For US companies serving the European market
Your AI reaches EU users.
That makes you already in scope.
Transparency obligations apply from 2 August 2026. High-risk obligations follow on
2 December 2027, deferred by the EU's Digital Omnibus. We tell you which of your systems
each one covers, close the gaps, and build the logging that proves it.
Not sure yet? Take the
two-minute scope self-check
Advice is cheap. Evidence is what regulators ask for.
Plenty of firms will explain the Act to you. Fewer can answer the question an
enforcement inquiry actually opens with: show us what this system did, when, and who
oversaw it.
For conventional software, application logs cover that. For agents — tool calls,
retrieved context, state carried across turns — they do not. The step that explains a
decision is the step standard logging throws away.
We work both halves: the regulatory judgment that sets what you owe, and the
instrumentation that produces the record.
How we build the evidence layer
The pathway
Five stages, in the order they happen.
Applicability
If your model’s output reaches users in the EU, you are likely in scope — whatever your incorporation or hosting region says. We establish that per system, in writing.
- Inventory of every AI system in your products
- Provider or deployer, per system
- Territorial scope, including indirect EU reach through US customers
Classification
Your tier decides your obligations. Get it wrong and you either over-build for a minimal-risk feature or under-build for a high-risk one. Both are expensive.
- Risk tier per system, with rationale your counsel can defend
- Annex III use-case mapping
- Transparency duties for anything user-facing
Gap assessment
Against the duties that actually attach to your tier — not a maturity model. The output is one register your engineers and your lawyers both understand.
- Quality management, data governance, human oversight
- Technical documentation to Annex IV structure
- Prioritised roadmap with effort estimates
Remediation
Most programmes stall here, because the work splits across teams that share no vocabulary. We hold both halves rather than handing you a report and leaving.
- Documentation and quality management system
- Human oversight design and escalation paths
- Incident and serious-malfunction reporting
Evidence
Logging and post-market monitoring are continuous duties, and standard application logs do not satisfy them for agents. The high-risk deferral to December 2027 is time to build this properly — not time to ignore it.
- Audit-ready traceability of agent behaviour
- Automated post-market monitoring
- Continuous evaluation against production failures
Engagements
Start narrow. Expand where the assessment says you must.
EU AI Act Exposure Assessment
Fixed scope · 2–3 weeks
Are you in scope, for which systems, at what tier, and where are you short? Delivers an inventory, classification with rationale, a gap register, and a roadmap.
Remediation Retainer
Monthly · 3–6 months typical
Execution against that roadmap: documentation, quality management, human oversight, data governance, incident reporting, conformity readiness.
Evidence Infrastructure
With Latitude.so · implementation
Traceability for multi-turn agents, automated post-market monitoring, continuous evaluation — built into your stack, not described in a slide.
Engagement detail
Who we work with
VPs of Engineering, Heads of AI, Chief Risk Officers and General Counsel at mid-market
and enterprise US companies — SaaS, FinTech, HealthTech, HR Tech — shipping AI into
Europe.
Also market-entry advisors and law firms placing clients in the EU. If you need a
defined, low-risk first step to recommend, the assessment is built for exactly that.
For advisors and counsel
Find out where you stand.
Fifteen minutes, no preparation. We will tell you whether you are in scope — including
when the answer is no.