AI CostGuard

EU AI Act · for the mid-market

Do you know which AI you use — and which risk class it falls into?

Over half of organisations have no AI inventory, and around 40% of systems can't be cleanly assigned to a risk class. With the transparency obligation (Art. 50, from August 2026) and the postponed high-risk deadlines (Annex III, expected December 2027), both become mandatory. Enterprise platforms are oversized and too expensive for 50–2,000-employee companies. AI-Act Radar delivers the inventory, a classification proposal and an audit-ready documentation scaffold — GDPR-compliant and from the same data collection as your cost audit.

Free self-test: gauge your AI readiness in 3 minutes →

The framework

Four risk classes — we map each of your AI applications

The EU AI Act classifies AI systems by risk. From the inventory, we assign each application to a class — with the obligations that follow.

Prohibited
unacceptable risk
Social scoring, manipulative or exploitative systems — banned.
High-risk
full obligations (Annex III/IV)
e.g. HR selection, credit, critical infrastructure — risk management, documentation, human oversight.
Limited risk
transparency obligation (Art. 50)
Chatbots, generative AI — labelling that users interact with AI or that content is AI-generated.
Minimal risk
no specific obligations
Spam filters, recommendations — voluntary codes of conduct possible.

Inventory register

Every AI application with purpose, provider, data flow and owner — the basis of any conformity statement.

Classification proposal

Assignment per the final AI Act text, with a rationale per system and the resulting obligations.

Documentation scaffold

Annex IV templates for high-risk systems and Art. 50 transparency checks — pre-filled from the inventory.

Deadlines

The AI Act timeline — staggered through 2028

The obligations apply in stages. Setting up the inventory now gives you real lead time before the relevant deadlines.

February 2025
Prohibited AI practices banned; AI-literacy obligation for staff.
August 2025
Obligations for general-purpose AI models (GPAI).
2 August 2026
Transparency obligations (Art. 50) — labelling of chatbots and AI-generated content.
2 December 2027
Stand-alone high-risk systems (Annex III) — postponed under the Digital Omnibus.
2 August 2028
High-risk as a safety component of regulated products (Annex I).

As of July 2026. The postponed high-risk deadlines are subject to the formal adoption of the "Digital Omnibus" in the EU Official Journal.

Why from a single audit

One data collection, two answers

Whoever captures every application with purpose, provider and data flow for the AI cost analysis has already gathered most of the AI-Act inventory. AI-Act Radar builds exactly on that: the same data collection answers "does our AI pay off?" and "is our AI documented compliantly?" — one appointment, one basis, two outcomes. Close to the EU legal context instead of a US enterprise tool.

How it works

To a solid basis in a few weeks

Inventory. We capture all running and planned AI applications — purpose, provider, data flow, owners.
Classify. Assignment to an AI-Act risk class, with rationale and obligations per system.
Document. Annex IV scaffold and Art. 50 transparency checks, pre-filled — plus re-audit reminders for the deadlines.
Align. You present the dossier to your legal counsel or a notified body for binding sign-off.
Important: AI-Act Radar prepares and documents — inventory, classification proposal and documentation scaffold. The legally binding classification and sign-off is done by your legal counsel or a notified body. AI CostGuard does not provide legal advice.

FAQ

The AI Act in the mid-market — briefly explained

Does the EU AI Act apply to the mid-market too?

Yes. The AI Act applies on a risk basis to providers and deployers of AI — regardless of company size. SMEs get some relief (e.g. on fees and simplified documentation), but the duty to inventory and classify risk remains.

When do which obligations of the AI Act apply?

Staggered: prohibited practices since February 2025, obligations for general-purpose AI models (GPAI) since August 2025. Transparency obligations under Art. 50 apply from 2 August 2026. For stand-alone high-risk systems (Annex III), application is expected to be postponed to 2 December 2027 under the Digital Omnibus, and for Annex I products to 2 August 2028 — subject to formal adoption in the EU Official Journal (as of July 2026).

What is an AI inventory and why is it the foundation?

A register of all deployed and planned AI systems with purpose, provider, data flow and owners. Without this inventory you can't assign a risk class or produce documentation. Over half of organisations have no such inventory today.

Which risk classes does the EU AI Act define?

Four: prohibited systems (banned), high-risk (full obligations under Annex III/IV), limited risk (transparency obligation under Art. 50) and minimal risk (no specific obligations).

What are the penalties for breaching the AI Act?

Fines of up to €35m or 7% of global annual turnover for prohibited practices, up to €15m or 3% for breaches of other obligations, and up to €7.5m or 1% for incorrect information. For SMEs, the lower amount applies.

Is AI-Act Radar legal advice?

No. AI-Act Radar prepares and documents — inventory, classification proposal and documentation scaffold. The legally binding classification and sign-off is done by your legal counsel or a notified body. AI CostGuard does not provide legal advice.

Get clarity on your AI — before the deadline.

A 30-minute call is enough to define scope and goals.

Request AI-Act Radar
AI CostGuard — a service by IT Consulting Franz Bauer · Confidential · Not legal advice · As of July 2026