ARC
Pricing
Discord
Talk to an engineerStart free
Start free
ARCby FenxLabsCollective Intelligence

Platform

  • How it works
  • Custom routing and governance
  • Use cases
  • Example architectures

Deployment

  • Hosted Platform
  • Managed Service
  • Self-hosted Licence
  • For ISVs
  • Open the portal

Services

  • Assessment and planning
  • Architecture and integration
  • Model Adaptation
  • EU AI Act readiness
  • Managed Service operations

Resources

  • Cost modeller
  • Compare approaches
  • Pricing
  • FAQ
  • Transparency
  • Get started
  • Discord community

Legal

  • Privacy notice
  • Terms and conditions
  • Sub-processors
  • Accessibility

For individuals

  • FenxChat

FenxLabs. KvK 91762782.

Herengracht 320, 1016 CE Amsterdam, Netherlands

+31 85 060 5273contact@fenxlabs.ai

© 2026 FenxLabs. All rights reserved.

EU AI Act Readiness Assessment

Stay ready as the EU AI Act evolves

A scoped assessment of your AI systems, controls and governance against the obligations that apply to your estate and your role in the value chain.

Book a scoping callSee what the report contains

Bring the systems and use cases you know about, the entities and jurisdictions involved, current documentation and the teams that own them. FenxLabs agrees the system count and assessment boundary before work begins.Scoped to your requirements and quoted per engagement.FenxLabs provides technical and operational readiness assessment. It does not provide legal advice, certify compliance or perform a required conformity assessment.

The high-risk dates moved. Readiness did not.

The AI Omnibus moved the application date for Annex III high-risk systems to 2 December 2027 and for high-risk systems embedded in Annex I products to 2 August 2028.

Other AI Act provisions are already applicable, including Article 50 transparency obligations from 2 August 2026. GDPR obligations remain separate.

Readiness starts with evidence you can still create

Enforcement is active

The AI Act already applies in material parts. Market-surveillance and enforcement powers are in force, while the high-risk regime has later application dates.

Your role changes your obligations

Provider, deployer, importer and distributor duties differ. Certain changes under Article 25 can move provider responsibility. The assessment maps a preliminary role for each system; legal counsel validates the interpretation.

Evidence cannot be created retroactively

Documentation, logs, risk records and oversight evidence need to reflect how a system was actually designed and operated. Starting the inventory and evidence review early exposes gaps while they can still be addressed.

Non-compliance with prohibited AI practices can attract administrative fines up to EUR 35 million or, for an undertaking, up to 7 percent of total worldwide annual turnover for the preceding financial year, whichever is higher.

This is the maximum for prohibited practices. It is not the penalty for every infringement.
Assess

Five phases to a prioritised plan

The engagement starts with an agreed system count and ends with work ordered by what has to happen first.

  1. 01ScopeInventory AI systems and use cases. Establish the preliminary role for each: provider, deployer, importer or distributor.
  2. 02ClassifyMap each system against the AI Act risk framework. Identify which obligations may apply, from when and under which conditions.
  3. 03AssessReview architecture, configuration, data governance, controls, documentation, logging and human oversight.
  4. 04ReportRecord observed controls, missing evidence, severity and the provision to which each gap relates.
  5. 05PlanPrioritise urgent work, readiness measures before the 2027 and 2028 deadlines, then longer-term structural improvements.

One report built to drive action

Findings are recorded against the provision they relate to, with severity, so the remediation plan can be worked rather than interpreted.

  • AI system and use-case inventory
  • Operator-role mapping, system by system
  • Preliminary risk classification
  • Applicable-obligations matrix
  • Control-and-evidence review
  • Gap register with severity ratings
  • Prioritised remediation roadmap
  • Assumptions, limitations and items requiring legal validation

Who owns which part of the work

A readiness assessment is one input to a compliance position. These four responsibilities stay separate throughout, and the report names the items that need legal validation.

FenxLabs

Technical and operational assessment, evidence review, findings and prioritised readiness roadmap.

Customer

Policy, process, documentation, system ownership, training and implementation decisions.

Legal counsel

Legal interpretation, final operator-role advice and confirmation of applicable obligations.

Authorised or notified body

Formal conformity assessment or certification activity, where required.

FenxLabs delivers a technical and operational readiness assessment. It is not a law firm, notified body or conformity assessment body. Legal interpretation and conformity assessment remain with counsel and, where required, an authorised body.

Staying current

Two ways to engage

The Regulation phases in through 2028, and its timeline has already moved once. A single assessment shows where you stand today. An ongoing arrangement keeps that current as more of it takes effect.

A single assessment

Inventory, role mapping, classification, controls and evidence review for the systems you bring to the scoping call. A one-off engagement, scoped once and closed with a report.

An ongoing arrangement

Quarterly reassessment and change review. Readiness stays current as the Regulation and your own estate both keep moving.

Where FenxARC™ can implement part of the plan

An assessment may find that people, applications and agents need consistent controls over the models, tools and approved data they can access. ARC can implement that model-layer part of the plan.

ARC can support model-layer governance and evidence. It does not implement every organisational, legal, documentation, training, risk-management or conformity obligation an assessment identifies.

The readiness assessment does not require you to purchase ARC.

Explore model governance

Dates, citation and next review

The dates, and where they come from
  1. February 2025

    Prohibited-practice rules and AI literacy provisions began applying.

  2. August 2025

    Governance rules, obligations for general-purpose AI models and relevant penalty provisions began applying.

  3. August 2026

    The Regulation became generally applicable, including Article 50 transparency obligations, subject to its specific exceptions and transition rules.

  4. 2 December 2027

    Chapter III high-risk obligations apply to systems classified under Article 6(2) and Annex III.

  5. 2 August 2028

    Chapter III high-risk obligations apply to systems classified under Article 6(1) and Annex I.

Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744.Last legal-content review: 10 August 2026. Next review: 10 November 2026. Owner: FenxLabs.
  • Regulation (EU) 2026/1744 on EUR-Lex
  • European Commission AI Act application timeline
  • European Commission high-risk-system guidance
  • European Commission Article 50 transparency guidance

Agree the scope, then the plan

Thirty minutes with an engineer. Your numbers. A straight answer.

Book a scoping callHow an engagement runs