AI Compliance & Data Ethics: the EU AI Act requires classifying, explaining and safeguarding. We bring structure to that as a technical partner.

the questions first.
then the code.

You set ethics at the design, not in the privacy policy.

Which data may you use?

Legal basis, origin and shelf life of every data source.

For what purpose?

Purpose limitation as an architecture principle, demonstrable per system.

Are the outcomes fair?

Fairness analysis for each group the model affects.

Who is responsible?

Roles and accountability, set before the build.

How do you explain it to a regulator?

Explainability (XAI) as a design principle, not an appendix.

Four risk levels.

The EU AI Act classifies every AI system by risk. The higher the level, the heavier the requirements.

unacceptable
Our focus
high risk
limited risk
minimal risk
prohibitedunacceptable risk

Manipulation, exploitation, social scoring. Fully prohibited, no exceptions.

Our focusstrict requirementshigh risk

Healthcare, HR, finance, critical infrastructure. Risk management, logging, human oversight, documentation.

transparency obligationlimited risk

Chatbots and generated content: users must know they are dealing with AI.

no extra requirementsminimal risk

Spam filters, inventory models, internal tooling.

heaviest requirementsno requirements

We determine together where your systems fall, and what that means for architecture, documentation and oversight.

Structure in three steps.

01

Risk classification & AI Act mapping

Which systems fall under which category, who is responsible, and what the regulator requires.

02

Compliance-by-architecture

Architecture choices that facilitate compliance rather than block it. As a technical partner, not a legal adviser.

03

Audit-proof documentation

Decision-making processes made transparent, traceable and explainable. Documentation that holds up in an audit.

Frank Blaauw

“Compliance is not a legal document you write afterwards. It is a series of architecture choices you make at the start. Reverse that, and you build twice.”

Frank Blaauw

Co-founder Researchable

Frequently asked questions

Everything you want to know about the EU AI Act, data ethics and how we approach compliance technically.

Almost certainly. The law applies to anyone who develops, offers or uses AI systems within the EU, even if the system was bought in. The question is not whether, but which risk category your systems fall into. We determine that in the first step.

No, and that is deliberate. We are the technical partner that translates compliance requirements into architecture, system design and documentation. For legal interpretation we work with your own lawyers or external advisers: to each their own field.

No. We then start with an inventory of the existing systems: classification, data flows and where the biggest gaps are. Then we prioritise: what must happen now, what can be phased. Making existing systems adaptable is exactly the kind of technical work we are here for.

XAI makes it traceable, per decision, why a model reached an outcome. For high-risk applications that is not a luxury but a requirement: a regulator does not ask whether your model works, but why it made this decision. We build explainability in as a design principle. That is how we did it for the financial sector too.

A working dossier: risk classification per system, AI Act mapping with responsibilities, well-founded architecture choices, fairness analysis per target group and audit-proof documentation. Not an advisory report that disappears into a drawer.

They complement each other: ISO 27001 and NEN 7510 safeguard information security, the AI Act sets requirements for the AI system itself. Our own organisation is ISO 27001 certified, so the security foundation under every compliance project is already in place.

Related expertise

Ready for demonstrably responsible AI?Interested?Get a call back
Eduard van Pagée

Leave your number and Eduard will get in touch.