision.
  • MAPPING
    Step 02

    Inventory of systems in use

    We inventory what is actually running: internal developments, AI components embedded in your off-the-shelf software, calls to external models, and tools adopted by teams outside the IT department's circuit. Each entry is described by its actual use, not by its commercial name.
  • QUALIFICATION
    Step 03

    Risk level and role

    For each system, we determine its level according to the regulation and your role: supplier, deployer, importer or distributor. This qualification sets your obligations and deadlines, and it shifts more often than one might think - especially when a product is built on a model's API.
  • ACTION PLAN
    Step 04

    Gap analysis and roadmap

    We produce a gap report per system and a roadmap ordered by regulatory deadline and actual exposure: transparency first, as it is already required, then high risk, within the time allowed by the December 2027 postponement.
  • IMPLEMENTATION
    Step 05

    Compliance and deliverables

    We implement the selected technical measures and produce the documentary deliverables. Each system completes the stage with its technical file, its records, and its human checkpoint in service.
  • SUSTAINABILITY
    Step 06

    Governance and monitoring

    An AI governance committee takes over, with its review procedures for each substantial modification, team training, and monitoring of a continuously evolving framework.
01/06
[Why Galadrim?]

Why entrust your AI Act compliance to Galadrim?

AI Engineers, not just auditors

The AI Act is primarily a technical regulation: data quality, traceability, robustness, cybersecurity, human oversight. Our 40 AI Engineers build these systems daily, and correct what the audit uncovers instead of just documenting it.

Technical and legal expertise under a single point of contact

Our partner law firm handles qualification, contracts, and liability alongside our teams. You retain a single point of contact on the Galadrim side, and no one has to arbitrate between two service providers.

Experience in constrained environments

Our teams deliver AI systems in production for healthcare, banking, insurance, industry, and defence, where data traceability and localisation are constrained from the design phase. Our cybersecurity engineers intervene on the measures required by the regulation.

Compliance that doesn't freeze your roadmap

The roadmap is ordered by deadline and actual exposure, and is conducted in parallel with your developments. Technical measures are added to your existing systems: we do not ask you to stop them.
[Projects]

AI systems delivered where constraint precedes code

HealthUrgo Médical

A clinical decision-making aid where each answer cites its source

Urgo Médical, a specialist in wound care, wanted to offer nurses decision support based on its proprietary corpus. Galadrim developed Med-ed GPT, a conversational agent integrated into the Healico application: it guides wound identification and care recommendation, and each answer refers to the source from which it is drawn. Health decision support falls under the most regulated areas of the regulation - source traceability and the healthcare professional's place in the loop were established from the design stage.
160 000nurses users
300 000documented wounds
Urgo Médical Logo
Commercial real estateMercialys

Setting up AI governance for a listed player before deployment

Mercialys wanted to define its AI strategy without multiplying inconclusive experiments. We framed the approach from end to end: steering committee, roadmap prioritised by return on investment, then deployment of four agentic solutions in six months - contract analysis, internal chatbot, investment memo generation and automated monitoring. The committee put in place is the very structure that the regulation expects from a deployer: a place where systems are inventoried, arbitrated and reviewed.
180internal users
4operational AI agents in 6 months
Mercialys Logo
DefenceDelia Strat · Ministry of Armed Forces

Running a Large Language Model on data that doesn't leave the premises

Delia Strat publishes software for defence stakeholders, including the Ministry of the Armed Forces, and wanted to provide intelligence analysts with a way to quickly read a voluminous documentary corpus. Galadrim developed the algorithm that converts these documents into relational graphs, relying on an open-source French Large Language Model that is self-hosted. This is the solution we provide whenever data cannot leave a controlled perimeter.
80 %of analysis time saved
7 billionparameters for the language model
Delia Strat · Ministry of Armed Forces Logo
They talk about us
[Our team]

