Do you hold the certifications you help us achieve?
Not all of them, and we publish exactly which. We would rather tell you than have you discover it during due diligence. The current status table is in section 11 of the main site, and it distinguishes between what we help clients achieve and what we hold ourselves.
Is the EU AI Act still on the original timetable?
No, and this is the most common out-of-date assumption we meet. The Digital Omnibus on AI came into force on 27 July 2026 and moved the standalone high-risk obligations under Annex III to 2 December 2027 and the embedded high-risk obligations under Annex I to 2 August 2028. Transparency and watermarking obligations for AI-generated content apply from 2 December 2026. We re-check this timetable at every review.
We are not in the EU. Does the AI Act affect us?
Possibly, if your system is used in the EU or its output is. Territorial scope is a legal question rather than an engineering one, so we will tell you what the architecture does and where it sits, and your counsel decides whether the obligation attaches.
Can you make us compliant?
No provider can, and one that says otherwise is selling something. Compliance is a state your organisation maintains, not a deliverable we hand over. What we produce is the technical evidence, documentation and controls an assessor asks for, plus an honest list of the gaps we cannot close for you.
Do you do the audit as well?
No, and we should not. We prepare the evidence and the controls; an independent assessor certifies. A supplier who both builds the controls and signs them off is a conflict of interest you should decline.
What happens when a model provider changes something material?
It is tracked from the provider's announcement rather than discovered later. Model documentation, the sub-processor list and the risk assessment are versioned, so a change produces an update to the record instead of a silent divergence between what is documented and what is running.