Inventory
We list AI systems in use or under development, both proprietary and third-party. What is not visible cannot be governed.
The AI Act applies generally from 2 August 2026 (Annex III high-risk obligations deferred to December 2027 by Regulation (EU) 2026/1744). We take you to compliance without waiting for a penalty. Consultoría + IA + Calidad cluster.
The AI Act classifies artificial intelligence systems by risk level: unacceptable (prohibited), high-risk (with stringent obligations), limited and minimal. Fines for non-compliant high-risk systems reach €35M or 7% of turnover. And most companies using AI — for recruitment, credit scoring, edtech or recommender systems — fall under these obligations without realising it.
Our work in three phases: (a) inventory of all AI systems in use or under development, whether proprietary or third-party; (b) risk classification according to the AESIA framework and an adaptation plan per system; (c) internal use policy, training for the management team and operational procedures.
Where applicable, we integrate the results with ISO 42001 (AI management system) implemented by Summum Calidad. And if you build or consume AI in production, we coordinate with Summum IA for the technical side of compliance.
Unacceptable risk
High risk
Limited risk
Minimal risk
We list AI systems in use or under development, both proprietary and third-party. What is not visible cannot be governed.
Each system is classified according to the AI Act: unacceptable, high risk, limited or minimal.
Use policy, procedures by risk level, Annex IV and training.
We support ISO 42001 certification through Summum Calidad. A recognised standard to demonstrate externally.
The operational detail: what we deliver as part of the engagement and what we keep active afterwards.
AI systems inventory
Proprietary models, third-party integrations, LLM automations.
Risk classification according to AESIA
Application of the AESIA framework and the 16 guidelines of December 2025.
Compliance plan per system
Technical documentation, impact assessment, controls, monitoring.
Internal AI use policy
What is permitted, what is prohibited, how to report misuse.
Training for the management committee
What a manager needs in order to decide with a clear grasp of the framework.
ISO 42001 support
Coordinated with Quality for the certifiable management system.
The AI Act is European regulation. ISO 42001 is the voluntary international standard that underpins compliance.
It is not just legal. It is the Summum cluster: legal + management system + technical capability.
2 August 2026 remains the general application date for the Regulation. Full high-risk obligations are deferred by Regulation (EU) 2026/1744 — the Digital Omnibus on AI, in force since 27 July 2026 — to 2 December 2027 for Annex III systems and to 2 August 2028 for Annex I ones. General-purpose obligations already active.
Fines of up to 35 million euros or 7% of global turnover. And suspension of the system in the European market.
No. It also affects those who use it. Scoring, recommendation engines, personnel selection and educational assessment are all in scope.