01 / 03 —— THE DATES THAT MATTER
The dates that matter
The AI Omnibus, in force since 27 July 2026, moved the high-risk deadlines. This is where things stand:
2 February 2025 — prohibited AI practices banned; AI literacy duties begin.
2 August 2025 — obligations for general-purpose AI models apply.
2 August 2026 — transparency obligations (Article 50) apply.
2 December 2027 — obligations for stand-alone high-risk AI systems (Annex III) apply.
2 August 2028 — obligations for high-risk AI in regulated products (Annex I) apply.
UK organisations can be in scope when they place AI systems on the EU market or when their AI output is used in the EU.
We work alongside your legal counsel; this is not legal advice.
02 / 03 —— ISO/IEC 42001
An AI management system to ISO 42001
01 — THE STANDARD
What ISO/IEC 42001 is
The international standard for an AI management system, published in December 2023, covering policy, risk, controls and improvement.
02 — GAP ANALYSIS
Where you stand
A clause-by-clause gap analysis against the standard, prioritised by risk and effort.
03 — READINESS
Ready for certification
A plan, templates and evidence so you are ready for an external certification audit.
03 / 03 —— OUR APPROACH
Our approach
Scoped to the number of AI systems you build, buy and use.
01
Inventory
STEP 1
Find every AI system you build, buy or use, including AI features inside your software. You get a complete AI register.
02
Classify
STEP 2
Classify each system against the EU AI Act risk categories and your role as provider or deployer. You get a risk map.
03
Gap analysis
STEP 3
Compare your controls with the obligations and ISO/IEC 42001. You get a prioritised gap list.
04
Remediate
STEP 4
Plan and support the fixes, from documentation to human oversight. You get a dated plan to compliance.
