Procurement wants to know how you govern AI, what trained it, who oversees it, and what happens when it's wrong. Answering properly means documents you haven't written — and every week the contract sits unsigned is revenue you've already earned and can't book.
A consultant quotes $20,000–$80,000 and months. We start at $3,500 and five days.
20 minutes · No prep · We'll tell you if you don't need us
The June headlines were half right. High-risk obligations moved to December 2027. But Article 50 transparency — the part that governs AI your users interact with — did not move.
If an EU user can chat with your AI or see content it generated, you must disclose it clearly at the point of interaction. Not buried in your terms. That obligation is enforceable 2 August 2026 — and a metadata-only tag or a line in your T&Cs does not satisfy it.
Sources: EU AI Act as amended by the Digital Omnibus; Gibson Dunn & Jones Walker guidance, 2026.
An enterprise buyer's vendor review has an AI governance section. Legal can't sign until it's answered and nobody internally owns it.
DPR v12 carries 63 requirements; Section K has 18, with 15 updated. For Sensitive Use AI — hiring, credit, healthcare, biometrics — ISO 42001 is required outright. Suppliers who can't evidence it hit Red Status: a hard block on new purchase orders.
Run a chatbot or ship generative features and transparency obligations apply now. The Digital Omnibus moved high-risk to December 2027 — it did not move this.
A term sheet or an acquirer raised AI governance and regulatory exposure, and the honest answer is that nothing is written down yet.
Twenty minutes tells you which regimes actually reach you and what's genuinely in scope. Often narrower than expected.
You probably don't need a full management system this quarter. You need the specific evidence one buyer is asking for, fast enough to keep the contract alive. So that's what we sell first.
Everything the security reviewer on the other side of your deal is asking for, in the format they expect it.
The full evidence base, for when SSPA requires ISO 42001 outright or an audit is booked.
Both are fixed-fee and agreed in writing before work starts. After delivery, Regulatory Watch keeps the evidence current at $500–1,500/month — free for the first 60 days, and opt-in after. We don't auto-enrol anyone.
We start from what's actually stuck — the questionnaire, the SSPA flag, the diligence request — and work backwards to the evidence that resolves it. Not a compliance programme you don't need yet.
What's blocked, which systems are in scope, which regimes reach you.
Your AI systems, data sources, jurisdictions and existing docs. Roughly 30 minutes of engineering time.
Classification, risk register, the artifacts the questionnaire asks for, plus cross-framework mapping.
PDF, editable Word and structured JSON. Your counsel reviews, your team validates, you send it.
He was reading AIMS-06 and noticed it referenced treatment actions by identifier — TRT-001 through TRT-016 — without describing what any of them were. He was right. Compliance documentation is only worth what the vendor's honesty is worth.
We audited the whole set and found two more defects he hadn't spotted. Four risks with no treatment action at all. Two SoA back-links that didn't reconcile with the treatment plan. An auditor tracing controls would have raised both as findings.
We rebuilt the documents, shipped v2.3 free to every existing customer with a written explanation, and published the account with the control IDs so anyone can check it.
Read the full changelog →Our buyers so far are a Tokyo IP firm, a European consultancy, and a certification body — organisations whose own reputation depends on the documentation holding up.
Book a free 20-minute call →Sometimes less than you think, and we'll tell you that on the call rather than sell you a programme. The EU AI Act applies extra-territorially — if your output affects people in the EU it reaches you regardless of incorporation — but obligations depend heavily on classification. Plenty of systems are limited-risk and need transparency measures, not a full technical file.
The AI Trust Package is $3,500 fixed, delivered in five business days. Readiness Engagements are fixed-fee too but scoped on the call, since it depends on how many systems are in scope and how much already exists in writing. Regulatory Watch is $500–1,500/month afterwards, free for 60 days and opt-in after that.
No hourly billing, no scope creep. For reference: independent consultants run $20,000–$80,000 and Big 4 engagements start at $75,000.
They can, and for a short vendor form they probably should. It stops working when the buyer asks for the underlying artifacts — Statement of Applicability, risk register, technical file — because those take weeks of senior time to produce from scratch, and they're the same documents the next buyer will ask for.
No to both. We are not a law firm, not an accredited certification body and not a registered auditor. We build the documentation; your counsel interprets it and an accredited body certifies you if you pursue certification. If what you need is a legal opinion, we'll say so.
Roughly 30 minutes for intake, plus a review pass where your team validates the technical claims. We build the structure and the regulatory reasoning; you confirm the facts about your systems are right.
Often you should — ours start at $149. But certification guidance is blunt: pre-written templates with your company name dropped in won't satisfy an experienced auditor. Buy templates if you have time and expertise; book a call if a deal is blocked.
Twenty minutes on what triggered this, which frameworks reach you, and the fastest route to an answer your buyer accepts. If you don't need us, we'll tell you.
Book a free 20-minute call →20 minutes · No prep required · Straight to the founder · No obligation