AI Strategy, Infrastructure Architecture & Security Research
Infrastructure and cybersecurity · Based in Cologne, Germany. Available for engagements in Vienna and across DACH.
The advisory approach connects AI risk assessment, technical documentation, human oversight and operational controls. Applicable duties depend on the system, organizational role and jurisdiction; this is not a guarantee of compliance. Enterprise infrastructure and cybersecurity form the foundation of the advisory work. See the career background for the scope of previous roles.
The general application date is 2 August 2026. Article 113 sets different dates and exceptions for prohibitions, GPAI and high-risk systems; Article 111 contains transitional rules. Check the current consolidated regulation for the specific system and role.
Chapters I and II generally apply from 2 February 2025; specified newer Article 5 provisions apply from 2 December 2026. Chapter V GPAI provisions apply from 2 August 2025, subject to transitional rules.
Chapter III Sections 1–3, except Article 6(5): 2 December 2027 for Article 6(2)/Annex III systems; 2 August 2028 for Article 6(1)/Annex I systems. Transitional rules must be checked separately.
Inventory systems, intended purposes and organizational roles before assessing applicable duties. Scope and duration require an individual assessment.
Check prohibited practices under Article 5, the high-risk criteria and exceptions under Article 6 and the annexes, and relevant transparency duties under Article 50. Intended purpose and the operator’s role matter; a four-label summary does not replace that assessment.
Design of AI governance structures including risk ownership, model documentation standards, incident response, and human oversight mechanisms aligned to Article 9 requirements.
Support for technical documentation packages required for high-risk AI systems, including system descriptions, training data governance, performance monitoring, and conformity assessment preparation.
ISO/IEC 42001 concerns AI management systems. Mapping its processes to applicable AI Act duties can support a review, but implementing the standard does not by itself establish legal compliance.
Specialist advisory for AI in regulated sectors (medical devices, financial services, critical infrastructure) where EU AI Act high-risk obligations intersect with existing sector-specific regulation.
Practical workshops for executive teams and boards on EU AI Act obligations, organizational accountability, and the strategic implications of trustworthy AI for competitive position.
The advisory approach connects AI risk assessment, technical documentation, human oversight and operational controls. Applicable duties depend on the system, organizational role and jurisdiction; this is not a guarantee of compliance.
Enterprise infrastructure and cybersecurity form the foundation of the advisory work. See the career background for the scope of previous roles. Research is not evidence of clinical deployment, regulatory approval or a clinical-performance improvement. No such outcome is claimed here.
An EU AI Act consultant helps organizations classify their AI systems under the regulation's risk tiers, design the required governance controls, prepare technical documentation, and establish human oversight mechanisms before compliance deadlines.
The general application date is 2 August 2026. Article 113 sets different dates and exceptions for prohibitions, GPAI and high-risk systems; Article 111 contains transitional rules. Check the current consolidated regulation for the specific system and role.
Check prohibited practices under Article 5, the high-risk criteria and exceptions under Article 6 and the annexes, and relevant transparency duties under Article 50. Intended purpose and the operator’s role matter; a four-label summary does not replace that assessment.
ISO/IEC 42001 concerns AI management systems. Mapping its processes to applicable AI Act duties can support a review, but implementing the standard does not by itself establish legal compliance.
Article 99 specifies different ceilings, assessment criteria and rules for undertakings and SMEs. The applicable category and conditions must be checked in the current regulation; a headline amount is not a case-specific penalty assessment.
The advisory approach connects AI risk assessment, technical documentation, human oversight and operational controls. Applicable duties depend on the system, organizational role and jurisdiction; this is not a guarantee of compliance.