All services 03 · Compliance embedded in daily work

AI Act Compliance Readiness

Know which AI obligations apply to you, and prove you meet them before a customer asks.

  • 8–10 weeks
  • ~16–18 consulting days
  • From 750,000 HUF + VAT
  • Deployer-focused

The problem

Nobody knows which articles apply to a company that just uses AI.

A customer sends a forty-question AI due-diligence form, or a tender asks how you comply with the AI Act, and the honest answer is that nobody has looked. The literacy obligation on employers has applied since February 2025 and there is no record of anything having been done about it. AI features keep arriving inside software you already licensed, without anyone reviewing the terms or asking where the data goes.

The law firm will tell you what applies. The AI vendor will tell you their product is compliant — for their product, not for your use of it. Neither of them turns any of it into a control that runs, or into evidence you can hand over. That layer is empty, and it is the layer the questionnaire is actually asking about.

And the GDPR exposure does not wait for the AI Act: a personal-data flow into an AI tool without a processor agreement is a problem today, whatever the AI Act timeline does.


Who it's for
This is a fit if
  • You use or license AI tools — including AI features inside software you already had
  • A customer questionnaire, tender, insurer or contract clause has asked how you comply
  • You supply a regulated customer whose own obligations now flow down to you
  • You have completed a Futable adoption programme and need the evidence layer beneath it
  • Up to 150 employees, up to 10 AI tools or AI-enabled systems
Who buys it
  • Managing directors; the head of legal or compliance where one exists; the CFO when a contract is at stake
  • HR is involved for the literacy records, procurement for the vendor terms, IT for the controls
  • If you build and place AI systems on the market, you are a provider not a deployer — that is quoted individually and needs counsel alongside
  • High-risk uses under Annex III and regulated sectors are quoted individually

What happens

Six steps, eight to ten weeks.

  1. Intake One week. Sponsor kick-off, and the inventory begins — every AI tool, every AI-enabled system, and the uses people actually put them to, gathered with IT and the department leads rather than assumed.
  2. Readiness assessment One to two weeks. Your regulatory role for each use — deployer, provider, or neither — an Annex III screening, the obligations that genuinely follow, and a triage of every vendor’s terms. Ends with a rated position and a prioritised plan.
  3. Scope Statement One week. Which tools and uses are in scope, which obligations will be met, which processes the controls go into, and where the Futable boundary sits. From here scope changes only by written change order.
  4. Obligation register and vendor review Two to three weeks. Each applicable article decomposed into a requirement, a control, an owner and an evidence type — and each AI tool reviewed for its data-processing position: agreement in place, data residency, training opt-out, retention.
  5. Control embedding Two to three weeks. Access, identity, logging and data-classification controls for AI tools written into your existing IT process descriptions, and the AI risks added to your risk register with owners.
  6. Sign-off and hand-over One week. Management sign-off, the evidence pack indexed, and a questionnaire response library seeded so the next customer form takes hours rather than weeks.

Premium adds implementation support with your IT or MSP, help renegotiating non-compliant vendor terms, a pre-inspection dry-run, and support answering up to three customer questionnaires from the pack.


What you get

Six documents that answer the questionnaire.

Readiness Assessment Report

Every AI tool and use identified, each with its regulatory role and reasoning, an Annex III screening, every applicable obligation rated, and a prioritised remediation plan.

Scope Statement

Entity, tools and uses in scope, obligations to be met, processes, the MSP and Futable boundaries, deliverables and dates — including any customer deadline that triggered the work.

Obligation Register

Each applicable article as a requirement, a control, an owner, an evidence type and a status. This is the document that answers "how do you comply".

Literacy & Transparency Framework

How the Article 4 literacy obligation is evidenced per role, with the first records captured — and the transparency measures that apply to you, with the actual disclosure wording and where in the process it appears.

AI Vendor & Data-Processing Review

Every in-scope tool: who the vendor is, what the terms say, whether an agreement is in place, where the data sits, whether your content trains their models, what has to change and who owns changing it.

Embedded Controls, Risk Entries & Evidence Pack

Access, logging and classification controls written into your IT processes with owners; AI risks in your risk register; and the evidence index with a response library for customer questionnaires.


Packages
  • Entry — readiness assessment The inventory, your regulatory role per use, the obligation map, the vendor triage and a rated position. Enough to answer a customer honestly and know what the gap costs. 750,000 HUF + VAT.
  • Standard — the compliance floor Everything on this page: obligation register, literacy and transparency evidence, vendor reviews, controls embedded, risks registered, evidence pack, management sign-off. 2,600,000 HUF + VAT, fixed price.
  • Premium — with implementation Standard plus control implementation with your IT or MSP, vendor renegotiation support, a dry-run, and questionnaire support. Quoted individually.
  • Custom AI providers, Annex III high-risk deployments, regulated sectors, multi-entity groups — quoted individually and with counsel.

Payment is 40% at signature, 30% at scope confirmation, 30% on the readiness report and evidence pack. Legal counsel fees, vendor fees and Futable’s services are separate.


What we need from you
  • A sponsor and a compliance or security owner
  • The list of AI tools and licences in use — or permission to establish it with your IT and MSP, since shadow use is the norm rather than the exception
  • Vendor contracts and whatever data-processing documentation exists
  • HR for the literacy records, procurement for the vendor actions
  • Decisions on vendor actions and risk treatment within five business days
What this is not
  • Not AI strategy, maturity assessment, use-case discovery, usage policy authoring, training or adoption — that is Futable’s, and we refer rather than compete
  • Not legal advice: we map obligations and build controls; formal classification and any representation before an authority need counsel you engage
  • Not conformity assessment, CE marking or notified-body work
  • Not building or modifying AI systems
  • Not a data protection impact assessment — we identify where one is required

Next step

Before the next questionnaire arrives.

The assessment takes about two weeks and ends with a written position you can hand to a customer. If it turns out almost nothing applies to you, that is also a useful thing to have in writing.