Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Role guide · Consultant

EU AI Act for consultants and advisory firms

The market is full of AI Act services and short on people who can tell a client precisely which obligations are live, which were deferred, and which of their systems is actually caught. Precision is the differentiator, and the fastest way to lose a client is to be confidently wrong about a date.

Arts. 6(4), 25, 40, 99Reg. (EU) 2026/1744

What lands on you, and what does not

Ownership boundaries are the most useful thing to settle early. Expert analysis: the Regulation names organisations, not job titles.

ObligationYours?Note
Classification assessments as a deliverableYesArt. 6(4) artefact, dated, reasoned, signed
Gap analysis against Chapter IIIYesArticle by article, evidence-based
Annex IV file structuringYesClient fills the technical substance
Art. 27 FRIA facilitationYesDeployer-side engagement
Signing the declaration of conformityNoProvider only
Performing conformity assessmentNoInternal control is the provider's own act
Legal adviceDependsKnow your jurisdiction's rules on reserved activities

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

Four claims that cost you the room

  1. “ISO 42001 makes you AI Act compliant.” It does not. JTC 21 assessed 42001 against Article 17, found it misaligned, and wrote EN 18286 instead. Any client with in-house counsel will check. The mapping →
  2. “High-risk breaches carry €35M or 7%.” They carry €15M or 3% under Article 99(4). The 7% tier is Article 5 only.
  3. “The deadline is August 2026.” For Annex III high-risk it is 2 December 2027, and it has been since 27 July 2026. Saying otherwise dates you precisely.
  4. “We can automate your conformity assessment.” You cannot. It is a legal procedure with a named responsible party and a signed declaration. Why →

The inverse is a genuine commercial advantage: the practitioners who know that the deferral covers Chapter III Sections 1 to 3 only, that regulatory sandboxes moved to 2 August 2027, and that no harmonised standard has yet been cited in the Official Journal, are visibly more credible than the market average.

Article 25 can make your firm a provider

If you white-label a client-facing AI tool under your own brand, or you materially modify a high-risk system, or you repurpose a general-purpose AI system into an Annex III use case for a client, Article 25 may make your firm the provider of a high-risk AI system, with conformity assessment, Annex IV documentation, CE marking and registration obligations of your own.

This is not theoretical for advisory firms building accelerators, assessment tools or client portals on top of foundation models. Whether your tool is itself an AI system, and whether its purpose is an Annex III one, are questions worth answering before the tool ships rather than during a client’s audit.

Separately: a white-label licence to reuse documentation is not a transfer of regulatory responsibility. Your client remains the provider or deployer of their systems whatever your engagement letter says. Roles →

Your first 30 days

  1. Date-stamp your materials. Anything written before 27 July 2026 describes a version of the Act that no longer exists.
  2. Build the classification assessment as a productised deliverable to the Article 6(4) standard, including the profiling analysis.
  3. Lead with what is live, Article 50, Article 4, Article 49, rather than with the 2027 date. It is more useful and more urgent.
  4. Check your own tooling against Article 25 before a client does.
  5. Track the standards: EN 18286 at Approval, nothing cited in the Official Journal yet.

Questions worth asking

  • Is our own accelerator an AI system, and whose provider are we?
  • Are our client materials current as at 27 July 2026?
  • Can we state the penalty tiers correctly without checking?
  • Do our deliverables produce artefacts the client can put in a technical file?

Status labels on this page

Verified fact: Article references, dates and penalty tiers cited above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.

Expert analysis: The ownership allocation, the failure modes, and the 30-day sequence — all our practice rather than the text.

Unsettled: Harmonised standards remain in development, and the Commission's Annex III guidelines are in draft. Both affect how these obligations will be evidenced.

Next step

Partner with people who maintain the source

We publish this reference because we have to keep it accurate for our own delivery work. The documentation set behind it is licensable, and we work with advisory firms rather than around them.

Start with the inventory

Every role guide on this site converges on the same first step: a list of the AI systems, their intended purpose, their role and their tier.

Run the classifier →

Frequently asked

Can consultants perform an EU AI Act conformity assessment for a client?

No. Under the Annex VI internal control procedure the provider verifies its own quality management system and technical documentation and takes responsibility for the result, and the provider draws up and signs the EU declaration of conformity under Article 47. Advisers can prepare, structure and review the evidence, but the assessment and the declaration are acts of the provider. Where a notified body route applies, the notified body must be an accredited third party.

Can a consultancy become a provider under the EU AI Act?

Yes. Article 25 makes a party a provider of a high-risk AI system if it puts its name or trade mark on such a system, makes a substantial modification to one, or modifies the intended purpose of a system, including a general-purpose AI system, so that it becomes high-risk. Advisory firms that white-label AI tooling or build client-facing accelerators on foundation models should assess their own position.

What deliverables does the EU AI Act actually name?

The Regulation names the Article 6(4) documented classification assessment, the Article 11 and Annex IV technical documentation, the Article 17 quality management system documentation, the Article 27 fundamental rights impact assessment for certain deployers, the Article 47 EU declaration of conformity, the Article 49 registration, and the Article 72 post-market monitoring plan. Advisory deliverables that map onto these named artefacts are more defensible than generic maturity assessments.