AI Act compliance

Under the regulation, disclosing your use of AI is already mandatory. Find out whether the rule applies to your company.

The AI Act transparency rules have applied since 2 August 2026. Which of them apply to your company depends on the specific use case and on your role: provider or deployer. We determine that remotely, identify the gaps and propose an order of work.

An AI Act audit is an organisational and technical review of how artificial intelligence is used across a company: what the AI does, which role the company plays, which obligations follow, and what evidence you have to demonstrate compliance. Localize.pl runs it remotely, in three service packages: screening, full audit and ongoing support.

Scope

Does this apply to my company?

Start by checking whether you answer yes to any of the questions below:

Do you run a chatbot or voicebot on your website or helpline?
Do you publish AI-generated text, images, video or audio?
Does anyone at the company use ChatGPT, Copilot or Gemini for work, even if no one formally approved their use?
Is any AI-based tool helping you with recruitment, employee assessment or customer scoring?
Is there an AI component inside your product, even someone else’s?
Do you offer customers an AI-based tool under your own brand?
Do you analyse call recordings, support ticket content or user behaviour with AI?
Do your subcontractors, agencies or translation vendors use AI while working for you?

If you answered yes to any of these questions, look at the specific use case and at your role. Only then can you tell which AI Act obligations apply. That is where the audit starts.

Calendar

What already applies, and what is still to come

DateWhat starts to applyStatus
2 February 2025Prohibited practices and the duty to support AI literacyin force
2 August 2025Obligations for providers of general-purpose AI models (GPAI)in force
2 August 2026Transparency: AI interaction, content marking, deep fakesin force
2 December 2026End of the transition period for machine-readable marking; new prohibitionsdate unchanged
2 December 2027High-risk systems under Annex III: HR, scoring, educationpostponed
2 August 2028AI embedded in regulated products (Annex I)postponed

Deadlines for high-risk systems were postponed (Digital Omnibus, adopted by the Council of the EU on 29 June 2026). The postponement also covered use cases found in ordinary companies, such as recruitment and employee assessment. The transparency obligations remain scheduled for 2 August 2026. The AI Act is an EU regulation and applies throughout the EU; in other Member States supervision rests with their own national authorities. In Poland it is to be KRiBSI, the Commission for the Development and Security of Artificial Intelligence, established under the Act of 3 July 2026 on artificial intelligence systems (Dz.U. 2026 item 1003). The Commission is not expected to start work until late 2026, but the obligations under the regulation apply regardless of when the national authority begins operating.

Outcomes

What you receive after the audit

The report records who owns each action, what evidence is required, the deadlines and the next review dates. It is laid out as a task list you can hand straight to the people who will do the work.

Register of AI use cases

A list of AI use cases, including those hidden inside tools the company already owns, each with an owner, a classification and a next-review date. Most of the additions come from going through SaaS invoices. Nobody lists a tool in a questionnaire when it was bought for something else and only picked up an AI feature in some later update. The regulation does not explicitly require such a register, but without one it becomes much harder to demonstrate that the remaining obligations have been met.

Classification with reasoning

We record the rationale alongside each classification: why we concluded that this particular use case is not a high-risk system, and on what basis. The same Copilot can be immaterial in one department and fall under Article 50 in another. What counts is the use case.

Prioritised list of gaps

For each gap, the report records the legal basis, the required and available evidence, an owner, an estimated effort and a deadline. That makes it clear what has to be done immediately, what must be resolved before the next deadline, and what is recommended good practice rather than a legal requirement.

Ready-to-use AI disclosure notices

We prepare notices for chatbots and for AI-generated text, video and audio, in Polish and in the languages used in your target markets. Writing the notice itself usually takes a quarter of an hour. The longer job is finding a place in the chatbot where it can appear before the user’s first message. Localisation is our speciality, so this part is included in the audit.

AI policy template

The template also covers an approval procedure for new tools, so that further use cases stop appearing in the company outside the register.

A 30, 60 and 90-day plan

A sequenced plan for the remaining work, naming the people or departments responsible for each action and flagging what needs our support or a legal opinion.

