Solutions / The situation
You added AI to the product. The questions arrived three months later.
The model went into the product because it made the product better. Nobody wrote down what data it was trained on, who reviews its outputs, what happens when it is wrong, or which of your customers' users it decides something about. Now an enterprise buyer wants your AI governance policy, and the EU AI Act has obligations that depend on answers you have never had to give.
The EU AI Act is phasing in, and its obligations run down the supply chain: your customer's compliance team must classify their AI use, and to do that they need documentation from you. ISO 42001 is emerging as the way to answer that once instead of per-customer. This market is barely contested. Being able to answer is currently a differentiator.
What it is costing you
- An AI feature you built to win deals starts blocking them, because you cannot document it.
- Classification is not optional: whether your feature is minimal-risk or high-risk changes your obligations entirely, and nobody in the company knows which it is.
- Every enterprise buyer asks a slightly different version of the same question, and your engineers answer it from scratch each time.
- Model behaviour changes with every retrain and every vendor update, so any answer you give is true only until the next release.
What we do
We inventory the AI you have
Models in the product, third-party APIs, models embedded in tools your teams adopted without telling anyone. You cannot govern what is not on the list, and the list is always longer than expected.
We classify each use under the EU AI Act
Prohibited, high-risk, limited-risk, minimal-risk, and whether you are a provider or a deployer. This one determination drives every obligation that follows, and getting it wrong is expensive in both directions.
We build the governance the buyers are asking for
AI policy, human oversight, data governance, transparency notices, logging, incident handling for model failures, and the technical documentation your customer's compliance team needs from you.
ISO 42001, if it is worth it to you
An AI management system you can certify, the same trick ISO 27001 pulls for security: answer once, present to everyone.
We keep it true through retrains
Governance written once is stale by the next model version. The ROC keeps the inventory, the classifications and the documentation current as the product changes.
Does the EU AI Act apply to an Israeli company?
Yes, if your AI system is placed on the EU market or its output is used in the EU, the same extraterritorial logic as GDPR. Your obligations depend on your role (provider or deployer) and on the risk classification of the specific use. In practice, most Israeli B2B software companies feel it first through their customers: the EU buyer must classify their own use of your AI feature, and they cannot do that without documentation from you.
What is ISO 42001 and do we need it?
ISO 42001 is the international standard for an AI management system, the governance equivalent of ISO 27001, but for AI: inventory, risk assessment, human oversight, data governance, transparency and continuous monitoring of AI systems. It is not legally mandatory. It is becoming the practical way to answer enterprise AI due diligence once rather than per-customer, and it maps closely to what the EU AI Act asks providers to document.
What AI documentation do enterprise customers ask for?
Typically: an inventory of the AI systems in your product, the risk classification of each, what data the models were trained on or receive at inference, whether customer data is used for training, where human oversight sits, how model failures are detected and handled, and which third-party model providers sit in your supply chain. Companies that can produce this in a document close faster than companies that answer it from scratch in every security review.