Article 50 transparency: enforceable 2 August 2026. High-risk moved to 2027 — this didn't. EU-facing chatbots and generative features are in scope. What applies to you →
Unblock the deal · ISO 42001 · EU AI Act · Microsoft SSPA

The deal is signed except for one section.
The AI questionnaire.

Legal won't sign. Procurement won't move. Every week it sits there is revenue you've already earned and can't book. A consultant quotes $20,000–$80,000 and eight weeks. Big 4 starts at $75,000. A $199 template pack won't survive an auditor tracing a control.

We build the evidence that unblocks it — fitted to your systems, in days, at a fixed fee agreed before we start.

Book a free 20-minute call See the actual documents

20 minutes · No prep · Straight to the founder · We'll tell you if you don't need us

Book a call if
  • A vendor questionnaire has an AI section and the contract is frozen behind it
  • Microsoft SSPA flagged you, or Sensitive Use AI made ISO 42001 mandatory
  • You ship a chatbot or generative feature and Article 50 applies from 2 August
  • You advise clients on AI and your associates rebuild the same artifacts every time
  • A Stage 1 audit is booked and the evidence binder is empty
38
Annex A controls,
each justified
23
Core AIMS documents
AIMS-01 → AIMS-22
4
Frameworks from one
evidence base
3
Formats: PDF, Word,
structured JSON
Days
Not the 4–8 weeks
an in-house build takes
The most expensive misunderstanding in AI compliance right now

The EU AI Act was delayed. Your deadline wasn't.

Every headline in June said the same thing: the EU delayed the AI Act. Boards heard “delayed” and stood their programmes down. Most of them read it wrong.

The Digital Omnibus moved the high-risk regime (Annex III) to December 2027. That part is real. But Article 50 — the transparency layer that governs chatbots, generative features and synthetic media — was deliberately left untouched. It applies from 2 August 2026 regardless of your risk tier.

If a user in the EU can talk to your AI or see content it generated, your date did not move. It is enforceable 2 August 2026.

Obligation Who it hits Date
Article 50 transparency Chatbots, generative content, deepfakes 2 Aug 2026
Article 50(2) watermarking Systems already in market 2 Dec 2026
Annex III high-risk HR, credit, biometrics, essential services 2 Dec 2027
Annex I embedded high-risk AI inside regulated products 2 Aug 2028

Sources: Regulation (EU) 2024/1689 as amended by the Digital Omnibus (Parliament 16 Jun 2026, Council 29 Jun 2026); Gibson Dunn, Jones Walker, DLA Piper client guidance, 2026. Article 50(2) applies to new systems on placement.

Find out which date reaches you →

20 minutes. We'll tell you which obligations apply — and if none do, we'll say that too.

Why this didn't exist before

The market has two prices. Neither of them works.

ISO/IEC 42001 was published in December 2023. The market that grew around it went straight to two extremes and skipped the middle entirely.

Option What it costs Why it fails
Template packs $150–$1,500 Generic by construction. A certification-industry guide puts it plainly: a set of pre-written templates with your company name dropped in will not impress an experienced auditor — the documentation has to reflect your systems and your risks.
Independent consultant $20,000–$80,000 Gap assessment alone runs $5,000–$15,000. Then 4–9 months on their calendar. Priced past most teams before the first document exists.
Big 4 / large consultancy From $75,000 Enterprise engagements run $75,000–$250,000+. And the standard is two years old — the large firms are learning it in real time, on your budget.
HumanAudit Fixed fee, agreed first The documents fitted to your systems, in days, priced in writing before work starts. Not a template with your logo. Not a five-figure retainer.

Ranges are published industry estimates from certification consultancies and compliance platforms, 2026. They vary by scope, number of AI systems, and existing ISO 27001 maturity. We cite them because the gap between the two ends is the entire reason this company exists.

Not sure which side of the gap you're on?

Twenty minutes tells you which regimes actually reach you, what's in scope, and roughly what it costs. Often the answer is narrower than expected.

Book a free call
How we work together

Start where the pain is. Stay for what decays.

