AI Act compliance audit for SMEs
From 2 August 2026, the first full obligations of the AI Act take effect, starting with transparency, while the high-risk requirements arrive by December 2027. If your company uses or develops AI systems, you have concrete obligations to meet: from risk classification to technical documentation, through to disclosure towards users. Our audit tells you exactly where you stand, what's missing and what to do, with a transparent fixed cost communicated before we start.
Who needs an AI Act audit
Not only large tech companies. AI Act consultancy concerns any organisation that uses AI systems in its business processes:
- SMEs using third-party AI tools: chatbots, CV-screening systems, credit-scoring software, predictive analytics tools bought from vendors.
- Companies commissioning bespoke AI: whoever commissions an AI system is considered a "deployer" and has its own obligations, regardless of who builds it.
- Anyone using AI in high-risk sectors: HR, credit, education, critical infrastructure, security. The most stringent requirements apply here.
- Anyone using generative AI with public interaction: chatbots, voice assistants, content-synthesis tools, with a disclosure obligation from August 2026.
The three-phase process
Our AI Act audit is a service structured in three progressive steps, with a concrete, usable output at every phase:
- Phase 1, Assessment: we map every AI system in use or developed internally, classify it by risk level (prohibited, high, limited, minimal) and identify the gaps against the obligations that apply under the regulation.
- Phase 2, Compliance report: we deliver a clear document with the current status of every system, the applicable requirements and the non-conformities found, in language accessible to both the legal and the technical team.
- Phase 3, Operational roadmap: we set out the necessary interventions, prioritise them by impact and urgency and estimate the effort. The roadmap is ready to take to the board or the compliance officer without further rework.
Fixed, transparent cost
The AI Act audit is a productised offer: the scope is agreed together before we start, the cost is communicated clearly after a 20-minute call in which we work out how many AI systems are involved and the regulatory context of your organisation. No surprises at the end:
- Price communicated upfront: starting from a transparent fixed cost, defined after a 20-minute call. We never open an engagement without having agreed it.
- No open-budget hourly consultancy: the price is fixed, it doesn't depend on hours logged.
- Scope in writing: what's included in the audit and what isn't is specified in the engagement document before the start.
- Immediately usable output: the report and the roadmap come in formats that are ready to use, not raw data your team has to rework internally.
How we work
The audit runs remotely or in person, with a dedicated technical and regulatory point of contact. The process doesn't require weeks of workshops from your team:
- Initial call (20 min): we define the scope, the systems to cover and agree the fixed cost. No commitment before this point.
- Document collection: you share the technical specifications and existing documentation with us. We work asynchronously so as not to take time away from your team.
- Technical and regulatory assessment: we analyse the systems against the AI Act categories and related GDPR rules, combining the legal perspective with the technical one.
- Delivery and walkthrough: we present the report and the roadmap to your team in a dedicated session and answer every question before closing.
Why Latentia
We already support real clients in managing AI Act compliance, combining the regulatory perspective with the technical one of people who design AI systems and put them into production:
- Technical and regulatory expertise together: we don't separate the legal layer from the technology layer. Whoever runs the audit also knows how the systems work under the hood.
- EU data and GDPR: every analysis is carried out in line with European regulation. No sensitive data leaves the EU perimeter.
- No lock-in: we deliver documents that belong to you. You can continue with us on implementing the roadmap or take the work elsewhere.
- Made in Italy: in-house team, Naples. Single point of contact for the whole project, response within 24 hours.
Before you book: download the AI Act checklist for SMEs
6 sections and 17 items to check off so you can see for yourself where you stand: system inventory, risk classification, transparency and high-risk obligations. In exchange for your email.
Are you ready for the AI Act, or operating in a grey area?
In 20 minutes we work out the scope of your audit together and tell you the fixed cost before any commitment. Response within 24 hours.
Book the 20-minute callRead more
AI Act Omnibus: deadline extended to 2027 and lighter rules for SMEs
What changes with the extension, which deadlines stay fixed and what companies using AI need to do now.
Read (Italian) → ServiceAI voice agents for customer service
One of the use cases subject to AI Act disclosure: how we put voice agents into production that are compliant from day one.
Discover the service →