Audit statement and summary for customers

A one-page statement that the audit was performed (by whom, in what scope, when and using which methodology), plus a short summary you can attach to a procurement questionnaire or a tender, without disclosing confidential details of your systems. Corporate clients usually ask for this document when they want confirmation that your company has a documented way of managing AI.

Packages

Three packages, from initial scoping to ongoing support

Screening

5 working days · up to 10 AI use cases

A limited readiness review based on the information you provide and on a sample of supporting evidence. Questionnaire, a 90-minute workshop, an initial map of roles and obligations, a list of red flags, evidence gaps, the register and a recommended scope for a further audit. The screening ends with a 45-minute review of the findings.

The five days are counted from the later of two events: the workshop, or receipt of the completed questionnaire and the agreed evidence. Screening does not confirm that the inventory of the whole organisation is complete.

Request a quote

AI Act audit

3–4 weeks · S / M / L variants

The full audit also covers supplier contracts, interactions with the GDPR and employment law, a readiness map for December 2027, and an assessment of whether any use case makes you a provider under the AI Act. That is an often-overlooked issue in agencies and IT companies that offer clients a tool under their own brand.

S covers up to 15 use cases, 3 departments and 1 legal entity; M up to 30 use cases and 6 departments. We price groups of companies, high-risk use cases and additional legal regimes separately. Scope and exclusions are confirmed in the contract before we start.

Request a quote

AI Act Monitor

monthly retainer

The law changed twice in twelve months, and the register becomes outdated even faster, because new tools arrive every month. We maintain the register, assess new tools before purchase, flag changes in the rules and run periodic reviews.

Every variant has monthly limits for requests, assessed use cases and consulting hours. The response time is 3 working days in every variant. A response means we confirm receipt and set out the next steps, not that the matter is resolved.

Request a quote

Optional, outside the audit: AI literacy training (Article 4). A remote session with materials and documentation of the activities carried out. It is available as a separate service; it is not included in any of the packages above. Training is one of several possible measures supporting AI literacy; Article 4 does not mandate a single format or an annual cycle, so we match the scope to roles and risk.

How we work

What the process requires from you

01A 20-minute call. We determine whether you need an audit and, if so, at what level. If you do not, we will say so
02NDA and contract. Scope, exclusions, rules on data processing and access, and the timeline, which starts once we receive the complete agreed set of materials
03Questionnaire. 30 to 45 minutes of your time
04A 90-minute workshop with the people who use these tools day to day
05We analyse the evidence, classify the use cases and prepare a prioritised report
06A presentation for the board plus 30 days of email support included

Data and confidentiality. We sign an NDA before any material changes hands. We work on documents inside your environment, not on copies held by us. We do not upload your data to public AI services. We do not normally record the workshop. Instead we take notes and agree them with you afterwards. Retention periods are set in the contract separately for project documentation, billing records and backups.

FAQ

Frequently asked questions

What exactly starts to apply on 2 August 2026?

The transparency obligations under Article 50: informing people that they are interacting with AI, marking generated content in a machine-readable format, disclosing deep fakes, and disclosing the use of AI in text published to inform the public on matters of public interest. That last obligation does not apply where the material has undergone human editorial review and a named person or organisation holds editorial responsibility for the publication. Systems placed on the market earlier have until 2 December 2026 for the machine-readable marking itself.

What applies on 2 August if we only use other people’s tools?

Article 50 has four paragraphs and each addresses a different role. The duty to disclose AI interaction and the duty to apply machine-readable marking to generated content sit with the provider of the system. As a company using an off-the-shelf tool you are responsible above all for disclosing deep fakes, informing people about emotion recognition and, as a matter of due diligence, for checking whether your tools mark content and whether your editing process strips that marking. There is one case that is easy to miss: if you offer someone else’s tool to your own customers under your brand, as your product or service, you may yourself act as the provider. The provider’s duties then pass to you as well, namely disclosing AI interaction and applying machine-readable marking.

We are a small company and we only use ChatGPT. Does that count?

Yes. Company size does not exempt you from the obligations. It does affect the level of fines, because for SMEs the lower of the two amounts applies. Using ChatGPT means deploying an AI system within the meaning of the regulation. At a minimum, keep a register of tools, rules on what data may be entered into them, and documented measures supporting your team’s AI literacy. If that is all there is, a screening may be enough.

