Back to the blog

AI Act: Legal Analysis of an AI System - How It Works and What It Costs

Pavel Čech 13. 4. 2026

AI Act_právní analýza AI systému – jak probíhá a kolik stojí

Not sure which risk category your AI system falls into? A legal analysis under the AI Act will tell you – and will show you what specifically you need to do. By August 2026, the regulation will affect most companies that develop or operate AI.

Read FAQs

1. What a legal analysis of an AI system is

A legal analysis of an AI system is an expert assessment that determines which risk category your system falls into under the AI Act, which regulatory obligations apply to you, and what specifically you must do to achieve compliance. It is the starting point of every AI compliance process, something like an audit of an AI system from a legal perspective. The compliance roadmap, which is part of the analysis, is a concrete plan of steps set within the timeline of the AI Act (Regulation 2024/1689, full text on EUR-Lex).

The AI Act enters into force gradually and by August 2026 will affect most companies that develop or operate AI. It is the first comprehensive regulation of artificial intelligence in the world, covering the entire value chain from development through deployment to distribution (see also the overview at Digitální Česko and the European Commission - AI policy).

2. Why you need a legal analysis of an AI system

The AI Act (Regulation (EU) 2024/1689 of the European Parliament and of the Council) is the first comprehensive legal framework for the regulation of artificial intelligence in the world. It introduces a risk-based approach. The greater the risk your AI system poses to the health, safety, or fundamental rights of individuals, the stricter the rules you must meet.

The problem? Most companies do not know which risk category their system falls into. And that is precisely the first and most important question, because everything else depends on it: what obligations you have, what documentation you must prepare, what penalties you face, and by when you must accomplish it all. Without a written legal analysis, a company has no certainty that its AI system is not prohibited.

Penalties for breaching the AI Act reach up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher.

For comparison: the maximum sanctions under GDPR are EUR 20 million or 4% of turnover. This is something worth having mapped out in advance.

A legal analysis of an AI system is therefore the starting point of every compliance process. Without it, you do not know whether your system is subject to obligations that already apply (for example, the prohibitions under Article 5 of the AI Act, effective from February 2025), or whether you face extensive compliance obligations for high-risk systems (effective from August 2026).

The analysis is typically requested by companies and organizations in three situations:

  • Before bringing an AI product to market: they want to know what regulatory obligations they must meet in order to legally sell or license their AI system in the EU.
  • When commercializing a research project: universities and research centers that want to bring AI technology into practice (spin-off, license, SaaS) need a legal framework.
  • When deploying a third-party AI system: corporations that introduce AI tools into their processes (HR, customer service, decision-making) need to know what obligations they have as deployers.

3. Who the analysis is intended for

The AI Act distinguishes several roles in the value chain, and each has different obligations. The legal analysis is relevant for all of them. A more detailed overview can be found on our AI compliance pack page.

Role under the AI Act

Who it is in practice

Typical need

Provider

A company that develops an AI system and brings it to market under its own name

Risk classification, compliance roadmap, documentation, texts for users

Deployer

A company that deploys an AI system in its environment (hospital, public authority, bank, HR)

Assessment of obligations, assessment of impacts on business processes, AI literacy

Importer / distributor

A company that imports an AI system into the EU or distributes it further

Verification that the provider has met its obligations; own compliance obligations

Downstream integrator

A company that integrates a GPAI model (e.g. GPT, Claude) into its product

Assessment of whether the integration has made it a provider; obligations toward GPAI models

💡 A downstream integrator is a company that integrates a general-purpose AI model (a so-called GPAI model, e.g. GPT-4, Claude, Gemini) into its own product or service. Through this integration, it may acquire the status of a provider of an AI system with the full range of compliance obligations.

Not sure which role you fall into? Arrange a no-obligation consultation. We will help you determine it within 30 minutes.

Arrange a free consultation

4. What the analysis assesses

A legal analysis of an AI system under the AI Act (sometimes also referred to as an AI system audit or an AI conformity assessment) has a clearly defined structure. Its scope varies from case to case, but it always covers the following key areas:

4.1 Risk classification - the core of the entire analysis

The AI Act distinguishes four levels of risk. The analysis systematically goes through each of them and assesses whether it applies to your system:

Risk level

What it means

Examples

Unacceptable

The system is prohibited - it may not be placed on the market or operated in the EU

Social scoring, manipulation of vulnerable persons, mass biometric identification

High

The system is subject to strict requirements (documentation, testing, monitoring, registration)

AI in HR, credit scoring, biometrics, critical infrastructure, education, justice

Limited

Transparency obligations - inform users about interaction with AI, label synthetic content

Chatbots, text/image generators, deepfake systems, emotion recognition

Minimal

No specific obligations (apart from the general ones - AI literacy)

Spam filters, AI in games, logistics optimization

Classification is not trivial. One and the same system may fall into different categories depending on where and how it is deployed. A sign language translator is, in everyday communication, a limited-risk system. But deploy it in a public authority, where the translation affects a citizen’s access to a public service, and you suddenly find yourself on the borderline of a high-risk system.

