Services

EU AI Act compliance, proven with documentation.

The evidence of how the system decides, before anyone asks. Logging, costs, data policy and the technical file a regulator will want to see.

Sooner or later someone asks why the system decided the way it did: a client, an internal audit, a regulator. Having the answer ready is an architectural decision taken at the start — reconstructing it afterwards is expensive and often impossible.

What we log

  • The input. The request as it arrived, with sensitive data masked where it must be.
  • The context. Which documents or records were used to produce the answer — without this there is no possible explanation.
  • The decision. What the system answered, with what confidence and against which threshold.
  • Human intervention. Who reviewed it, what they changed and when.
  • The cost. Consumption per request, aggregated by process and period.

Data policy

Together with your team we write down what may leave the organisation, to where, for how long and under what contract. Then we implement that policy in code — masking, retention, access control — so it does not depend on anyone remembering.

Where the data category demands it, the alternative is a model hosted in your own infrastructure. It costs more to run and is sometimes the only acceptable answer.

Cost control

Commercial model consumption grows without warning as adoption rises. We instrument it per process, set ceilings and alerts, and identify the expensive requests that could be served by a smaller model or a cached answer.

Regulatory readiness

The European AI Act classifies systems by risk and imposes documentation, human oversight and traceability obligations on those in the more demanding categories. We are not legal advisers and we do not perform the legal qualification of your case — we build the technical record and the operating documentation your legal team needs in order to answer.

Frequently asked questions

Does this apply to us if we only run an internal assistant?

Logging and cost control apply to any use at some scale. Regulatory obligations depend on the risk classification of the specific case, which is a legal assessment.

Can you audit an AI system we already run?

Yes. We review what is logged, what is not, where the system decides without oversight and where data leaves without control, then deliver a remediation plan ordered by priority.

How long should logs be kept?

We define that with you, based on purpose and applicable obligations. Keeping everything indefinitely is a risk too.

Shall we talk about your case?

A first conversation is about working out whether there is work here worth doing. If there is not, we will say so.

Book 20 minutes

See our AI in action — this assistant was built by us, with the same technology we sell.

← All services