Skip to Content



Your AI policy is documented
The operational reality may differ



The assessment establishes which AI systems are in use across the organisation, how each is classified under the EU AI Act risk framework, and what evidence could be presented to a supervisory authority today. Conducted by our engineers alongside affiliated legal counsel.


Take the AI act readiness check

Book a 45-minute scoping call

***Transparency obligations under Article 50 have applied since 2 August 2026. The high-risk obligations follow on 2 December 2027 for standalone systems listed in Annex III, and on 2 August 2028 for AI embedded in products already covered by EU product safety legislation (Annex I). The AI literacy obligation has applied since 2 February 2025, in amended form since July 2026: providers and deployers must take measures to support the development of AI literacy, but are not required to guarantee any particular level. Two further prohibited practices apply from 2 December 2026.


AI Act audit


Scope under the regulation is sector-specific. 

In banking, the boundary runs through the credit scoring environment. In manufacturing, it turns on whether the model functions as a safety component.

Read the audit scope 


Thor 1.0


The digital assistant and environment we intend to build for organisations that wish to automate following the audit, with all processing remaining under EU law.

About Thor 1.0 

 

Audit

01

Scope and inventory 

Together we agree which legal entities, processes and systems the audit will cover.

We then map which AI systems your organisation uses, including tools adopted outside IT.

02

Risk classification

Each system is then classified under the risk categories of the EU AI Act.

Where an exemption appears to apply, we examine it and record the reasoning, whether or not it is upheld. Legal qualification is provided by the affiliated lawyers.

03

Gap analysis and assessment 

We then compare current practice with the obligations that follow from the classification. The assessment is based on how systems are used in practice, not on how policy describes them:

Does the person assigned to oversee the system have the time to do so ? Are logs actually being kept? Where does the date go and who can access it ? 

04

Reporting and debriefing 

You receive an audit report setting out the findings, a risk assessment and a prioritised remediation plan. We then go through it with you.

The report is written so that you can share it with your board, your auditor or your insurer.

Guarantees


After the audit 

 
Thor  1.0




The audit shows where evidence is missing. Thor is being built for organisations that want to automate this work without their business data falling under non-EU jurisdiction. Development starts on 1 November 2026 and runs for six months.

an automation environment running on dedicated hardware under Belgian jurisdiction, connecting directly to your existing ERP and logging every action.

Thor is not a plug-and-play product, and it will not be the right choice for every organisation. The audit puts that decision on a factual footing before you take it.


                                                    Thor

FAQ

That work is useful and much of it can be reused, but the EU AI Act asks different questions: classification per system, your role as provider or deployer, technical documentation, logging and human oversight. The two frameworks apply alongside each other. Neither replaces the other.

The obligations that already apply have not been postponed: prohibited practices, AI literacy and Article 50 transparency. Two further prohibitions take effect on 2 December 2026. What the deferral changed is the deadline, not the amount of work, and building a defensible evidence base takes months.

No, and nobody can. Compliance is determined by the competent authorities, and where the EU AI Act requires it, by a notified body. We assess and classify your systems against agreed criteria, on a fixed date. We are not a notified body. Our audit does not replace a conformity assessment, an EU declaration of conformity or CE marking where the EU AI Act requires them.

A supplier's compliance does not discharge your own obligations. Those follow from your role under the EU AI Act, as provider or as deployer, and a contract cannot transfer them. We assess what you can demonstrate yourself, not what a supplier declares.

No. We test whether the controls work in practice. Does the person assigned to oversee the system have the time to do so? Are logs kept, and are they retained for long enough? Where does the data actually go?

That can be a sound choice, particularly if your board wants a well-known name on the cover. Larger firms also offer international coverage and sector-specific teams that we do not. The difference here is in the team: legal qualification comes from a lawyer, the technical assessment from engineers, and you speak to both directly. There are no intermediate layers between the analysis and the report.

That depends on the scope: the number of legal entities, processes and AI systems the audit covers. We agree that scope in the scoping call, and only then do we confirm a timeline and a price. We do not start an audit with an open scope.

The affiliated lawyers are bound by professional secrecy (legal professional privilege). For DataNerds, confidentiality is contractual. We ask for access only to what the agreed scope requires, and that access ends when the engagement is complete.

That is what Thor is being designed for. DataNerds is a member of SAP PartnerEdge, Build, the partner track for developers building software on SAP technology. Thor is intended to connect to your existing SAP environment without migration and without changes to your data model.

No. The audit is a self-contained engagement with its own report, which remains usable whatever you decide next. Thor is one option for organisations that want to address the findings without their data falling under non-EU jurisdiction. It will not be the right choice for every organisation.

That last question is the most important of the ten. A corporate buyer wants to know if an audit ties him to a supplier, and as long as that is not explicitly denied, he assumes it does.