Compliance evidence isn't a one-time artifact. Systems change, models get retrained, regulations move, staff turn over. Most vendors sell you a document and disappear. We price for the whole lifecycle.

01 · Unblock

AI Trust Package

$3,500
Fixed · 5 business days

For the deal that's stuck right now. Everything your buyer's security reviewer needs, in the format they expect.

  • ·Public trust page their reviewer can visit
  • ·Pre-filled questionnaire bank — SIG Lite, CAIQ, SSPA Section K
  • ·AI system inventory and classification
  • ·One-page governance summary for your champion to forward
Unblock the deal
02 · Build · most common

Readiness Engagement

Fixed fee
Scoped on the call · 10–15 days

The full evidence base. Statement of Applicability, risk register, impact assessments, technical file — fitted to your systems.

  • ·All 38 Annex A controls, each with written justification
  • ·Cross-framework mapping — one base, four regimes
  • ·PDF, editable Word and structured JSON
  • ·60 days of Regulatory Watch included
Scope your engagement
03 · Maintain

Regulatory Watch

$500–1,500/mo
Free for 60 days with any engagement

Documentation decays. When a regulation moves, you find out what changed in your artifacts — not just that something changed.

  • ·Change alerts mapped to your specific documents
  • ·Quarterly evidence refresh and re-trace
  • ·Surveillance-audit readiness check
  • ·Cancel any time — no lock-in, no auto-enrol
Start with the free tier
For firms · the model that scales
Firm Partnership — $2,000–5,000/mo

Unlimited white-label artifact generation for your client engagements, priority turnaround, co-branded templates, and a quarterly regulatory briefing for your team. One relationship instead of one engagement at a time.

How partnerships work
What you actually receive

Documents an auditor can trace end to end.

Not a dashboard. Not a maturity score. The artifacts a Stage 1 reviewer opens first — where every control carries a justification and every risk carries a treatment action that actually exists.

AIMS-07 · Statement of Applicabilityextract
ControlDecisionJustification
A.2.2 Included AI policy approved by the board 14 Mar 2026. Reviewed annually and on material change to any in-scope system.
A.4.2 Included Resource inventory covers 3 in-scope systems. Compute, data and human oversight roles documented per system.
A.5.4 Included Impact assessment completed for the hiring-recommendation model. Article 27 FRIA elements (a)–(g) addressed.
A.10.3 Excluded No third-party model providers in scope as of this revision. Reassess on procurement of any external model.
4 of 38 controls shown · every decision carries a written justification, not a tick
AIMS-06 · Risk Treatment Planextract
RiskActionTreatment
RISK-004 TRT-007 Demographic drift in candidate scoring. Quarterly fairness evaluation against protected-attribute proxies; owner: Head of ML.
RISK-009 TRT-011 Undisclosed AI interaction. Article 50 disclosure implemented at first response in the chat surface; owner: Product.
RISK-012 TRT-014 Serious-incident reporting exceeds statutory window. Article 73 escalation path with 2 / 10 / 15-day tiers; owner: Legal.
RISK-017 TRT-016 Silent model update bypasses review. Change-management gate requires re-assessment before deployment; owner: Eng.
Every TRT identifier resolves to a described action — and back-links to the SoA

Illustrative extracts using representative content, formatted exactly as delivered. Your documents carry your systems, your risks, your owners and your dates. Delivered as PDF, editable Word and structured JSON.

Scope your document set 20 minutes · you'll leave knowing what you need, whether or not you use us
Why trust a compliance vendor

A customer found a defect in our work. We published it.

A director at a European consultancy was reading AIMS-06 and noticed it referenced treatment actions by identifier — TRT-001 through TRT-016 — without describing what any of them were. He was right.

We audited the whole set and found two more defects he hadn't spotted. Four risks with no treatment action at all. Two SoA back-links that didn't reconcile with the treatment plan. An auditor tracing controls would have raised both — as findings against his client's management system, not against our documentation.

We rebuilt the documents, shipped v2.3 free to every existing customer with a written explanation, and published the account with the control IDs so anyone can check it.

