Skip to main content
Image coming soon

EU AI Act Compliance Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
EU AI Act Compliance for Product and Legal Teams · classify the system, meet the transparency and marking duties, keep the classification honest · Evidence & Implementation Kit
Own AI Act compliance as a product and legal team: settle scope and your role for each system, classify it into the right risk tier from use and placement, screen features against the prohibited practices before you build, implement the transparency and content-marking duties as real requirements, and keep the classification current after launch with monitoring and named ownership.
Every control handed to you adopt-ready, from scope and risk-tier classification through the prohibited and high-risk obligations, the transparency and disclosure duties, and the content marking and provenance, to the technical documentation and records and the post-market monitoring and governance a product team, legal or a conformity assessor can follow.
Ready in a weekend, not a quarter.

Here is the honest situation. Here is the honest situation. The AI Act does not ask how clever your model is. It asks what your system does, to whom, and in what setting, and it assigns duties by the risk that answer implies, which is why the obligations land on product and legal directly and why the hardest ones are decided by design choices made long before launch. Most teams meet the Act as a compliance panic once a launch is already committed, and they misjudge the tier because tier is driven by use and placement, not by how advanced the model is. Misclassify a system and you either overbuild for a tier you are not in or, far worse, ship a high-risk system with none of the controls it required. Doing this well does not mean buying tooling. It means rebuilding the judgement: settle scope and your role, work the risk ladder from the prohibited check down to a written tier, screen features against the banned practices at the concept stage, apply the high-risk regime as real build items, place the transparency disclosures where users meet them, mark AI-generated content both for people and for machines, version the documentation and logging with the system, and run a monitoring loop that keeps the tier honest as the product changes. Where teams fall short is predictable: scope assumed away, tier driven by model capability, prohibited designs caught late, human oversight that is a button no one uses, disclosures buried in a policy, no machine-readable marking, documentation reconstructed under deadline, and a launch classification filed and forgotten.

This Kit removes the guesswork. It is EU AI Act compliance written as adopt-ready controls you personalize in a weekend, with the evidence a product review, a legal sign-off or a conformity assessor examines.

What you get, the moment you buy

18
Controls, adopt-ready. Every control, written so you personalize and apply it.
18
Evidence-they-examine checklists. For each control, exactly what a reviewer examines, plus where teams fall short, so you close the gap first.
1
Control Matrix, pre-built. Every control in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each control and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the EU AI Act's risk-based structure applied to how product and legal teams actually build and ship: scope and provider or deployer roles, the risk tiers from prohibited through high-risk to transparency duties and minimal-risk, the transparency and content-marking obligations, machine-readable provenance, technical documentation and logging, and post-market monitoring. Editable Word and Excel files. This is a practitioner method, not legal advice or a substitute for your own reading of the Act, your regulatory obligations and qualified counsel.

Let the tier drive the build, not the launch-day panic
A team that meets the AI Act after a launch is committed misjudges the tier and ships either overbuilt or dangerously under-controlled, and the fix is rebuilding the judgement, not more tooling. This Kit builds the scope and classification, prohibited and high-risk, transparency, content marking, documentation and monitoring controls that make shipping AI into the Union a repeatable, defensible process, with the evidence a reviewer asks for.

What one control looks like

This is the opening control, where the assessment begins. All 18 are built to this depth.

EUA-1 Determine scope and your role for every AI system SCOPE AND RISK-TIER CLASSIFICATION
Put this control in place

Require [your organization name] to record, for each AI system it develops or uses, whether the system is in scope because it is placed on the market or put into service for users in the Union, and whether the organization is acting as the provider that puts the system out under its own name or as the deployer that uses it, recognizing a company can hold both roles across different systems, so every system carries a named role and an in-scope decision before its duties are worked out.

Control note.

Scope follows where the system is placed and used, not where the organization is established, so a team outside the Union serving Union users is in scope.

Evidence a reviewer examines
  • An inventory of AI systems with an in-scope or out-of-scope decision recorded for each
  • The provider or deployer role recorded per system with the reasoning
  • Identification of systems where the organization holds both roles
  • Evidence the inventory is refreshed as new systems or uses are added
Common finding they raise: Teams assume a non-EU establishment or a vendor relationship keeps them out of scope, so systems that serve Union users or that they provide under their own name are never assessed.

Why this is not another template pack

  • The evidence is the point. A system you cannot evidence as classified, disclosed, documented and monitored is a finding waiting to land. This tells you what a reviewer or a conformity assessor examines and where teams fall short, for every control.
  • The Act's specifics built in. Provider and deployer roles, the risk ladder worked from the prohibited check down, meaningful human oversight, machine-readable content marking alongside the human-visible label, versioned documentation and logging, and re-classification triggers are written into the controls, not left generic.
  • Built on real practice, not one person's opinion, grounded in how product and legal teams translate a broad regulation into a specific, defensible build and evidence trail.
  • It compounds. This work shares its shape with AI management systems, AI risk management and data-protection governance, so it feeds your wider governance and compliance practice.

Who buys this

Product managers, legal counsel and compliance officers responsible for AI systems that serve users in the Union and who own the intended-use definition, the tier determination, the disclosure and marking builds, and the documentation and monitoring, and who have to prove their systems are classified, disclosed and defensible. Whether this is your first pass at the AI Act or a hardening pass on a system already live, you save weeks and walk in with your scope, classification, transparency, marking, documentation and monitoring controls structured.

By the end of the weekend you will have
✓  An adopt-ready control for all 18 areas
✓  A completed control matrix
✓  The evidence a reviewer examines
✓  A written risk-tier classification per system
✓  The transparency and marking duties your systems owe
✓  A readiness percentage and a fix list

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Does it cover the whole AI Act compliance problem? Yes. Scope and risk-tier classification, prohibited and high-risk obligations, transparency and disclosure duties, content marking and provenance, technical documentation and records, and post-market monitoring and governance each have their own controls with their own evidence.

Is this tied to one kind of system? No. The controls are principle-level: role and scope, risk classification, prohibited and high-risk duties, transparency, content marking, documentation and monitoring, so they apply across chatbots, generative products, decision-support systems and more, alongside your team rather than replacing it.

What if it is not for me? A 30-day money-back guarantee.

Do not let your next launch be a high-risk system shipped without its controls, a prohibited design caught after engineering built it, or a classification you cannot defend to a regulator.
Every control is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com