Cerberus blocks the lethal trifecta at the tool boundary — see the 525-run evidence set.

Warden · AI Governance

The EU AI Act asks what your systems do, and you have to answer per system

A readiness engagement against Regulation (EU) 2024/1689: classify every AI system you operate or place on the market, establish which obligations attach, and build the technical documentation and risk management the Act requires.

Obligations attach to systems, not to companies

The Act's duties depend on the role you hold for each system — provider, deployer, importer or distributor — and on the risk category that system falls into. Organizations that treat it as one program-level question usually get the classification wrong.

  1. Role determines dutyFine-tuning and rebranding a model can move you from deployer to provider, with substantially more obligation attached.
  2. Classification is per systemThe same model used for two purposes can be minimal-risk in one deployment and high-risk in another.
  3. The technical file is evidence, not narrativeData governance, logging, accuracy and human oversight all have to be demonstrable rather than described.

How the engagement runs

1

Inventory and role mapping

Every AI system in scope, the role you hold for it, and where it is placed on the market or put into service.

2

Classification

Prohibited, high-risk, limited-risk or minimal-risk per system, with the reasoning recorded so it can be defended.

3

Gap analysis

For each high-risk system, obligations against current practice: risk management, data governance, logging, transparency, human oversight, accuracy and robustness.

4

Remediation plan

Sequenced work with owners, mapped to the applicable dates in the Act's phased application.

What you hold at the end

  • A classified AI system inventory with documented reasoning per system
  • A role determination per system, including where fine-tuning changes it
  • A per-obligation gap analysis for every high-risk system
  • Technical documentation structure and the evidence sources that populate it
  • A remediation plan sequenced against the Act's application dates

The instrument itself

Regulation (EU) 2024/1689
The AI Act, applying in phases, with the prohibitions and the general-purpose AI provisions arriving ahead of the full high-risk regime.
Extraterritorial reach
It applies where the output is used in the Union, not only where the provider is established.
Harmonized standards
Conformity is expected to be demonstrated largely through harmonized standards as they are published.

What carries the evidence

Classification first, everything else follows

Most of the cost in an AI Act program is spent on systems that turn out not to be high-risk. Getting the classification right is the saving.