Skip to content
gitogi
AI compliance

What the AI Act requires of your business

What AI compliance covers

The problems to solve

Sales pitches lead with fines

Your company's role is unclear

There is no record of the tools in use

What we do

We establish your role for each system

We record which tools are in use

We organise the evidence

We review how personal data is used

What we do not do

We do not issue certifications

We do not sell audits you do not need

We do not use fines to sell our services

The work your company remains responsible for

Keeping the tool inventory up to date

Making sure new users know how to use the tools

Reviewing your role and duties when uses change

The questions to start with

  • How many AI systems are in use in your company, including those accessed through personal subscriptions?
  • For each system, is your company the provider or the deployer?
  • Which of these systems process personal data about customers, staff or suppliers?
  • Do the people using them know what data they must not enter and why answers need checking?
  • If asked, could you show what you did and when?

Facts and sources

Commissione europea — AI Act, articolo 4consulted on 2026-09-20
Commissione europea — AI Literacy, domande e risposteconsulted on 2026-09-20
Commissione europea — calendario di attuazione dell'AI Actconsulted on 2026-09-20
Commissione europea — AI Act, articolo 43consulted on 2026-09-20
Gazzetta Ufficiale — legge 23 settembre 2025, n. 132consulted on 2026-09-20

Questions we often hear

Does a chatbot bought from a provider need certification?
Do staff have to take an AI training course?
When can a deployer become a provider?
Do some sectors have additional duties?
When is a data protection impact assessment needed?
What is the risk of leaving this unchecked?
Does a small business need an AI Act audit?

Tell us which AI tools you already use