Step 1: Discover
We lead the discovery process, surfacing both the AI systems known to IT and those operating beneath the radar. You receive a documented AI inventory that forms the basis for everything that follows.
The EU AI Act (Regulation (EU) 2024/1689) applies to any organisation operating within the EU that develops, deploys, imports, or distributes AI systems. It introduces obligations that vary depending on the risk classification of the systems involved, with key provisions already in force.
Many organisations do not yet have a clear picture of what AI is operating across their business, let alone whether any of it falls within the Act’s scope. That uncertainty itself is the reason to act. Datapac works with organisations to establish that picture, classify their AI systems against the Act’s requirements, and put in place the governance and controls their obligations demand.
We identify the AI systems operating across your organisation, classify each against the Act's risk tiers, and give you a clear, defensible picture of where your obligations lie and what needs to change to meet them.
We lead the discovery process, surfacing both the AI systems known to IT and those operating beneath the radar. You receive a documented AI inventory that forms the basis for everything that follows.
We apply the Act’s risk classification logic to every system in your inventory, identifying prohibited and high-risk systems and mapping the specific obligations that flow from each classification.
We advise on governance design and provide the policy templates needed to establish the roles, oversight structures, and decision rights the Act requires from deployers and providers of AI systems.
We guide your teams through implementing the operational controls the Act demands, including conformity assessments, transparency notices, human oversight mechanisms, and activity logging. Your teams own the implementation.
The Act requires deployers to ensure appropriate AI literacy across their workforce. We deliver role-based training or shape your internal programme, with records that demonstrate the Act’s literacy requirement has been met.
We help establish the cadence and systems for ongoing monitoring of AI performance, serious incident reporting obligations, and regulatory developments, and remain available for periodic review as requirements evolve.
We lead the discovery process, surfacing both the AI systems known to IT and those operating beneath the radar. You receive a documented AI inventory that forms the basis for everything that follows.
We apply the Act’s risk classification logic to every system in your inventory, identifying prohibited and high-risk systems and mapping the specific obligations that flow from each classification.
We advise on governance design and provide the policy templates needed to establish the roles, oversight structures, and decision rights the Act requires from deployers and providers of AI systems.
We guide your teams through implementing the operational controls the Act demands, including conformity assessments, transparency notices, human oversight mechanisms, and activity logging. Your teams own the implementation.
The Act requires deployers to ensure appropriate AI literacy across their workforce. We deliver role-based training or shape your internal programme, with records that demonstrate the Act’s literacy requirement has been met.
We help establish the cadence and systems for ongoing monitoring of AI performance, serious incident reporting obligations, and regulatory developments, and remain available for periodic review as requirements evolve.
We identify the AI systems operating across your organisation, classify each against the Act's risk tiers, and give you a clear, defensible picture of where your obligations lie and what needs to change to meet them.
Our discovery and classification process gives your organisation a complete, accurate picture of its AI footprint and a clear understanding of exactly where its obligations under the Act lie. That clarity is the starting point for everything else.
The expectation that suppliers can demonstrate responsible AI governance is growing rapidly across both public and private sector procurement. Organisations that can evidence a structured approach to AI governance, grounded in the Act’s requirements, are better positioned to win and retain business in environments where this is increasingly a baseline requirement.
Meeting obligations under the EU AI Act is not a one-time exercise. The regulatory landscape will continue to evolve, and so will the AI systems operating in your business. Our programme is designed to leave your organisation with the governance systems, internal knowledge, and processes to manage its obligations independently over the long term, not to create a dependency on ongoing external support.
We build it, we hand it over, and it works without us.