Legal won't sign. Procurement won't move. Every week it sits there is revenue you've already earned and can't book. A consultant quotes $20,000–$80,000 and eight weeks. Big 4 starts at $75,000. A $199 template pack won't survive an auditor tracing a control.
We build the evidence that unblocks it — fitted to your systems, in days, at a fixed fee agreed before we start.
20 minutes · No prep · Straight to the founder · We'll tell you if you don't need us
Every headline in June said the same thing: the EU delayed the AI Act. Boards heard “delayed” and stood their programmes down. Most of them read it wrong.
The Digital Omnibus moved the high-risk regime (Annex III) to December 2027. That part is real. But Article 50 — the transparency layer that governs chatbots, generative features and synthetic media — was deliberately left untouched. It applies from 2 August 2026 regardless of your risk tier.
If a user in the EU can talk to your AI or see content it generated, your date did not move. It is enforceable 2 August 2026.
| Obligation | Who it hits | Date |
|---|---|---|
| Article 50 transparency | Chatbots, generative content, deepfakes | 2 Aug 2026 |
| Article 50(2) watermarking | Systems already in market | 2 Dec 2026 |
| Annex III high-risk | HR, credit, biometrics, essential services | 2 Dec 2027 |
| Annex I embedded high-risk | AI inside regulated products | 2 Aug 2028 |
Sources: Regulation (EU) 2024/1689 as amended by the Digital Omnibus (Parliament 16 Jun 2026, Council 29 Jun 2026); Gibson Dunn, Jones Walker, DLA Piper client guidance, 2026. Article 50(2) applies to new systems on placement.
20 minutes. We'll tell you which obligations apply — and if none do, we'll say that too.
ISO/IEC 42001 was published in December 2023. The market that grew around it went straight to two extremes and skipped the middle entirely.
| Option | What it costs | Why it fails |
|---|---|---|
| Template packs | $150–$1,500 | Generic by construction. A certification-industry guide puts it plainly: a set of pre-written templates with your company name dropped in will not impress an experienced auditor — the documentation has to reflect your systems and your risks. |
| Independent consultant | $20,000–$80,000 | Gap assessment alone runs $5,000–$15,000. Then 4–9 months on their calendar. Priced past most teams before the first document exists. |
| Big 4 / large consultancy | From $75,000 | Enterprise engagements run $75,000–$250,000+. And the standard is two years old — the large firms are learning it in real time, on your budget. |
| HumanAudit | Fixed fee, agreed first | The documents fitted to your systems, in days, priced in writing before work starts. Not a template with your logo. Not a five-figure retainer. |
Ranges are published industry estimates from certification consultancies and compliance platforms, 2026. They vary by scope, number of AI systems, and existing ISO 27001 maturity. We cite them because the gap between the two ends is the entire reason this company exists.
Twenty minutes tells you which regimes actually reach you, what's in scope, and roughly what it costs. Often the answer is narrower than expected.
Compliance evidence isn't a one-time artifact. Systems change, models get retrained, regulations move, staff turn over. Most vendors sell you a document and disappear. We price for the whole lifecycle.
For the deal that's stuck right now. Everything your buyer's security reviewer needs, in the format they expect.
The full evidence base. Statement of Applicability, risk register, impact assessments, technical file — fitted to your systems.
Documentation decays. When a regulation moves, you find out what changed in your artifacts — not just that something changed.
Unlimited white-label artifact generation for your client engagements, priority turnaround, co-branded templates, and a quarterly regulatory briefing for your team. One relationship instead of one engagement at a time.
Not a dashboard. Not a maturity score. The artifacts a Stage 1 reviewer opens first — where every control carries a justification and every risk carries a treatment action that actually exists.
| Control | Decision | Justification |
|---|---|---|
| A.2.2 | Included | AI policy approved by the board 14 Mar 2026. Reviewed annually and on material change to any in-scope system. |
| A.4.2 | Included | Resource inventory covers 3 in-scope systems. Compute, data and human oversight roles documented per system. |
| A.5.4 | Included | Impact assessment completed for the hiring-recommendation model. Article 27 FRIA elements (a)–(g) addressed. |
| A.10.3 | Excluded | No third-party model providers in scope as of this revision. Reassess on procurement of any external model. |
| Risk | Action | Treatment |
|---|---|---|
| RISK-004 | TRT-007 | Demographic drift in candidate scoring. Quarterly fairness evaluation against protected-attribute proxies; owner: Head of ML. |
| RISK-009 | TRT-011 | Undisclosed AI interaction. Article 50 disclosure implemented at first response in the chat surface; owner: Product. |
| RISK-012 | TRT-014 | Serious-incident reporting exceeds statutory window. Article 73 escalation path with 2 / 10 / 15-day tiers; owner: Legal. |
| RISK-017 | TRT-016 | Silent model update bypasses review. Change-management gate requires re-assessment before deployment; owner: Eng. |
Illustrative extracts using representative content, formatted exactly as delivered. Your documents carry your systems, your risks, your owners and your dates. Delivered as PDF, editable Word and structured JSON.
A director at a European consultancy was reading AIMS-06 and noticed it referenced treatment actions by identifier — TRT-001 through TRT-016 — without describing what any of them were. He was right.
We audited the whole set and found two more defects he hadn't spotted. Four risks with no treatment action at all. Two SoA back-links that didn't reconcile with the treatment plan. An auditor tracing controls would have raised both — as findings against his client's management system, not against our documentation.
We rebuilt the documents, shipped v2.3 free to every existing customer with a written explanation, and published the account with the control IDs so anyone can check it.
Read the full changelog →Our buyers so far are a Tokyo IP firm, a European consultancy, and a certification body — organisations whose own reputation depends on the documentation holding up. That is the reference we'd want if we were you.
