Skip to content
Hendez
← All services

Services

AI compliance and governance

Last updated

Short answer

AI compliance is not a documentation exercise; it is a record-keeping regime. Until it is written down which AI systems the organisation runs, which risk tier each falls into, who owns them and how decisions are logged, no regulation can be met. We build that regime and hand it over audit-ready.

2 Aug 2026EU transparency duties — in force
2 Dec 2027EU high-risk systems (Annex III)
SAR 5MSaudi data breach penalty, doubling on repeat

Three regimes, one record-keeping system

Most organisations do the same work three times: a separate file for the EU, another for the Gulf, another for national data law. Yet all three ask for the same core — which systems exist, what they do, where the data comes from, who owns them, how decisions are logged.

We build a single record-keeping regime and generate each regulator's required output from it. When a new regulation arrives, nobody starts from zero.

This is the largest single source of cost difference. An organisation running three separate files collects the same information three times and keeps none of them current.

The order of work

1. Inventory. Every AI system running in the organisation, including purchased tools. Most organisations find about twice what they expected.

2. Classification. Which risk tier does each system fall into? Done against the regulation's own criteria, not by intuition.

3. Gap analysis. Which obligation is unmet on each system, and by which date it must be met.

4. Build-out. Risk management regime, data governance records, technical documentation, automatic event logging, defined human oversight.

5. Ownership. Every file gets an owner by name. There is no such thing as an unowned compliance programme.

6. Refresh. When a system changes, the record changes. That gets a calendar and a responsible person.

If you are a supplier, this is a sales subject

European and Gulf buyers are pushing these obligations into supplier contracts. Tenders now ask bidders for technical documentation, data-governance records and a defined human-oversight arrangement.

In Saudi Arabia the SDAIA framework sets a mandatory governance baseline for public sector entities, and ISO 42001 is becoming central to procurement. If you intend to sell technology into government, governance is not a preference — it is the entry ticket.

A supplier holding these documents ready beats one that does not. Compliance stops being a cost line and becomes a point of differentiation.

Starting early changes the cost, not the calendar

The EU AI Act's high-risk obligations were postponed by the Digital Omnibus — 2 December 2027 for Annex III, 2 August 2028 for Annex I. That looks like relief. It is not.

As the date approaches, consultant and notified-body capacity becomes the scarcest resource in the market. Producing the same file in late 2027 costs several times what it costs today.

An organisation that starts early also does the work with its own people at its own pace; one that starts late buys it from outside, in a hurry.

What each regime asks for

RegimeCore obligationCritical date
EU AI Act — transparencyAI disclosure, machine-readable marking, deepfake disclosure2 August 2026 (in force)
EU AI Act — high riskRisk management, data governance, technical documentation, human oversight2 December 2027 (Annex III)
SDAIA framework (Saudi Arabia)Data governance, model accountability, transparency, human oversight, risk managementMandatory baseline for public sector
Oman personal data lawData protection officer appointment, documented consent trail5 February 2026 (fully in force)
National data protection lawLawful basis, notice, retention periods, transfer rulesIn force

Frequently asked

Frequently asked

We are a small company. Does this bind us?

Scope follows what the system does and where its output is used, not company size. And if you sell to a large customer, the obligation reaches you through contract.

We have lawyers. Why do we need you?

Your counsel tells you what the text says; we build the system so that it meets the text. The two do not substitute for each other — they work together.

How long does it take?

Inventory and classification are usually measured in weeks. The real duration is in closing the gaps, and that depends on the number of systems.

We have no records at all. Is it too late?

No. Most organisations start exactly here. What is too late is starting two months before the deadline.

Do you also deliver AI literacy training?

Yes, and it is an obligation the regulation imposes regardless of risk tier. We hand over the training record in audit-ready form.

Let us begin

Let us discuss this on your own operation. The first session is free.