AI Governance and EU AI Act Compliance Engineering Services
The EU AI Act's obligations for high-risk AI systems became enforceable on 2 August 2026. Penalties for breaching them reach €15 million or 3% of global annual turnover, whichever is higher. Mixcore Studio builds the technical layer that compliance depends on — the logging, documentation, oversight controls and data lineage that turn a policy commitment into something you can actually evidence to an auditor.
To be clear about scope: we are software engineers, not a law firm. Your counsel determines whether a system is classified as high-risk and what your legal obligations are. We build and retrofit the systems that make meeting those obligations possible, and we work alongside your legal advisers rather than in place of them.
Why this became urgent
The Act phased in over three waves. Prohibited practices applied from 2 February 2025. Obligations on general-purpose AI model providers applied from 2 August 2025. The Annex III high-risk obligations — the ones that touch the largest number of ordinary businesses — applied from 2 August 2026.
Annex III captures far more everyday software than most teams expect, including AI used in recruitment and worker management, credit scoring, insurance pricing, education and access to essential services, as well as biometrics, critical infrastructure, law enforcement, migration and justice. A hiring tool that ranks applicants, or a model that prices a policy, can fall in scope without anyone having thought of it as an "AI system".
The gap we usually find
Most organisations discover the same problem: they cannot produce an inventory of the AI systems already running in production. Models get embedded in features by individual teams, third-party vendors ship AI inside products already in use, and nobody owns the register. Without that inventory, risk classification is impossible and every downstream obligation stalls.
What we build
- AI system inventory and model registry — a maintained record of every model in production, its purpose, owner, data sources, version and risk classification.
- Audit-grade logging — automatically retained records of inputs, outputs, model version and decision path, at the granularity record-keeping obligations require.
- Human oversight mechanisms — real intervention points where a person can review, override or halt an automated decision, with the override itself logged.
- Data governance and lineage — provenance tracking for training and inference data, with the quality and bias checks documented rather than assumed.
- Technical documentation pipelines — model cards and system documentation generated from the live system, so they do not drift out of date the moment they are written.
- Transparency surfaces — the user-facing disclosure that a decision was automated, and the explanation behind it.
- Robustness and accuracy testing — evaluation suites covering performance, bias and adversarial robustness, run continuously rather than once before launch.
How an engagement runs
We start with a technical discovery that produces the AI inventory almost nobody has, mapping every model and AI-bearing vendor feature in your estate with its data flows. That inventory is what your legal team needs to classify risk. From there we scope the engineering work required to close the evidence gaps, prioritising systems your counsel has identified as high-risk.
This work has value well beyond the European Union. The same controls — knowing what models you run, what data trained them, what they decided and who reviewed it — are what any serious AI governance regime asks for, and increasingly what enterprise customers demand in procurement.
Our expertise
- Technical documentation
- Model registry and inventory
- Human oversight controls
- Bias and robustness testing
- Audit-grade traceability
- Data lineage and provenance
Frequently asked questions
When did EU AI Act high-risk obligations take effect?
Obligations for high-risk AI systems listed in Annex III became enforceable on 2 August 2026. This followed the ban on prohibited practices from 2 February 2025 and the obligations on general-purpose AI model providers from 2 August 2025. Penalties for breaching high-risk obligations reach up to €15 million or 3% of global annual turnover, whichever is higher.
Does the EU AI Act apply to a company outside the European Union?
It can. The Act reaches providers and deployers whose AI system output is used within the European Union, regardless of where the company itself is established. Whether it applies to your specific situation is a legal determination for your counsel, not an engineering one, and we work alongside your legal advisers rather than substituting for them.
What counts as a high-risk AI system?
Annex III lists categories including biometrics, critical infrastructure, education, employment and worker management, access to essential services such as credit scoring and insurance pricing, law enforcement, migration and the administration of justice. Many ordinary business tools fall inside these categories without having been thought of as AI systems, which is why an accurate inventory is the necessary first step.
Do you provide legal advice on AI compliance?
No. We are software engineers. Your legal counsel classifies your systems and determines your obligations. We build the technical capabilities those obligations depend on — inventory, logging, documentation, oversight mechanisms, data lineage and testing — and we work directly with your legal team so the engineering matches the legal position.
Where should we start if we have done nothing yet?
Start with the inventory. Most organisations cannot list the AI systems already running in their production estate, including AI features inside third-party products they have bought. Until that register exists, risk classification is impossible and every other obligation is blocked behind it.
Contacts
We are always happy to talk with you.
Feel free to contact us in any suitable way
Request a quote
Let's discuss your project!
Please, provide us with a brief description of what you
already have and what you are going to achieve.
Mail us contact@brainiacminds.com