A compliance document doesn't fail visibly. It looks correct right up until an assessor follows a control back to a treatment action that was never written. By then it's in your engagement, under your name.
So we automated the exact check that caught us. Every deliverable is machine-traced before a human reviews it, and again before it ships.
Every check in that list exists because we failed it once. The changelog above is the receipt.
Book a free 20-minute call →Over 60% of corporate legal teams expect to rely less on outside counsel. Firms without a demonstrable AI capability are structurally exposed — but building one means either hiring into a two-year-old discipline or writing off the first month of every engagement.
We are the artifact layer under your brand. Your template, your file naming, your sign-off. Your client never needs to know we exist.
SSPA DPR v12 carries 63 requirements; Section K covers AI systems with 18, of which 15 were updated. For Sensitive Use AI — hiring, credit, healthcare, biometrics — ISO 42001 is required outright, and suppliers who can't evidence it hit Red Status: a hard block on new Microsoft purchase orders.
We build the evidence that clears it — classified, justified, and mapped so the next questionnaire isn't a new project.
Not sure which one you are? Most people aren't — the call sorts it in ten minutes.
Book a free 20-minute call →When a deadline moves, a Member State transposes, or a guideline lands, you get one email: what changed, which article, and who it actually applies to. Written from primary sources, not press releases. No spam and no drip sequence.
Paying clients get the version that matters — the same intelligence mapped to their documented systems, so you know which of your artifacts just went stale.
No card, no drip sequence. Reply "unsubscribe" any time and you're removed immediately.
Ten years in enterprise software sales, operations and go-to-market before founding HumanAudit — Sales Director at a US SaaS company, COO of a luxury retail group, and consulting roles at Cognizant and Dell Technologies.
That background matters here for one specific reason. Most AI compliance work fails commercially, not technically. It arrives late, it's written for a regulator instead of for the procurement officer holding up the contract, and nobody translates it into something a buyer will accept. HumanAudit is built backwards from the blocked deal.
Delivery is a network model. Specialists are brought in per engagement across AI research, security, compliance and technical domains, rather than staffing a fixed bench. You are told who is working on your engagement before it starts.
Not a law firm, not an accredited certification body, not a registered auditor. We do not issue certificates and cannot certify you. Anyone who says otherwise is selling something that doesn't exist.
We hold referral agreements with accredited certification bodies for audit support. Those are covered by NDA, so we don't publish names — and impartiality rules under ISO/IEC 17021-1 mean a body that consults for you generally cannot then certify you. We stay on the readiness side of that line deliberately and hand off to the body you choose.
Deliverables are first-draft work product. Your counsel interprets, your team validates technical accuracy, you own final sign-off. That's the correct division of responsibility and we won't blur it to close a sale.
What's blocked, which systems are in scope, which regimes actually reach you. Often narrower than feared.
Your AI systems, data sources, jurisdictions and existing documentation. One form, one short call.
Classification, risk work, then the artifacts. Specialists brought in where the domain requires it.
One revision round included. PDF, editable Word and structured JSON, yours to maintain.
The AI Trust Package is $3,500 fixed. Readiness Engagements are fixed-fee too, but scoped on the call, because the honest answer depends on how many AI systems are in scope, which regimes reach you, and how much already exists in writing. Regulatory Watch runs $500–1,500/month and is free for 60 days with any engagement. Firm Partnerships are $2,000–5,000/month.
No hourly billing, no scope creep, and the number is agreed in writing before work starts. For reference, the alternatives run $20,000–$80,000 for an independent consultant and from $75,000 at a Big 4 firm.
No to both, and we won't imply otherwise. We are not a law firm, not an accredited certification body, not a registered auditor. We build the documentation; your counsel interprets it and an accredited body of your choosing certifies you. If what you need is a legal opinion, we'll say so on the call.
Partly true, widely misread. Under the Digital Omnibus, Annex III high-risk obligations moved to 2 December 2027 and Annex I embedded high-risk to 2 August 2028. But Article 50 transparency obligations, Article 49 registration and national market surveillance authority powers apply from 2 August 2026, and Article 5 prohibitions plus GPAI obligations have been in force since 2025.
If you run a chatbot or ship generative features, your date did not move. And procurement doesn't wait for regulators — the questionnaire arrives when the deal arrives.
Sometimes you should, and we sell them — from $199. But understand what you're buying. Certification guidance is blunt about this: pre-written templates filled in with your company name will not impress an experienced auditor, because the documentation has to reflect your actual systems and your specific risks.
Buy templates if you have the internal expertise and the weeks to adapt them. Book a call if a deal is blocked or an audit is booked.
Engagements are led by the founder, with specialists brought in per engagement across AI research, security, compliance and technical domains depending on scope. You're told who is working on your engagement before it begins. We don't staff a fixed bench and we don't pretend to.
Every engagement includes a revision round. On the toolkits there's a 7-day refund, no reason required. And when we get something wrong we correct it in public with the control IDs — the changelog above is what that looks like in practice.
Yes, and most of our work is cross-border. The EU AI Act applies extra-territorially: if your system is placed on the EU market or its output affects people in the EU, it reaches you regardless of where you're incorporated. Microsoft SSPA obligations follow the supplier relationship, not geography.
Paste the questionnaire section that's blocking you, or describe what the auditor asked for. We'll tell you what's actually needed — including if the answer is that you don't need us.
Replies come from the founder, usually same day. Or email truth@humanaudit.ai directly.
What's actually blocked, which frameworks reach you, what it costs and how fast it moves. If we're not the right answer, we'll tell you on the call rather than sell you an engagement.
Book a free 20-minute call →20 minutes · No prep required · Straight to the founder · No obligation