EU AI Act compliance: implemented by experts, maintained on the platform.
We inventory how your company uses AI, classify the risk, prepare the policies and documents, train your team and put transparency and human oversight rules in place. What you keep is not just a report: it is a working compliance system for the next 12 months.
Tools compliance overview
WHAT THE PROGRAMME COVERS
Everything you need to put AI in order and keep it under oversight.
One programme combines expert analysis, finished deliverables and a platform where you keep them current.
A register of AI use
An inventory of tools, vendors and AI use cases in one place. The library helps fill in the data faster, and an expert sets the scope and the priorities.
tools · owners · purposes · data classes
Risk classification and DPA analysis
Prohibited-practice screening, risk-level classification, a clear split between deployer and provider duties, and analysis of your vendor agreements.
Art. 5 · Annex III · DPA · vendor risk score
AI policy and documentation
An AI use policy and documents matched to your real use cases, including FRIA, DPIA, ROPA, notices and worker notifications, to the extent they are actually needed.
FRIA · DPIA · ROPA · information notices
Transparency rules
Rules for telling clients, users and staff that AI is in use, with ready wording and the places to apply it.
Art. 50 · wording · where it applies
AI training
An AI literacy programme matched to roles: a general level, training on the tools in use, and training for the people who exercise oversight. Progress and completion records stay in the system.
Art. 4 · roles · progress · records
Human oversight and ongoing governance
Roles, responsibilities, reporting of new tools and incidents, periodic reviews, reminders and a living compliance report with an audit trail.
roles · reviews · incidents · audit trail
HOW THE HYBRID MODEL WORKS
Technology speeds the work up. The expert gives it the right context.
The platform automates the repeatable analysis and documentation. The consultant runs the rollout, validates the conclusions, adapts the rules to your organisation and helps you decide. You are not left alone with an application or with a set of templates.
The expert runs the rollout
- Sets the scope and learns your organisation's context
- Runs the workshop and puts the AI use cases in order
- Validates the risk classification and the priorities
- Adapts the policy, the roles and the oversight process
- Trains the team and answers its questions
- Agrees the action plan with you
The platform keeps you compliant
- Holds the shared register of AI use
- Suggests the data and the next actions
- Analyses DPAs and drafts the documents
- Reminds you about reviews and deadlines
- Records training evidence and the change history
- Generates the compliance report and the audit trail

Zofia Żak
Leads AI and Shine rollouts · founder of ROI and Shine
A digital project leader working where data, technology and regulation meet.
More than 15 years in international organisations and across more than 30 markets, with hundreds of digital projects covering data and processes. She combines deep regulatory knowledge with real implementations and the everyday realities of digital and e-commerce: from mapping AI tools, through risk classification (including high risk), to documents that are ready for audit. On the AI and Shine platform she runs projects personally, setting the scope, validating the risk classification and taking responsibility for the quality of everything that reaches the client.
Get to know usHOW THE ROLLOUT RUNS
From an incomplete list of tools to a working oversight system.
Four steps in which the platform does the repeatable work and the expert owns the decisions that cannot be automated.
1. Diagnostic and scope
We agree the goals, the teams, the AI use cases, the data, the roles and the level of support you need.
2. Inventory and classification
We build the register, analyse the DPAs, screen against Art. 5, classify the risk level and name the gaps.
3. Documents, rules and training
We prepare the policy, the documents, the transparency wording, the human oversight model and the training programme.
4. Ongoing oversight
The platform reminds you about reviews, takes in new tools and incidents, records changes and keeps the compliance report current.
You get an ordered picture of the situation quickly. How long the full rollout takes depends on the number of AI use cases and their risk level, which is why the scope is agreed before the work starts rather than during it.
LEGAL POSITION
What applies now, and what is worth preparing ahead?
We do not build urgency on a single universal deadline, because there is no longer one. Below are the dates that actually affect companies using AI.
February 2, 2025
AI literacy and prohibited practices
Your team has to understand the AI tools it uses, and none of the practices banned by Art. 5 may occur in the company.
Art. 4 · Art. 5
August 2, 2025
General-purpose AI models
Obligations for GPAI model providers, with market surveillance authorities in place across member states.
Art. 51 · Art. 55
August 2, 2026
Transparency obligations
Telling clients, users and staff when they are dealing with AI or with AI-generated content.
Art. 50
December 2, 2027
High-risk systems (Annex III)
Recruitment, credit scoring, education and the other Annex III use cases. Preparation takes months, because the hard part is finding and classifying every system.
Date moved by the AI Omnibus.
Annex III · Art. 26 · Art. 27
August 2, 2028
High risk in regulated products
AI built into products covered by EU sectoral law, including medical devices and machinery.
Annex I
Legal position as of September 5, 2026 · Source: European Commission
CHOOSE YOUR LEVEL OF SUPPORT
Which level fits your company?
The scope depends on how many AI use cases you have and how risky they are. Here are the most common situations.