Read the full changelog
changelog · v2.39 Jul 2026
$ audit --set AIMS --trace-controls
 
✗ AIMS-06 · TRT-001…016 never defined
   reported by customer
✗ 4 risks · no treatment action
   found internally
✗ 2 SoA back-links · unreconciled
   found internally
 
✓ 3 defects corrected
✓ 1 document added
✓ v2.3 shipped free to all buyers
✓ published with control IDs
Who buys this

Our buyers so far are a Tokyo IP firm, a European consultancy, and a certification body — organisations whose own reputation depends on the documentation holding up. That is the reference we'd want if we were you.

How you know it will be right

We run the auditor's trace before you ever see the documents.

A compliance document doesn't fail visibly. It looks correct right up until an assessor follows a control back to a treatment action that was never written. By then it's in your engagement, under your name.

So we automated the exact check that caught us. Every deliverable is machine-traced before a human reviews it, and again before it ships.

01Intake — structured form. Nothing starts without it. 02Spec lock — scope, price and named specialist, in writing, before work begins. 03Trace check — automated reconciliation, then senior reviewer. 04Your review — one revision round, scoped in writing. 0530-day defect window — anything found is fixed free and published.
trace-check · pre-deliveryautomated
$ humanaudit trace --set AIMS --strict
 
✓ 38/38 Annex A controls decided
✓ 38/38 decisions carry justification
✓ 20/20 risks have treatment actions
✓ 20/20 TRT identifiers resolve
✓ SoA back-links reconcile both ways
✓ every owner and date populated
✓ no placeholder text remaining
 
7 checks · 0 findings
✓ cleared for reviewer

Every check in that list exists because we failed it once. The changelog above is the receipt.

Book a free 20-minute call
Two situations

The work is different depending on who's asking.

For consultancies, law & advisory firms

Your associates keep rebuilding the same documents

Over 60% of corporate legal teams expect to rely less on outside counsel. Firms without a demonstrable AI capability are structurally exposed — but building one means either hiring into a two-year-old discipline or writing off the first month of every engagement.

We are the artifact layer under your brand. Your template, your file naming, your sign-off. Your client never needs to know we exist.

How this works for firms
For AI & software companies

A customer is blocking your deal

SSPA DPR v12 carries 63 requirements; Section K covers AI systems with 18, of which 15 were updated. For Sensitive Use AI — hiring, credit, healthcare, biometrics — ISO 42001 is required outright, and suppliers who can't evidence it hit Red Status: a hard block on new Microsoft purchase orders.

We build the evidence that clears it — classified, justified, and mapped so the next questionnaire isn't a new project.

How this works for AI companies

Not sure which one you are? Most people aren't — the call sorts it in ten minutes.

Book a free 20-minute call
Free · no card · unsubscribe any time

Regulatory Watch, the free tier.

When a deadline moves, a Member State transposes, or a guideline lands, you get one email: what changed, which article, and who it actually applies to. Written from primary sources, not press releases. No spam and no drip sequence.

Paying clients get the version that matters — the same intelligence mapped to their documented systems, so you know which of your artifacts just went stale.

No card, no drip sequence. Reply "unsubscribe" any time and you're removed immediately.

Or talk about the client tier
Who you'll be talking to

The person on the call is the person accountable for the work.

Akshay Dubey, Founder and CEO of HumanAudit Inc.
Akshay Dubey
Founder & CEO

Ten years in enterprise software sales, operations and go-to-market before founding HumanAudit — Sales Director at a US SaaS company, COO of a luxury retail group, and consulting roles at Cognizant and Dell Technologies.

That background matters here for one specific reason. Most AI compliance work fails commercially, not technically. It arrives late, it's written for a regulator instead of for the procurement officer holding up the contract, and nobody translates it into something a buyer will accept. HumanAudit is built backwards from the blocked deal.

Delivery is a network model. Specialists are brought in per engagement across AI research, security, compliance and technical domains, rather than staffing a fixed bench. You are told who is working on your engagement before it starts.

2026AI For Business Specialization — University of Pennsylvania (Wharton Online)
2026AI Foundations for Business Professionals — Saïd Business School, University of Oxford
2013B.Com — DAVV University
Book 20 minutes with Akshay

What we are not

Not a law firm, not an accredited certification body, not a registered auditor. We do not issue certificates and cannot certify you. Anyone who says otherwise is selling something that doesn't exist.

