AI Compliance & Data Ethics: the EU AI Act requires classifying, explaining and safeguarding. We bring structure to that as a technical partner.
the questions first.
then the code.
You set ethics at the design, not in the privacy policy.
Legal basis, origin and shelf life of every data source.
Purpose limitation as an architecture principle, demonstrable per system.
Fairness analysis for each group the model affects.
Roles and accountability, set before the build.
Explainability (XAI) as a design principle, not an appendix.
Four risk levels.
The EU AI Act classifies every AI system by risk. The higher the level, the heavier the requirements.
Manipulation, exploitation, social scoring. Fully prohibited, no exceptions.
Healthcare, HR, finance, critical infrastructure. Risk management, logging, human oversight, documentation.
Chatbots and generated content: users must know they are dealing with AI.
Spam filters, inventory models, internal tooling.
We determine together where your systems fall, and what that means for architecture, documentation and oversight.
Structure in three steps.
Risk classification & AI Act mapping
Which systems fall under which category, who is responsible, and what the regulator requires.
Compliance-by-architecture
Architecture choices that facilitate compliance rather than block it. As a technical partner, not a legal adviser.
Audit-proof documentation
Decision-making processes made transparent, traceable and explainable. Documentation that holds up in an audit.

“Compliance is not a legal document you write afterwards. It is a series of architecture choices you make at the start. Reverse that, and you build twice.”
Frank Blaauw
Co-founder Researchable
Frequently asked questions
Everything you want to know about the EU AI Act, data ethics and how we approach compliance technically.
Almost certainly. The law applies to anyone who develops, offers or uses AI systems within the EU, even if the system was bought in. The question is not whether, but which risk category your systems fall into. We determine that in the first step.
No, and that is deliberate. We are the technical partner that translates compliance requirements into architecture, system design and documentation. For legal interpretation we work with your own lawyers or external advisers: to each their own field.
No. We then start with an inventory of the existing systems: classification, data flows and where the biggest gaps are. Then we prioritise: what must happen now, what can be phased. Making existing systems adaptable is exactly the kind of technical work we are here for.
XAI makes it traceable, per decision, why a model reached an outcome. For high-risk applications that is not a luxury but a requirement: a regulator does not ask whether your model works, but why it made this decision. We build explainability in as a design principle. That is how we did it for the financial sector too.
A working dossier: risk classification per system, AI Act mapping with responsibilities, well-founded architecture choices, fairness analysis per target group and audit-proof documentation. Not an advisory report that disappears into a drawer.
They complement each other: ISO 27001 and NEN 7510 safeguard information security, the AI Act sets requirements for the AI system itself. Our own organisation is ISO 27001 certified, so the security foundation under every compliance project is already in place.
Related expertise

Leave your number and Eduard will get in touch.