- A small team with standard toolsSTART
- An SME with several departments and many vendorsCOMPLIANCE
- Many tools and non-standard use casesGOVERNANCE
- A regulated sector, an AI provider or high-risk systemsENTERPRISE + HIGH RISK
START
For a small team with standard AI use
from 825 PLN net / month
from 9 900 PLN net / year · 12-month agreement
The final price depends on how many AI systems you have and how much expert support you need.
- A year of platform access and setup of the core scope
- A register of AI tools and use cases with no cap on entries
- Prohibited-practice screening (Art. 5) and a first risk classification
- An AI policy plus the core documents and information notices
- A basic compliance report, monitoring and review reminders
Training can be added from 5 000 PLN net.
See what START coversCOMPLIANCE
For an SME that needs a guided rollout
from 1 492 PLN net / month
from 17 900 PLN net / year · 12-month agreement
The final price depends on how many AI systems you have, their risk level and how much expert support you need.
- Everything in START, at a wider scope
- Guided onboarding and a scoping workshop
- Fuller risk classification and analysis of vendor agreements (DPAs)
- Documentation matched to how your company actually uses AI
- AI policy, transparency rules and a human oversight model
Training can be added from 12 000 PLN net.
Book a free diagnosticGOVERNANCE
For many departments, tools and non-standard use cases
from 59 000 PLN net / year
12-month agreement
The quote depends on the number of departments, custom use cases and process owners.
- Everything in COMPLIANCE
- In-depth workshops and responsibility mapping
- An approval process for new tools and an incident workflow
- Rules for an AI committee and process owners
- Non-standard use cases and internally built solutions
Training can be added from 16 000 PLN net.
Discuss the governance modelENTERPRISE + HIGH RISK
For regulated sectors, AI providers and high-risk systems
Quoted individually
12-month agreement
Scope, schedule and SLA are set individually after a conversation about your organisation.
- The full scope of all seven platform modules
- SSO, API and integrations with your environment
- Automated tool inventory
- A dedicated AI governance model
- Extended documentation and human oversight for high-risk systems
HOW WE WORK
You know who answers for the result and where the service stops.
On a compliance product, missing trust costs more than a missing feature. So we say plainly what a person does, what the platform does, and what this service does not cover.
A named person is accountable
Zofia Żak runs the rollout. She sets the scope, approves the risk classification and answers for the quality of the documents handed to the client.
It is clear what the expert reviews
The platform drafts the documents and proposes a classification. Decisions about scope, risk level and policy content always pass through the expert and are approved with you.
Documents are versioned
Every document carries a change history and the moment the client approved it. That makes it clear what applied when, and it can be shown if you are ever asked.
Operational guidance is not legal advice
AI and Shine supports the operational preparation and maintenance of compliance. The scope does not constitute individual legal advice unless the offer explicitly includes a separate legal review carried out by a qualified partner.
A European platform for European obligations
The platform is hosted in Europe, in Frankfurt.
Data and documents are stored in encrypted form.
Designed in Poland for organisations operating in the European Union.
Legal position as of September 5, 2026
BEFORE YOU DECIDE
The questions worth asking before you buy.
No. We handle the operational work: the register of AI use, risk classification, documents, training and oversight. That is usually most of what has to be done. Where individual legal advice is needed, we bring in a separate review by a qualified partner and price it separately.
They set the scope and learn your organisation's context, run the workshop where the AI use cases are put in order, validate the risk classification and the priorities, adapt the policy and the oversight process to how you actually work, train the team and agree the action plan with you.
The first ordered picture, the tool register and an initial classification, comes together quickly, usually in the first days of the engagement. The full rollout depends on the number of AI use cases and their risk level, so the schedule is agreed during the diagnostic, before the work starts.
In START it is: online training for a team of up to 12 people is part of the price and stays available for 12 months. In the other packages training is quoted separately, because its cost depends on the number of participants and the level of the programme. That way you do not pay for scope you do not need.
The AI tool register in the platform has no cap on entries: you can record everything you use. The limit applies to expert work, that is, how many systems the package price covers for expert validation and prepared documentation. In START that is 5 systems; in the other packages the scope is agreed during the diagnostic.
The agreement runs for 12 months, because compliance is a cycle rather than a one-off project. Over that year we keep the register and the documents current, and we track the review dates. Before the term ends we discuss the next year and what scope is needed then. The documents and the data remain yours.
Yes. The documents, the register and the compliance report can be exported at any time and used outside the platform, for instance handed to an auditor, a law firm or a client asking how you use AI.
The platform is hosted in Europe, in Frankfurt, and data and documents are stored in encrypted form. You upload vendor agreements so the platform can analyse them against AI Act and GDPR obligations. The Privacy Policy sets out the processing detail.
Start with the tools your company already uses today.
In a 30-minute call we agree the scope, show the platform against your own use cases and point you to the right level of support.