EU AI Act compliance and AI governance built into the implementation
The EU AI Act sets obligations that follow from the risk category of the system, and they apply in stages. We run the classification at the start of every project: which category your running and planned AI systems fall into, what that means for documentation, human oversight and logging, and what has to be built into the system. We also have experience implementing high-risk AI systems. Delivered by a Budapest-based team.
The next step is the AI opportunity assessment: from HUF 500,000 + VAT.
Updated:
The EU AI Act classifies AI systems by risk: unacceptable, high, limited and minimal. Obligations follow from the category and become applicable in stages between 2025 and 2027. The first question is therefore which category a system falls into; the classification answers it, with written reasoning.
Most AI applications running in companies — document processing, customer service assistants, internal knowledge bases — fall into the limited or minimal risk category, where the obligations are typically about transparency, such as the user knowing they are talking to an AI. Systems that make or prepare decisions about people typically fall into the high-risk category. Those carry risk management, data quality, technical documentation, human oversight and logging.
We run the EU AI Act risk classification at the start of every project, and we have experience implementing high-risk AI systems. Our team has been building production enterprise systems since 2013 and has closed 46+ projects so far. A full team carries the work: a project manager, senior developers, and an AI DevOps engineer. We do the technical and organizational preparation; the legal assessment stays with your legal counsel.
What the preparation covers
Risk classification with written reasoning
We go through the AI systems you run and plan, and assign a risk category to each one. The reasoning is written down, so your legal counsel can review it.
Compliance documentation
We assemble the documentation the category calls for: how the system works, which data it uses and the quality of that data, the risk management steps, the review points. Whatever can be carried over from your existing material, we carry over.
Human oversight and logging in the system
Human review points and logging are built in as part of the system: who approves a decision, what the reviewer sees, and what goes into the log. When someone checks later, this is what can be retrieved.
AI governance for day-to-day operation
We write down who authorizes a new AI system going live, who owns it, what is measured on it, and when it has to be reclassified. The governance is built together with the system.
How we work
- 1
AI opportunity assessment — from HUF 500,000 + VAT
We list the AI systems you run and plan, and classify each one by risk. The output is a written plan: the category, what it requires, and what is missing today. You can use it even if you continue without us.
- 2
Compliance plan and documentation
The gap list becomes a scheduled plan: which document gets written, what has to change in which system, and what belongs to your legal counsel. The documentation is built on your existing material.
- 3
Build-in and pilot — 2-3 weeks
We test the human review points, the logging and the data quality checks on one system in production conditions. A small proof of concept is ready in 2-3 weeks.
- 4
Implementation and operations — 6-12 weeks
Most projects go from kickoff to production in 6-12 weeks. We re-run the classification when the system changes; monitoring and support are part of how we work. Source code, models, and data remain yours.
Why Leventech
Classification at project start
EU AI Act risk classification is part of every project we run. We have experience implementing high-risk AI systems as well.
Engineering work alongside your legal team
We do the technical and organizational preparation: classification, documentation, human oversight, logging. Your legal counsel does the legal assessment, and the documentation is handed over to them.
Our team has built production systems since 2013
46+ completed projects, 96% client satisfaction. What we build, we also operate and maintain, and the compliance documentation is kept in line with it.
Your data stays with you
On-premise or private cloud deployment when needed, with open-source models. Your data never leaves your environment, and the logs stay with you as well.
Common questions
The EU AI Act uses four categories: unacceptable, high, limited and minimal risk. Most applications running in companies — document processing, customer service assistants, internal knowledge bases — are limited or minimal risk. Systems that make or prepare decisions about people typically fall into the high-risk category. We run the classification per system at the start of the project, with written reasoning.
The EU AI Act applies in stages: obligations become applicable between 2025 and 2027, and which one applies from when depends on the risk category of the system. We can tell you the dates that concern you after the classification; the text in force and the deadlines are reviewed together with your legal counsel.
No. We do the technical and organizational preparation: risk classification, compliance documentation, human review points, logging, AI governance. The legal assessment and the question of legal liability belong to your legal counsel; the documentation is handed over in a form they can review.
We list the AI systems you run and plan, classify each one by risk, and check what documentation exists and what is missing. The output is a written plan: the category, the obligations, the gap list, and the next steps with a cost estimate. The assessment starts from HUF 500,000 + VAT.
High-risk systems carry risk management, management of the quality of the data used, technical documentation, human oversight and logging. The exact scope of the obligations follows from the text in force and the classification of the system, so we go through the two together.
That it is written down: who authorizes an AI system going live, who owns it, what is measured on it, and when it has to be reclassified. Human review points and logging belong to it too. The governance is built together with the system, so it works from the day of go-live.
The EU AI Act assigns separate obligations to the provider and the deployer of a system — which role is yours is clarified together with the classification, because on a custom build the two can differ. We add the classification, the documentation and the technical solution, and your legal counsel does the legal assessment. Source code, models, data and documentation remain yours.
The entry point is the AI opportunity assessment: from HUF 500,000 + VAT. It establishes the scope: how many systems are involved, which category they fall into, and what is missing from the documentation. After that you get an exact quote, with no hidden costs.
Still have questions?
Start with a conversation
Tell us which AI systems you run or plan — we tell you what the EU AI Act touches and what the preparation involves.
What would you automate in your business?
Tell us briefly about the task. We will reply by email to arrange an initial conversation.
The next step is the AI opportunity assessment: from HUF 500,000 + VAT.
What happens after you send?
In the first conversation we review the task, your existing systems and the outcome you need. Then we discuss whether a detailed assessment would help. We provide a proposal before any paid work.
Or reach us directly:
[email protected]
Monday-Friday, 9:00-17:00 CET
