Service · Compliance
G4Regulatory Readiness (EU AI Act / GCC PDPL).
The regulatory perimeter around AI is closing in. The EU AI Act's deployer obligations reach any business selling into or operating in the EU. GCC PDPL regimes are already live. In three to five weeks we tell you exactly where you're exposed and what closes the gap.
Outcomes
What changes when the engagement lands.
Applicable regime map
Which regulations apply to your operation, where, and at what threshold.
Gap assessment
Where you currently fail to meet obligation. Ranked by regulatory risk.
Closing roadmap
The programme of work required to close the gaps, sized and sequenced.
Documentation the regulator expects
The evidence pack drafted or scoped, ready for internal or external audit.
Deliverables
What's in the engagement.
A three- to five-week structured gap assessment against the EU AI Act deployer obligations and the applicable GCC data protection regimes (UAE PDPL, KSA PDPL, others as scoped). Delivered as a closing roadmap.
Regime applicability memo
Which regulations apply to which parts of the operation. Defensible against legal review.
Gap assessment
Detailed assessment against each applicable obligation. Ranked findings.
Closing roadmap
Work plan to close the gaps. Effort and priority.
Documentation scope
The evidence artefacts the regulator will expect. Scoped for delivery.
How we deliver
Fixed scope. Named phases. Duration on the cover.
The engagement is priced against the outcome, not open-ended hours. Every phase has a duration, a named deliverable, and a check-out.
Total duration3 to 5 weeks
Sales cycle4 to 8 weeks
- 01Week 1
Applicability
Business footprint reviewed. Applicable regimes confirmed.
- 02Weeks 2 to 4
Gap assessment
Structured assessment against each applicable obligation. Findings ranked.
- 03Week 5
Roadmap and read-out
Closing roadmap. Executive read-out.
Built for
Buyers this engagement fits.
Typical buyer
Head of Legal, Head of Risk, CISO
Businesses selling into or operating in the EU
The AI Act's deployer obligations reach you. Understand what applies before enforcement bites.
GCC organisations under UAE or KSA PDPL
The regimes are already live. Know your posture.
Regulated businesses expecting AI-related audits
The audit is coming. Have the position before the auditor arrives.
Related services
Where this leads next.
Sovereign AI Readiness & Governance Baseline
Governance review. Model and data inventory. Control set mapped to ISO 42001. Certification roadmap.
AI Policy & Acceptable Use Framework
Published policy. Practical staff guidance. Rollout the team follows.
AI Governance Retainer
Ongoing control oversight. Evidence maintenance. Regulatory change monitoring. Audit support.
Talk to us.
45 minutes on your operation and the engagement you have in mind. No pitch, no deck.
Lead intake
Request a briefing
A 45-minute call. No pitch, no deck. We ask the questions we'd ask a Discovery client and tell you honestly whether this is the right next move.