Atheros AIAtheros.AI
FAQ

The questions that come up before anyone signs anything.

Scope, sequencing, and the things we will not claim. If your question is about the regulation itself, the EU AI Act reference and the ISO/IEC 42001 guide go deeper.

Last reviewed 6 September 2026. Answers describe our practice and summarise the regulation; they are not legal advice.

Does this apply to us?

The questions that decide whether you have a compliance programme to run at all.

Does the EU AI Act apply to us if we only use vendor AI like ChatGPT or Copilot?

Yes, as a deployer. Using an AI system under your own authority in a professional capacity makes you a deployer under Article 3(4), and the AI literacy duty in Article 4 has applied to deployers since 2 February 2025. If the use case falls under Annex III — screening candidates, scoring creditworthiness, allocating essential services — the deployer duties in Article 26 apply too, and fine-tuning or rebranding the vendor system can make you its provider under Article 25.

Are general-purpose models like GPT covered by the EU AI Act?

They are covered, but under a separate chapter. Chapter V imposes obligations on providers of general-purpose AI models — technical documentation, information for downstream providers, a copyright policy and a training-content summary — with additional obligations in Article 55 for models presenting systemic risk. Those duties sit with the model provider. What matters for your organisation is the use you put the model to, which is classified on its own terms.

We are a 20-person startup. Is any of this proportionate for us?

The obligations scale with the risk of the use case, not the size of the company, so a small team building a hiring tool carries the full high-risk set. Two things do scale: Article 99(6) caps administrative fines for SMEs and start-ups at the lower of the two figures in each band, and Article 62 requires Member States to give SMEs priority access to regulatory sandboxes and dedicated guidance. In practice the affordable route is to build the evidence into the pipeline from the start rather than reconstructing it under deadline.

What is the fastest way to find out whether our systems are high-risk?

Inventory every AI system with its intended purpose written in one sentence, then read each one against Annex III and Article 6. Classification follows the purpose, not the technology, so the same model can be minimal risk in one product and high-risk in another. Our 30-minute classification call does this with you and leaves you with a written memo of the tiers and the reasoning, whether or not you engage us afterwards.

Which part of Atheros AI do we need?

Software, advisory and training solve different problems. Most organisations need fewer of them than they expect.

Do we need the software, the advisory, or the training?

Advisory if you do not yet know which systems you have and what tier they are in — the diagnosis has to come first. Software if you already know your obligations and the problem is producing evidence repeatedly, on every model version, without a person assembling it by hand. Training if the gap is that your teams cannot recognise a compliance decision when they are making one, which is also the Article 4 literacy duty. They are sold separately and are useful separately.

We already run ISO 27001. Does that cover us for AI?

Partly. ISO 27001 and ISO 42001 share the Annex SL clause structure, so your governance body, internal audit programme, management review and document control carry over — typically the largest single saving on a certification path. What ISO 27001 does not cover is AI-specific risk: impact on affected individuals, data and model lifecycle controls, and the AI system impact assessment in clause 6. Those are new work.

Does ComplianceEngine work with our existing MLOps stack?

It is designed to run inside the pipeline you already have rather than replace it: the checks execute as a stage in CI/CD, and the technical file is generated from what the pipeline already knows about each model version. The right way to answer this for your stack specifically is a scoping call — we would rather tell you a connector does not exist yet than discover it during a pilot.

Can you work alongside our law firm and our external auditor?

Yes, and it is the normal arrangement. We are not a law firm and do not give legal advice; counsel interprets the regulation for your circumstances. We build the management system and produce the evidence, in the form your auditor will ask for it. Where an accredited certification body is involved, we sit on your side of the audit only.

How the work runs

What an engagement actually looks like, and what we will not claim.

How long is a typical advisory engagement?

Our Regulation Ready engagement runs in three phases — Assess, Architect, Activate — over roughly 90 days, moving from a regulatory gap analysis to an operating AI Management System with board reporting. Certification is a longer horizon: an ISO 42001 audit window depends on records accumulating over months, which no engagement can compress.

Can Atheros AI certify us against ISO 42001?

No. Under ISO/IEC 17021 the body that certifies a management system must be independent of the body that designed it, and only certification bodies accredited for the scheme issue certificates. We prepare you for that audit and support you through it. Any consultancy offering both would not survive an accreditation review.

Do you provide legal advice or a conformity assessment?

Neither. We produce the technical and organisational evidence that a conformity assessment relies on, and we design the management system that keeps it current. Legal interpretation belongs to your counsel, and conformity assessment is carried out under Article 43 — by you under internal control, or by a notified body where the Act requires one.

What happens when the regulation changes?

The AI Act's implementing acts, harmonised standards and Annex III interpretations will keep moving for years, so the material question for any tool or programme is who maintains the mapping and how fast. We version the regulatory content our assessments run against and date every deliverable, so you can always tell which text a conclusion was reached under. Our reference pages carry a review date for the same reason.

Training and AI literacy

Article 4 has applied since February 2025 and is the obligation most organisations discover last.

Does Academy training satisfy the Article 4 AI literacy obligation?

Article 4 requires providers and deployers to take measures ensuring a sufficient level of AI literacy among staff and others operating AI systems on their behalf, taking into account their technical knowledge, experience and the context of use. The Act does not accredit courses, so no training can be certified as satisfying it. What discharges the duty is a documented, role-appropriate programme plus records of who completed it — which is what we deliver and hand over.

Who delivers the training?

Practitioners rather than professional trainers: PhD-level instructors and ISO 42001 Lead Auditors who also run our advisory engagements. The tracks are separated by audience — executives and boards, technical teams building regulated AI, and the wider workforce using generative tools — because the literacy each group needs is different and mixing them wastes everyone's time.

Can training be delivered in-house and tailored to our sector?

Yes. Tracks run from half-day executive briefings to five-day technical programmes, and the material is rebuilt around your sector's obligations and your own AI inventory where you can share it. Tell us the audience and the outcome you need, and we come back with a tailored proposal within five business days.

Still the wrong question for your situation?

Thirty minutes with an ISO 42001 Lead Auditor is usually enough to tell you which obligations you carry and in what order to take them.