Is emotion analysis in a call centre prohibited?

It depends on whose emotions the system is intended to infer and from what data. The prohibition in Article 5 covers emotion recognition in the workplace and in educational institutions, meaning employees, candidates and students. Analysis concerning customers does not as a rule fall under that prohibition, but it is subject to the duty to inform those people (Article 50(3)) and to the GDPR. It also matters whether the system infers emotions from biometric data or analyses the content of the transcript itself. We assess each case separately.

Have the obligations for high-risk systems been cancelled?

Cancelled no, postponed yes: Annex III to 2 December 2027, Annex I to 2 August 2028. Preparing documentation for such a system can take more than a year, so it is worth drawing up a readiness map now.

What are the fines?

Up to EUR 35 million or 7% of worldwide turnover for prohibited practices under Article 5 only; up to EUR 15 million or 3% for most other infringements, including the transparency obligations under Article 50; up to EUR 7.5 million or 1% for supplying incorrect, incomplete or misleading information to a notified body or a national competent authority in reply to a request. For SMEs the lower of the two amounts applies. The 7% threshold is often quoted as "the AI Act fine", but it covers the narrowest category of infringements.

Will the audit protect us from a fine?

There is no guarantee, and nobody honest will give you one. A report and a register help demonstrate that action was taken, and an authority may take that into account when setting a penalty, alongside cooperation and the circumstances of the case. An inspecting authority sets out to assess what the company actually did and what it can show to prove it.

What do we get to show a customer or a tender panel?

An AI Act readiness review report, which is a working document for you. The statement is a short document setting out the scope of the audit, the date, the methodology used, the details of the person who ran it and the legal position as of that date. And a short summary you can attach to a procurement questionnaire or a tender, without disclosing confidential details of your systems. The statement confirms that an audit was carried out in a defined scope, and that is all it can confirm.

Will I get a certificate of conformity?

No consultancy can issue a certificate of AI Act conformity, ourselves included. Conformity assessment is a formal procedure under the regulation, carried out for high-risk systems by the provider or by a notified body, ending in a declaration of conformity and CE marking. The rules also do not provide for a certificate covering a company as a whole, because the procedure in the regulation applies to a single system only. What you do receive is the report, the statement that the audit was performed, and the summary for customers and tender processes. If you need a certificate issued by a third party, the right route is the ISO/IEC 42001 standard and an accredited certification body; we can prepare you for it.

Is the audit legal advice?

No. The audit is organisational and technical in nature. Where a provision needs legal interpretation, we say so explicitly, record it in the report and recommend an opinion from a qualified lawyer.

Why does an AI implementation company run compliance audits?

Because compliance starts with the question of where the AI is actually running. You find the answer in integrations, in tool settings and in SaaS invoices. We know these tools from the inside: automations in n8n or Make, AI features slipped into systems bought two years ago for an entirely different purpose. So the inventory has to begin with the invoices and with real conversations in each department. The official list of tools comes somewhere further down the line. That is how we find things that appear neither in the contracts nor in the record of processing activities. Second, we close some of the gaps ourselves. A chatbot notice is one sentence in the interface, content marking is a change in the video production pipeline, and the disclosures still have to be translated into every language you sell in. Localisation has been our daily work for years, so that last part comes with the job.

How much does it cost and how much of our time will it take?

We quote after a short call, because the price depends on the number of AI use cases, departments and legal entities in the group. We do not publish ranges up front, so as not to sell you a scope you do not need, nor to underprice the work before we know its scale. The call is free and non-binding; if we conclude afterwards that you do not need an audit, we will say so. On your side, a screening takes around three hours in total, and a full audit six to ten hours over a three- to four-week period, plus the time of people from individual departments for interviews.

Do you work with companies across the EU?

Yes. The whole process is remote and can be delivered in English or Polish: online meetings, documents in your environment, electronic signatures. We work with companies operating on the EU market; where national supervision matters, we take account of the relevant Member State and its authority.

Want to establish which AI Act obligations apply to your company?

In a free call we go through your AI use cases and determine whether you need a full audit, a screening, or only a targeted fix.

Book a call