// Research / Trust, PII & Safety

EU AI Act compliance your auditor and your DPO both want.

High-risk Annex III systems must comply by August 2026. Risk classification, technical documentation, post-market monitoring, GDPR DPIA - run by engineers who can also read the regulation, producing artifacts from your CI/CD that stay current.

// What we see

August 2026 is closing in. Most teams aren't ready.

01

Classification gets done after the system is built

Most teams discover their system is high-risk halfway through engineering, then retrofit Article 9 governance onto a stack that wasn't built for it - all visible to a competent auditor.

02

Technical documentation is written from a deck

Annex IV documentation compiled from architecture slides doesn't connect to the model registry. The supervisory authority asks where the eval results came from, and the remediation is starting over.

03

GDPR and AI Act run as parallel programs

DPIA, ROPA, transfer impact assessment, AI Act technical documentation - all overlap by design. Teams run them through different vendors, pay twice, and get two incompatible records of the same processing.

// Case Study

We trained EasyDocs' invoice extraction model

EasyDocs is the platform provider - they ship document management software to their own customers. We trained the fine-tuned NLP model that runs inside it, auto-extracting VAT numbers, totals, and addresses from invoices and learning from every user correction. Deployed on their servers, no external dependencies.

  • 98%

    field-level extraction accuracy

  • <300ms

    inference time per invoice

  • On-prem

    deployment with no external dependencies

Read the case study
We trained EasyDocs' invoice extraction model

// What we do

Three things that decide whether the documentation holds up.

Most AI Act work is consulting that produces a binder. The compliance program that survives a supervisory authority is the one where the documentation comes out of the engineering pipeline that's already running.

Risk classification before you build

Each system classified before engineering decisions calcify - a defensible position for legal and procurement.

  • Prohibited, high-risk (Annex III), limited, minimal, GPAI
  • GDPR processing-purpose lens applied alongside
  • Clear obligations attached to each system

Technical documentation from CI/CD

Annex IV is what supervisory authorities ask for - built from your pipeline so it stays current.

  • Generated from model cards, eval pipelines, registry
  • Architecture, data sources, metrics, known limitations
  • Auto-generated where possible, version-controlled where not

Post-market monitoring wired to production

Article 72 requires ongoing monitoring with reporting obligations - wired into the production system.

  • Drift detection, performance monitoring, incident classification
  • Reporting templates for national competent authorities
  • Trend analysis fed back into risk management

// Method fit

AI Act compliance work isn't the right engagement for every AI system.

skip it if

  • Your system isn't high-risk and you don't sell to the EU

    Most marketing chatbots and internal tools aren't high-risk under Annex III - outside the EU market, light-touch documentation is enough.

  • You need an ISO-certifiable management system

    If procurement wants a certifiable AI management system, ISO 42001 is the right framework - a different deliverable shape.

    ISO 42001 AI Management System
  • Your dominant concern is data privacy at the LLM boundary

    If the actual risk is customer PII reaching a third-party LLM, an egress-side redactor is faster and cheaper.

    PII Redaction & LLM Data Privacy

use it if

AI Act compliance fits when you place high-risk or GPAI systems on the EU market, buyers or regulators are asking, and the documentation layer must hold up by August 2026.

// How we work

Classify first. Document from the pipeline. Hand off the monitoring.

Every AI Act engagement starts with classification - because the obligations differ by an order of magnitude across categories. The technical work follows the classification, not the other way around.

01

Risk classification and gap assessment (week one)

Each in-scope system classified against Annex III, the GPAI rules, and the GDPR processing-purpose lens, cross-referenced with your existing artifacts. Output: a gap matrix tied to specific obligations.

02

Build the documentation layer in your stack

Annex IV technical file generated from CI/CD outputs. Risk management integrated with the model registry. DPIA and ROPA entries aligned with engineering reality - no parallel SharePoint tree.

03

Hand off the post-market monitoring

We hand off the technical file template, post-market monitoring dashboards, incident reporting playbooks for national authorities, and the management review cadence. Slack for 30 days after delivery.

Michał Pogoda-Rosikoń

// Expert insight

The AI Act isn't a parallel universe to your engineering practice - it's the documentation a competent engineering team should already produce. The teams that struggle aren't bad at compliance, they're missing the link between Annex IV and what their CI/CD already outputs. Our job is to wire those two together.

Michał Pogoda-Rosikoń

Co-founder @ bards.ai

See our open-source work

// Why bards.ai

We operate under the AI Act ourselves.

Most AI compliance work is run by lawyers without engineering depth. Most AI engineering teams skip the regulation. We do both.

EU-based, EU-regulated

A Polish company shipping AI under the AI Act and GDPR for EU and global customers - our PII research is published.

Crosswalk to ISO 42001 built in

ISO 42001 covers most AI Act management-system and technical-documentation requirements. We map them in the same engagement so you don't pay twice.

Documentation written by people who ship the systems

Everyone on your engagement has shipped AI to production under this regulation - the Annex IV file reads like an engineering document.

// FAQ

Common questions about EU AI Act compliance

No. We're not a notified body and we don't audit. For most high-risk Annex III use cases the AI Act allows internal control conformity assessment - the company self-assesses against the requirements. We help you build the documentation, controls, and evidence so that internal assessment (or, where required, a notified body's review) holds up. Audit and certification belong to accredited bodies.

Prohibited practices have been banned since February 2025. GPAI obligations have been live since August 2025. High-risk systems under Annex III: full compliance required August 2026 - three months from now. High-risk systems integrated as safety components of regulated products (Annex I): August 2027. The August 2026 deadline is not a planning horizon anymore - it is an active enforcement date. If you operate a high-risk Annex III system and haven't started the technical documentation and risk management program, you are in triage, not planning.

Two paths. Annex I covers AI as a safety component of products already regulated under EU harmonization legislation (medical devices, machinery, automotive). Annex III lists eight standalone use cases including biometric ID, critical infrastructure, education, employment, essential services (incl. credit scoring and insurance pricing), law enforcement, migration, and administration of justice. We classify against both in the gap assessment.

Heavily. AI Act Article 10 references GDPR for data governance. DPIA under Article 35 GDPR is effectively required for any high-risk AI system. ROPA entries need to capture the AI processing purpose. Lawful basis for training data is its own analysis - legitimate interest is increasingly contested for web-scraped training data after recent CJEU developments. We run AI Act and GDPR in one engagement.

// Let's ship it

August 2026 is coming. Send us your AI portfolio.

Send your AI systems and buyer geography - you'll get a risk classification, gap matrix, and roadmap to August 2026 within a business day.

Engagements from
$40K
Typical range
$40K-$150K
Duration
4-8 weeks

Fixed-fee proposal after the first scoping call. Scope drivers: number of in-scope systems, GPAI vs. high-risk obligations, GDPR work in scope.

Michał Pogoda-Rosikoń

Michał Pogoda-Rosikoń

Co-founder @ bards.ai