The profiles involved in your compliance

An AI Act mission mobilises three areas of expertise: consulting, which inventories and qualifies; AI engineering, which implements what the regulation requires of the system; and infrastructure, when data cannot leave the Union.
Benjamin Drighès
Benjamin Drighès Partner and CTO Data & AI
A former strategy advisor at the French Financial Markets Authority (AMF) and an engineer from the Corps des Mines, he knows from within organisations where every decision must remain justifiable, and arbitrates the architectural choices for Galadrim's AI projects.
Pierre-Antoine Dornic
Pierre-Antoine Dornic Head of GenAI
It maps and prioritises the AI use cases of departments, in workshops with management committees - the same exercise that begins a compliance inventory.
Lucien Maillard
Lucien Maillard Principal AI Strategy Consultant
He frames AI projects with client departments, inventories with teams the systems actually in service, and qualifies what the available data allows to build.
Quentin Massonnat
Quentin Massonnat AI Tech Lead
He designs the architecture of our clients' AI systems, including decision logging and human checkpoint, and supervises developments until production.
Surya Ambrose
Surya Ambrose Head of Engineering
An Engineering Manager for four and a half years in a FinTech regulated by the AMF, he structures Galadrim's engineering practices: testing, delivery traceability, and documentation, exactly what a technical file relies upon.
Côme Lassarat
Côme Lassarat AI and Infrastructure Engineer
It builds the data foundations and hosting architectures - connectors, warehouses, migrations - and deploys self-hosted models when data cannot leave the Union.

Galadrim inventories your AI systems, qualifies them under the AI Act, and leads their compliance.

Chat with an expert
[FAQ]

Frequently asked questions about the AI Act

Most likely. The regulation targets any provider, deployer, importer, or distributor of an AI system in the Union, and it also applies to organisations established outside the Union as soon as the produced outcome is used there. If you operate a candidate sorting tool, a scoring system, a client chatbot, an internal copilot, or a content generator, or if your teams call ChatGPT, Claude, or Mistral in their work, you are a deployer within the meaning of the regulation.
Prohibited practices and AI literacy apply from 2 February 2025, obligations for general-purpose models from 2 August 2025, and transparency obligations under Article 50 - stating that an interlocutor is a machine, marking generated content, reporting a deepfake - from 2 August 2026. The Digital Omnibus, which came into force on 27 July 2026, has however postponed the obligations for high-risk systems under Annex III to 2 December 2027, and to 2 August 2028 for AI embedded in an already regulated product.
It changes the timeline, not the workload. A complete inventory, the qualification of each system, and the revision of documentation require several months, and the two new dates are firm: Parliament and the Council rejected the triggering conditioned on the publication of harmonised standards proposed by the Commission. Transparency obligations, however, are now enforceable.
A provider develops an AI system and places it on the market; a deployer uses it in a professional context without having developed it. A company that builds a product on a model's API switches from deployer to provider as soon as it commercialises a distinct system under its own name. This qualification is central: it determines the extent of your obligations.
Annex III lists eight areas: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential services - credit, insurance, social assistance, emergency services -, law enforcement, migration and border control, administration of justice and democratic processes. A system falling under Annex III may be excluded from high risk, but the assessment must be justified and recorded in the European database.
For an organisation that identifies two to five high-risk systems, allow four to seven months between scoping and documented compliance. The timeframe extends when there are numerous uses outside the IT department's scope or when no mapping exists. We adapt the pace to your deadlines.
You have a single point of contact on the Galadrim side, who manages the mission. The partner firm intervenes on the qualification of roles, contracts with your providers and clients, the articulation with GDPR, intellectual property of produced content, and the liability regime, in coordination with our technical teams. You don't have two service providers to orchestrate.
Three caps, based on the higher of the two amounts: €35M or 7% of global turnover for prohibited practices, €15M or 3% for other failures - including transparency -, and €7.5M or 1% for inaccurate information provided to authorities. Reduced caps apply to SMEs and small and medium-sized enterprises.
The AI Act does not impose it as such: it is the GDPR and, where applicable, your sectoral regulations that govern localisation. In practice, the question arises as soon as an external model processes personal or sensitive data. Depending on the case, we anonymise upstream of the call, host within the Union, or deploy a self-hosted open source model - this is what we did for the Ministry of Armed Forces.
[Contact us]

Let's bring your project to life together

We work with all types of clients, across all sectors. Whether you're an entrepreneur or managing a large organisation, a tailored team will meet your needs.

Over 800 companies have trusted us to create their web, mobile, and AI products

Your enquiry

We'll get back to you within 1 hour.