AI Act compliance consulting, with legal weight behind it
Most companies looking for an AI Act compliance consultant want the same three things: to know what applies to them, to have documentation that holds up, and to stop guessing. We do that work — and because we are a law firm, the conclusions come with legal reasoning you can rely on.
First hour’s on us. No commitment.
What you get
- A classification of every AI system in your portfolio, with written reasoning — not a colour-coded spreadsheet
- A gap analysis against the obligations that actually apply to your risk category and your role
- A prioritised roadmap with dates tied to the phase-in schedule
- The documentation itself — technical file structure, logging requirements, human oversight design, AI literacy records
- Contract language for the AI you buy and the AI you sell
How it works
- Intake, 45 minutes. What you build, what you buy, what worries you. Free.
- Assessment, one to three weeks. Inventory, classification, role determination, gap analysis.
- The roadmap. Written, prioritised, with a timeline. You run it yourself or with us.
- Ongoing support, if you want it. On demand for specific questions, or as a dedicated partner.
Consultant or law firm — what the difference means in practice
The AI Act compliance market has two kinds of provider. Consultancies are strong on process: inventories, tooling, project management, rolling out a framework across a large organisation. Law firms are strong on the questions that have a right and a wrong answer: whether a system falls under Annex III, whether you are the provider or the deployer, whether an exemption applies.
The distinction matters at three specific points.
When the classification is borderline. Annex III is written in categories that require interpretation. Whether a system “makes” or merely “assists” a decision, whether a use is “employment-related”, whether a filtering tool is preparatory or determinative — these are legal questions, and the answer determines whether a whole compliance programme is necessary or not.
When it lands in a contract. Obligations move between parties by agreement. Getting that wrong is expensive in a way a framework document never is.
When someone challenges you. A customer’s procurement team, an investor’s diligence process, a supervisory authority. What they ask for is reasoning, and reasoning is what a legal assessment produces.
Many companies use both, and that works well. We are happy to work alongside a consultancy you already have — we take the judgement calls, they take the rollout.
Where companies most often go wrong
Treating everything as high-risk. Applying the full high-risk regime across a portfolio is expensive and unnecessary. Most systems are not high-risk. The work is proving which ones are.
Missing the systems inside other tools. The AI you did not procure as AI — CV ranking in the recruitment platform, scoring in the credit tool, monitoring in the workforce system — is where high-risk classifications tend to hide.
Becoming a provider by accident. Putting your own name on a third-party system, or substantially modifying one, moves you from the deployer’s obligations to the provider’s. It happens in white-label and fine-tuning arrangements all the time.
Documenting the conclusion but not the reasoning. A classification you cannot defend is not much better than no classification.
Running it separately from GDPR. A DPIA and an AI risk assessment cover overlapping ground. Doing them in two disconnected projects costs twice and produces inconsistencies.
What the timeline means for your planning
The prohibitions and the AI literacy obligation have applied since February 2025. General-purpose AI model obligations since August 2025. The high-risk obligations under Annex III now apply from December 2027, and high-risk AI in regulated products from August 2028, after the amendments adopted in 2026.
That deferral changed the shape of the work rather than the amount of it. The systems you procure and the contracts you sign this year will still be running when the obligations take effect — which makes contracts the part that is genuinely time-sensitive, and the documentation the part you now have room to do properly.
Frequently asked questions
Do you work with companies outside Sweden?
Yes. The AI Act applies across the EU, and much of our work is with companies selling into several member states, or with non-EU companies placing systems on the EU market.
We already have a consultancy running our AI governance. Can you still help?
Yes, and that is a common arrangement. We take the classification and the contracts; they take the rollout and the tooling.
How long does an assessment take?
For a single product line, typically one to two weeks. For a group with multiple entities and a large portfolio, three to six weeks.
What does it cost?
The first conversation is free. After that you get a fixed price, scoped against what you actually have, before any work starts.
Can you help with the AI literacy requirement?
Yes. We run sessions for engineering, product, HR and management, pitched at the level each group needs, and produce the record that shows it happened.
Where to start
You do not need to have your inventory ready or your questions formed. A first conversation is usually enough to tell you whether this is a two-week piece of work or a six-month one.
Who you’ll work with
Fidan Ibrahimzada, Legal Counsel for AI and technology law, leads this work. She advises companies on AI regulation, data protection and technology contracts, and previously led the legal department of a commercial law firm. She holds an LL.M. in European Business Law from Lund University. Lawgent is Sweden’s first law firm dedicated to AI and EU regulation — meet the team.