We hold referral agreements with accredited certification bodies for audit support. Those are covered by NDA, so we don't publish names — and impartiality rules under ISO/IEC 17021-1 mean a body that consults for you generally cannot then certify you. We stay on the readiness side of that line deliberately and hand off to the body you choose.

Deliverables are first-draft work product. Your counsel interprets, your team validates technical accuracy, you own final sign-off. That's the correct division of responsibility and we won't blur it to close a sale.

How it runs

Four steps. Roughly an hour of your team's time.

Step 1 · 20 min

Scoping call

What's blocked, which systems are in scope, which regimes actually reach you. Often narrower than feared.

Step 2 · 30 min

Structured intake

Your AI systems, data sources, jurisdictions and existing documentation. One form, one short call.

Step 3 · days

We build

Classification, risk work, then the artifacts. Specialists brought in where the domain requires it.

Step 4

Review & handover

One revision round included. PDF, editable Word and structured JSON, yours to maintain.

Before you book

The questions people actually ask.

What does it cost?

The AI Trust Package is $3,500 fixed. Readiness Engagements are fixed-fee too, but scoped on the call, because the honest answer depends on how many AI systems are in scope, which regimes reach you, and how much already exists in writing. Regulatory Watch runs $500–1,500/month and is free for 60 days with any engagement. Firm Partnerships are $2,000–5,000/month.

No hourly billing, no scope creep, and the number is agreed in writing before work starts. For reference, the alternatives run $20,000–$80,000 for an independent consultant and from $75,000 at a Big 4 firm.

Are you lawyers? Can you certify us?

No to both, and we won't imply otherwise. We are not a law firm, not an accredited certification body, not a registered auditor. We build the documentation; your counsel interprets it and an accredited body of your choosing certifies you. If what you need is a legal opinion, we'll say so on the call.

The EU delayed the AI Act. Can't we wait?

Partly true, widely misread. Under the Digital Omnibus, Annex III high-risk obligations moved to 2 December 2027 and Annex I embedded high-risk to 2 August 2028. But Article 50 transparency obligations, Article 49 registration and national market surveillance authority powers apply from 2 August 2026, and Article 5 prohibitions plus GPAI obligations have been in force since 2025.

If you run a chatbot or ship generative features, your date did not move. And procurement doesn't wait for regulators — the questionnaire arrives when the deal arrives.

Why not just buy templates?

Sometimes you should, and we sell them — from $199. But understand what you're buying. Certification guidance is blunt about this: pre-written templates filled in with your company name will not impress an experienced auditor, because the documentation has to reflect your actual systems and your specific risks.

Buy templates if you have the internal expertise and the weeks to adapt them. Book a call if a deal is blocked or an audit is booked.

Who does the work?

Engagements are led by the founder, with specialists brought in per engagement across AI research, security, compliance and technical domains depending on scope. You're told who is working on your engagement before it begins. We don't staff a fixed bench and we don't pretend to.

What if the work isn't right?

Every engagement includes a revision round. On the toolkits there's a 7-day refund, no reason required. And when we get something wrong we correct it in public with the control IDs — the changelog above is what that looks like in practice.

Do you work outside the EU and US?

Yes, and most of our work is cross-border. The EU AI Act applies extra-territorially: if your system is placed on the EU market or its output affects people in the EU, it reaches you regardless of where you're incorporated. Microsoft SSPA obligations follow the supplier relationship, not geography.

If a call isn't the right first step

Send us the question instead.

Paste the questionnaire section that's blocking you, or describe what the auditor asked for. We'll tell you what's actually needed — including if the answer is that you don't need us.

Replies come from the founder, usually same day. Or email truth@humanaudit.ai directly.

Start here

Twenty minutes. Then you'll know.

What's actually blocked, which frameworks reach you, what it costs and how fast it moves. If we're not the right answer, we'll tell you on the call rather than sell you an engagement.

Book a free 20-minute call

20 minutes · No prep required · Straight to the founder · No obligation