System inventory
Models, use cases, owners, data, users, integrations and deployment boundaries.
Start a review↗
For organisations that need AI systems
to survive legal, risk and procurement review.
The review converts regulatory questions into an engineering backlog. No generic policy deck and no unsupported compliance claim.
Models, use cases, owners, data, users, integrations and deployment boundaries.
Provider and deployer roles, prohibited uses, transparency duties and potential high-risk exposure.
Missing oversight, records, evaluations, access controls, incident paths and vendor evidence.
Prioritised controls, target architecture, owners, sequencing and a realistic production path.
Each obligation is mapped to an observable system behaviour, a responsible owner and evidence that can be reviewed.
Purpose · actors · data · affected users · deployment
Defined scopeIdentity · permissions · oversight · evaluations · monitoring
Enforced behaviourVersions · decisions · approvals · incidents · vendor artefacts
Audit trailRegulation (EU) 2026/1744 is in force. The high-risk requirements in Chapter III Sections 1–3 apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product systems. Other AI Act duties already in application are assessed separately.
Official Journal ↗Engineering scope, not legal advice. Your legal counsel interprets the regulation. N137.AI maps that interpretation into technical controls and evidence.
See AI transformation ↗The review starts with the AI system and maps every applicable obligation to the same owners, controls and evidence. Coverage is scoped with counsel and sector specialists.
Roles, prohibited uses, transparency, high-risk controls, GPAI dependencies and post-market evidence.
Lawful data flows, access, minimisation, retention, portability and rights-aware operations.
Security ownership, supplier risk, incidents, continuity and operational resilience where applicable.
AI management-system responsibilities, lifecycle controls, records and continual improvement.
Govern, Map, Measure and Manage outcomes, plus the Generative AI Profile where relevant.
Procurement, internal policy, contractual commitments and sector-specific control requirements.
Senior-led delivery with a documented evidence trail, shared working files and an explicit handover. Typical fixed fee: €8,000–€15,000, confirmed before access to systems.
Collect use cases, architecture, model providers, data flows, owners and existing policies.
Map roles, risk indicators, transparency duties, controls and evidence gaps.
Agree priorities, target controls, responsible owners and the production remediation sequence.
No. It is a technical readiness review. Your counsel owns legal interpretation; we identify and implement the system controls required by that interpretation.
The default control map covers the EU AI Act and its 2026 amendment, with GDPR, Data Act, NIS2, DORA, ISO/IEC 42001 and NIST AI RMF crosswalks included where they affect the system or client obligations.
Organisations already deploying AI or preparing a production launch, especially where risk, compliance, procurement or audit teams need reviewable evidence.
You can implement the plan internally, take it to another supplier or ask N137.AI to build the control layer and remediation work.
START WITH ONE SYSTEM
Tell us what the system does, who uses it and what regulatory question is blocking production.
hello@n137.ai ↗