This is why the analysis is always carried out with regard to the specific intended purposes and deployment contexts of your system - not “from behind a desk”.

4.2 Assessment of prohibited practices

The first step is to rule out that your system falls among the prohibited AI practices defined in Article 5 of the AI Act. These are systems that the EU considers unacceptable from the perspective of fundamental rights - for example, subliminal manipulative techniques, exploitation of the vulnerability of persons, social scoring, or mass biometric identification in public places.

The prohibitions have applied since 2 February 2025; if you have not yet undergone this test, you should do so as soon as possible.

4.3 Assessment of high-risk categories

If the system is not prohibited, we assess whether it falls under one of the eight categories of high-risk AI systems listed in Annex III of the regulation. These include, among others, biometrics, critical infrastructure, education, employment, access to public services, law enforcement, migration, and justice. Furthermore, this concerns systems subject to a conformity assessment obligation.

The analysis goes through all eight categories systematically and, for each, states whether it is relevant to your system and why. This is important not only for your internal certainty but also for any potential communication with a supervisory authority.

4.4 Exemptions from classification

Even a system that formally falls under the high-risk categories need not ultimately be assessed as high-risk. The AI Act contains an exemption for systems that perform a narrowly defined procedural task, do not pose a significant risk, and do not serve to profile individuals. The analysis assesses whether this exemption applies to your case. If so, it documents this in a manner that will withstand any potential inspection.

4.5 Transparency obligations

Even limited-risk systems have obligations. You must inform users that they are communicating with an AI system. If your system generates synthetic content (text, image, video, voice), the outputs must be labeled in a machine-readable format. If the system recognizes emotions or performs biometric categorization, you must inform users about it.

The analysis identifies which specific transparency obligations apply to your system and proposes how to implement them.

4.6 Training data and GDPR

If your AI system works with personal data, whether during model training or during operation, the analysis also assesses compliance with GDPR. More about our services in the area of personal data protection on the Personal Data Protection page.

We focus in particular on:

  • The legal basis for processing training data (consent, legitimate interest, performance of a contract)
  • The need to carry out a DPIA (data protection impact assessment) - for AI systems, a DPIA is often mandatory
  • The licensing terms of third-party datasets - some sources expressly prohibit use for AI training
  • The obligation to inform affected individuals about the processing of their data

4.7 GPAI models

If your system uses general-purpose AI models (GPT, Claude, Gemini, Llama, etc.), we assess whether, as a downstream integrator, you are subject to the obligations under Chapter V of the AI Act and whether, by integrating the model into your own product, you acquire the position of a provider with full compliance obligations.

5. How the analysis proceeds step by step

The entire process from the first consultation to delivery of the finished analysis typically takes 1-4 weeks depending on the complexity of the system. Here are the individual steps:

  1. Initial consultation - We go through your system, its purpose, technical architecture, and intended deployment contexts. Typically 30-60 minutes online. This meeting is free.
  2. Questionnaire and materials - We send you a structured questionnaire covering the technical description of the system, intended purposes, target users, data processing, business model, and regulatory context. The more specific the answers, the more precise the analysis.
  3. Legal analysis - Based on the materials, we carry out a comprehensive classification of the system under the AI Act. We assess prohibited practices, high-risk categories, exemptions, transparency obligations, GDPR aspects, and obligations relating to GPAI models.
  4. Compliance roadmap - We propose concrete short-term, medium-term, and ongoing steps that you must take to achieve compliance - including a timeline tied to the AI Act deadlines.
  5. Draft texts and documentation - Depending on the scope of the engagement, we prepare drafts of informational texts for end users (transparency obligation under Article 50), a liability disclaimer, and other documentation needed for compliance.
  6. Handover and follow-up - We deliver the analysis as a written document and go through it with you at a meeting. We answer questions and agree on any further steps (implementation, DPIA, contractual documentation, AI literacy training).

6. What the output is - and what to do with it next

The output of the legal analysis of an AI system is a written legal document (typically 15-25 pages) that contains detailed reasoning for each of the assessed high-risk categories and a clear classification conclusion. Specifically:

  • Classification conclusion - which of the 4 risk categories (unacceptable, high, limited, minimal) your system falls into and why.
  • Overview of obligations - specific obligations (transparency, documentation, AI literacy, registration, etc.) with references to the relevant articles of the regulation.
  • Compliance roadmap - short-term steps (within 3 months), medium-term (within 12 months), and ongoing steps, set within the AI Act timeline.
  • Draft texts for users - information about the AI system, a liability disclaimer, notices about system limitations - texts ready for implementation.
  • GDPR recommendations - assessment of the need for a DPIA, recommendations regarding training data and the licensing terms of datasets.

