A scoped assessment of your AI systems, controls and governance against the obligations that apply to your estate and your role in the value chain.
Bring the systems and use cases you know about, the entities and jurisdictions involved, current documentation and the teams that own them. FenxLabs agrees the system count and assessment boundary before work begins.Scoped to your requirements and quoted per engagement.FenxLabs provides technical and operational readiness assessment. It does not provide legal advice, certify compliance or perform a required conformity assessment.
The AI Omnibus moved the application date for Annex III high-risk systems to 2 December 2027 and for high-risk systems embedded in Annex I products to 2 August 2028.
Other AI Act provisions are already applicable, including Article 50 transparency obligations from 2 August 2026. GDPR obligations remain separate.
The AI Act already applies in material parts. Market-surveillance and enforcement powers are in force, while the high-risk regime has later application dates.
Provider, deployer, importer and distributor duties differ. Certain changes under Article 25 can move provider responsibility. The assessment maps a preliminary role for each system; legal counsel validates the interpretation.
Documentation, logs, risk records and oversight evidence need to reflect how a system was actually designed and operated. Starting the inventory and evidence review early exposes gaps while they can still be addressed.
Non-compliance with prohibited AI practices can attract administrative fines up to EUR 35 million or, for an undertaking, up to 7 percent of total worldwide annual turnover for the preceding financial year, whichever is higher.
This is the maximum for prohibited practices. It is not the penalty for every infringement.The engagement starts with an agreed system count and ends with work ordered by what has to happen first.
Findings are recorded against the provision they relate to, with severity, so the remediation plan can be worked rather than interpreted.
A readiness assessment is one input to a compliance position. These four responsibilities stay separate throughout, and the report names the items that need legal validation.
Technical and operational assessment, evidence review, findings and prioritised readiness roadmap.
Policy, process, documentation, system ownership, training and implementation decisions.
Legal interpretation, final operator-role advice and confirmation of applicable obligations.
Formal conformity assessment or certification activity, where required.
FenxLabs delivers a technical and operational readiness assessment. It is not a law firm, notified body or conformity assessment body. Legal interpretation and conformity assessment remain with counsel and, where required, an authorised body.
The Regulation phases in through 2028, and its timeline has already moved once. A single assessment shows where you stand today. An ongoing arrangement keeps that current as more of it takes effect.
Inventory, role mapping, classification, controls and evidence review for the systems you bring to the scoping call. A one-off engagement, scoped once and closed with a report.
Quarterly reassessment and change review. Readiness stays current as the Regulation and your own estate both keep moving.
An assessment may find that people, applications and agents need consistent controls over the models, tools and approved data they can access. ARC can implement that model-layer part of the plan.
ARC can support model-layer governance and evidence. It does not implement every organisational, legal, documentation, training, risk-management or conformity obligation an assessment identifies.
The readiness assessment does not require you to purchase ARC.
Prohibited-practice rules and AI literacy provisions began applying.
Governance rules, obligations for general-purpose AI models and relevant penalty provisions began applying.
The Regulation became generally applicable, including Article 50 transparency obligations, subject to its specific exceptions and transition rules.
Chapter III high-risk obligations apply to systems classified under Article 6(2) and Annex III.
Chapter III high-risk obligations apply to systems classified under Article 6(1) and Annex I.
Thirty minutes with an engineer. Your numbers. A straight answer.