EU AI Act Advisory

Aug 2026 is not a deadline — it is the operational floor.

The EU AI Act is the regulatory floor. An AI Management System (AIMS) is the operating system that makes the floor walkable. Axiom Advisory builds the AIMS first, then overlays the five conceptual gaps the Act assumes but never defines — so your Article-by-Article readiness holds up under Annex III enforcement and under audit.

Annex III high-risk obligations begin enforcement August 2026. The conformity clock starts now — not at certification, not at notified-body engagement, but at first production deployment.

What the advisory covers.

Four advisory tracks, each anchored by an AIMS and exit-conditioned on Article-by-Article survivability under Annex III enforcement.

01

Gap analysis — For organizations with no formal AI governance posture — scopes the AIMS, the Annex III high-risk classification, and the third-party landscape in a single deliverable.

02

AIMS overlay — For organizations holding (or building) ISO 42001 — extends the existing AIMS into Article-by-Article conformity, with the five conceptual gaps overlaid as a continuous integrity layer.

03

Article 14 readiness — For high-risk AI teams shipping production models — interrogates who can interrogate the system, what "effective oversight" means in concrete terms, and how escalation actually fires.

04

Third-party diligence — For organizations deploying third-party or foundation-model AI — closes the diligence loop upstream where the Act places the conformity burden.

01

Annex III classifier ambiguity — does your classifier treat "biometric categorization" and "emotion recognition" as overlapping categories when the Act treats them as distinct obligations?

02

Data-governance provenance under Article 10 — when training data crosses jurisdictional boundaries, does your AIMS know what "relevant" and "representative" mean in each downstream context?

03

Effective human oversight under Article 14 — the Act assumes a reviewer who can interrogate the system; your AIMS must define what that interrogation looks like for non-technical oversight bodies.

04

Substantial-modification tracking — when does a model update constitute a "substantial modification" triggering re-conformity? The Act defines the trigger; your AIMS must define the detection.

05

Cross-Annex interoperability — a system may satisfy Annex III (high-risk) and Annex IV (technical documentation) simultaneously — the AIMS must broker what each Annex demands without fragmenting the operational view.

AIMS as foundation, five gaps as overlay.

We build the AIMS first — the operating system for AI governance — then overlay the five conceptual gaps the Act assumes but never defines. The order matters: overlay-without-foundation is paper; foundation-without-overlay is conformity theater.

01

Conceptual inventory. Map the terms your AI systems actually rely on — "fairness," "ground truth," "drift," "oversight" — and the disagreements between teams over what those terms mean.

02

AIMS build. Construct the AI Management System as a living system: risk treatment register, competency framework, policy harmonization, and the conceptual commitments that bind them.

03

Annex III overlay. Map every high-risk obligation onto the AIMS as Article-indexed controls, with the five conceptual gaps inherited from across the project.

04

Article 14 hardening. Engineer the human-oversight pathway so a non-technical oversight body can actually interrogate the system — not checkbox, principle.

05

Audit rehearsal. Walk the conformity register against Annex IV documentation requirements and a notified-body-style challenge, before the August 2026 clock runs out.

Packages and timeline.

Indicative ranges from current EU AI Act Annex III readiness work. Scope is the dominant variable — not org size.

SMB

$40K — $75K

Article-by-Article Annex III mapping for a single product line and one production AI system. Gap-analysis deliverable + remediation playbook for one AI deployment cycle.

Mid-market

$90K — $180K

Multi-Annex coverage (Annex III + Annex IV) with policy harmonization across business units shipping AI. Includes data-governance provenance register and substantial-modification detection framework.

Enterprise

$400K — $800K

Group-wide jurisdictional overlay — EU AI Act + Member-State implementing rules + sectoral + cross-border. Includes Article-by-Article conformity register, integrated third-party diligence, and a board-grade readiness posture report.

20–30%   Annual surveillance audits run 20–30% of the initial certification cost — budget this as recurring operating expense, not a one-time project.

P0

Phase 0 — Scoping. Annex III classification + advisory-track selection. Deliverable: readiness backlog with prioritized Article obligations.

P1

Phase 1 — AIMS build. Conceptual inventory and AI Management System construction. Deliverable: living AIMS with conceptual commitments recorded.

P2

Phase 2 — Annex III overlay. Article-by-Article obligations mapped onto AIMS controls. Five conceptual gaps overlaid as continuous integrity layer.

P3

Phase 3 — Audit rehearsal. Notified-body-style challenge against Annex IV documentation and conformity register. Deliverable: audit-ready posture for August 2026.

~70

high-risk obligations across Annex III categories

65%

of EU AI Act readiness tasks remain unaddressed by current ISO 42001 implementations

The market is not "ISO 42001 vs. EU AI Act" — it is ISO 42001 plus the conceptual layer the Act assumes. Buyers want a single adviser who can build the AIMS, overlay the Article obligations, and defend both under Annex III enforcement.

Get in touch about the EU AI Act.

Tell us where you are relative to the August 2026 deadline. We respond from axiom-advisory@polsia.app within two business days.