Solutions /  The situation

You added AI to the product. The questions arrived three months later.

The model went into the product because it made the product better. Nobody wrote down what data it was trained on, who reviews its outputs, what happens when it is wrong, or which of your customers' users it decides something about. Now an enterprise buyer wants your AI governance policy, and the EU AI Act has obligations that depend on answers you have never had to give.

Get your free exposure assessment

The EU AI Act is phasing in, and its obligations run down the supply chain: your customer's compliance team must classify their AI use, and to do that they need documentation from you. ISO 42001 is emerging as the way to answer that once instead of per-customer. This market is barely contested. Being able to answer is currently a differentiator.

What it is costing you

  • An AI feature you built to win deals starts blocking them, because you cannot document it.
  • Classification is not optional: whether your feature is minimal-risk or high-risk changes your obligations entirely, and nobody in the company knows which it is.
  • Every enterprise buyer asks a slightly different version of the same question, and your engineers answer it from scratch each time.
  • Model behaviour changes with every retrain and every vendor update, so any answer you give is true only until the next release.

What we do

01

We inventory the AI you have

Models in the product, third-party APIs, models embedded in tools your teams adopted without telling anyone. You cannot govern what is not on the list, and the list is always longer than expected.

02

We classify each use under the EU AI Act

Prohibited, high-risk, limited-risk, minimal-risk, and whether you are a provider or a deployer. This one determination drives every obligation that follows, and getting it wrong is expensive in both directions.

03

We build the governance the buyers are asking for

AI policy, human oversight, data governance, transparency notices, logging, incident handling for model failures, and the technical documentation your customer's compliance team needs from you.

04

ISO 42001, if it is worth it to you

An AI management system you can certify, the same trick ISO 27001 pulls for security: answer once, present to everyone.

05

We keep it true through retrains

Governance written once is stale by the next model version. The ROC keeps the inventory, the classifications and the documentation current as the product changes.

How long it takes. An AI inventory and a defensible classification take a few weeks. Governance documentation your customers will accept takes two to three months; ISO 42001 certification, longer.

Does the EU AI Act apply to an Israeli company?

Yes, if your AI system is placed on the EU market or its output is used in the EU, the same extraterritorial logic as GDPR. Your obligations depend on your role (provider or deployer) and on the risk classification of the specific use. In practice, most Israeli B2B software companies feel it first through their customers: the EU buyer must classify their own use of your AI feature, and they cannot do that without documentation from you.

What is ISO 42001 and do we need it?

ISO 42001 is the international standard for an AI management system, the governance equivalent of ISO 27001, but for AI: inventory, risk assessment, human oversight, data governance, transparency and continuous monitoring of AI systems. It is not legally mandatory. It is becoming the practical way to answer enterprise AI due diligence once rather than per-customer, and it maps closely to what the EU AI Act asks providers to document.

What AI documentation do enterprise customers ask for?

Typically: an inventory of the AI systems in your product, the risk classification of each, what data the models were trained on or receive at inference, whether customer data is used for training, where human oversight sits, how model failures are detected and handled, and which third-party model providers sit in your supply chain. Companies that can produce this in a document close faster than companies that answer it from scratch in every security review.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.