Service · Compliance
Regulation & Compliance — AI Act · DORA · KSC/NIS2 · PLD
Four regulations, one overlapping set of obligations. We help build compliance that actually protects the organization — not just documentation that looks good in a drawer.
Regulatory scope
- AI Act — risk-based classification of AI systems, provider vs. deployer obligations, requirements under Art. 4 (AI literacy), Art. 5 (prohibited practices), and Art. 50 (transparency of AI-generated content).
- DORA — ICT risk management for the financial sector, requirements for third-party providers, including AI systems.
- KSC law / NIS2 — obligations for essential service operators and critical infrastructure providers, registration, supply-chain obligations.
- PLD (Product Liability Directive) — civil liability for products with a software/AI component, including defects arising from model behavior.
How we work
We start with a regulatory map for your industry and scale of operations — not every regulation applies to every organization to the same degree. We then build concrete compliance artifacts: an AI system register, risk documentation, human oversight procedures, and evidence you can point to in an audit or liability dispute.
Who it's for
For banks, insurers, IT providers, and essential service operators who fall under several of these regulations at once and need a coherent approach to compliance, not a fragmented one.
Check your regulatory exposure
Book a call — we'll help you figure out which regulations actually apply to you and what to tackle first.
Contact us →