Build your company's AI Governance, with full autonomy
Roles, use policies, human oversight, and incident response — the structure any company using AI needs. The AI Act is today's main regulatory reference in the EU, but it's one part of the path, not the whole path.
📍 Outside the EU? This path is built around the AI Act, but it applies the same way if you offer AI systems in the EU or use their output there, wherever you're based. If your country has its own AI governance framework (like NIST AI RMF in the US), the same roles and controls give you a head start.
Does this sound familiar?
You use AI (ChatGPT, copilots, in-house models) without knowing which AI Act risk category you fall into.
There's no registry of which AI systems each team uses, or who approved them.
Nobody has defined what's allowed and what isn't when using AI with customer data.
If a regulator asked tomorrow, you wouldn't have a single document to show.
What AI Act risk level are you at?
Answer 4 questions and get an instant, indicative classification.
1. Does your AI system subliminally manipulate people's behaviour, or is it used for social scoring?
2. Does your system make or decisively influence decisions about people: hiring, credit, health, justice?
3. Is it a chatbot, content generator, or does it interact directly with people simulating a human?
4. Do you use it as internal support (analytics, productivity, internal task automation)?
Your company doesn't need to be based in the EU. The AI Act has extraterritorial scope: it applies if you offer an AI system in the European market, or if its output is used in the EU — wherever you're established.
Reference timeline after the Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026). Always check the latest official update.
The 8 layers of your AI Governance
You already know your risk level. This is how the rest gets built, layer by layer: answer the self-check and you'll see exactly what's missing.
Choose your profile
The 6 phases are the same for everyone — what changes is where you start, based on your role.
Haven't sorted out your Data Governance yet? Article 10 of the AI Act relies on that foundation: start with the Data Governance path →
/// The same result, in your handsThe same result, with full control in your hands
| Dimension | Traditional approach | AI Governance path |
|---|---|---|
| Cost | €10,000 – €40,000+ | From a single template to the full pack |
| Time | Months of back-and-forth | 8–12 weeks, at your own pace |
| Approach | Generic legal report | Ready-to-use operational templates |
| Updates | Pay again for every regulatory change | Content reviewed as the timeline progresses |
Each AI system you use may need its own risk classification and documentation — this estimates what you save by doing it with templates instead of commissioning each audit from an outside law firm.
Rough estimate. €1,200/system is an average market cost for a risk classification and technical documentation commissioned from an outside law firm. Your case may vary.
Ready-to-fill templates — buy now
What does it cost not to prepare?
This entire path in one download
Risk classification, registry, use policy, technical documentation, human oversight, GPAI, DPIA, vendor due diligence, training, and inspection kit — all 14 AI Governance products in one bundle.
No subscription · Prefer the Complete Pack (24)? →
Before you ask
Does the AI Act apply to me if I only use ChatGPT or Copilot internally?
What happens if I don't comply?
Does this replace legal advice?
Do I need to sort out my Data Governance first?
Related articles
Discover your AI Act exposure in 12 questions
Free, no sign-up. We'll tell you which obligations apply now and which come later.