The EU AI Act's technical requirements — logging, human oversight, traceability — describe things a system must actually do, not just document. Most compliance work stops at policy templates. This is about verifying whether your inference pipeline can produce the receipts the Act describes.
A common gap: a company has the policy documents, but no way to prove — for any single past output — what version of the model produced it, what inputs it saw, or whether a human reviewed it.
Mapping your system's actual logging, oversight, and traceability against the Act's technical requirements, then closing the specific gaps found — not delivering a generic checklist.
Related real work:
trust-scoring for clinical AI, a domain the Act treats as high-risk
a clinical AI system built with auditability in mind
No. This is technical verification work aligned with the Act's requirements, not a legal compliance guarantee. Legal sign-off is a separate function from a lawyer or compliance officer.
Standard audits review documentation. This verifies the actual system — whether it can reproduce a past inference result, whether oversight is enforced in code, not just described in a policy.
Access to your technical documentation and a diagnostic call about what needs verifying and why it matters to your specific system.