With this document, you have a clear picture of where you stand and what you must do. For most companies, the analysis is the starting point - it is followed by concrete implementation steps:

  • Preparation of technical documentation for high-risk systems
  • Carrying out a DPIA and a fundamental rights impact assessment
  • Setting up business contracts (licenses, SaaS contracts) with regard to the AI Act
  • AI literacy training for the team
  • Ongoing monitoring of regulatory changes

7. The AI Act timeline

The AI Act is being phased in. Here are the key milestones you need to know:

  • 1 August 2024 The AI Act entered into force.
  • 2 February 2025 Prohibition of unacceptable AI practices (Article 5) and the AI literacy obligation (Article 4). Already in effect.
  • 2 August 2025 Obligations for GPAI models (Chapter V). Concerns providers of models such as GPT, Claude, etc., and downstream integrators.
  • 2 August 2026 The main wave: transparency obligations (Article 50), requirements for high-risk systems (Annex III), obligations of deployers, registration, penalties in full scope.
  • 2 August 2027 Requirements for high-risk systems under Annex I (regulated products - medical devices, machinery, etc.).

There are less than 5 months left until August 2026. If you develop or deploy an AI system that may fall under Annex III or under the transparency obligations of Article 50, it is time to start. Implementing compliance measures takes weeks to months, and time is running out.

8. How much the analysis costs and how long it takes

The scope (and thus the price) varies depending on the complexity of the system, the number of intended deployment contexts, and whether you also need follow-up documentation. As a guide:

Scope

What it includes

Price

Duration

Basic analysis

Risk classification + overview of obligations + brief roadmap

from CZK 30,000

A few days

Complete analysis

All of the above + compliance roadmap + draft texts + GDPR assessment

from CZK 50,000

1-2 weeks

Analysis + implementation

Complete analysis + DPIA + contractual documentation + AI literacy training

individually

1-3 months

💡 Start with a free, no-obligation consultation. You tell us about your AI system. We tell you what you need to do and how much it will cost.

Arrange a free consultation

Frequently asked questions

We answer the most common questions about the Artificial Intelligence Regulation (AI Act), which entered into force in August 2024 and whose key obligations take effect gradually through 2026.

1
Do I need an analysis even if my system is not high-risk?
Yes, precisely so that you have it documented. If your system falls under "limited risk", you must meet the transparency obligations that apply from August 2026. And if the system is "minimal risk", the AI literacy obligation still applies (Article 4, effective from February 2025). What is more, a written analysis is your safeguard in case the supervisory authority takes a different view of the classification.
2
I'm a startup - does the AI Act apply to me?
If you develop an AI system and place it on the market in the EU (or for users in the EU), then yes, regardless of the size of the company. The AI Act contains no exemption for small businesses. It only contains certain reliefs in regulatory sandboxes and in the assessment of fines.
3
We use the GPT/Claude API in our product - do we have to deal with the AI Act?
Yes. By integrating a GPAI model into your product, you most likely become a provider of an AI system within the meaning of the AI Act. You have your own obligations depending on how risky your product is. This is exactly the type of situation where an analysis brings clarity.
4
We deploy a third-party AI system (we are a deployer) - do we need an analysis?
The AI Act imposes obligations on deployers too, not only on developers. If you deploy a high-risk system, you must, among other things, carry out a fundamental rights impact assessment, ensure AI literacy and comply with the rules on human oversight. An analysis will show you which obligations apply to you.
5
Is it enough to do the analysis internally?
Technically yes, the AI Act does not prohibit it. But classification requires detailed knowledge of the regulation, including its recitals, implementing materials, exemptions and the boundaries between categories. Some boundaries are unclear in interpretation (for example, when analysis of facial expressions is "emotion recognition" and when it is not). An independent legal analysis gives you certainty that will stand up even under inspection.
6
My system processes biometric data - is it automatically high-risk?
Not necessarily. It depends on the purpose of the processing. Remote biometric identification may be prohibited, high-risk or even just limited risk - it depends on the specific context of deployment. This is exactly the case where careful legal analysis is needed.
7
How do I prepare for the AI Act?
Preparation starts with a legal analysis of your AI system, which determines your risk category and specific obligations. Next, you need to prepare the documentation, arrange AI literacy training for your team, implement the transparency requirements and set up internal processes for ongoing compliance. The key is to start in time - implementing compliance measures takes weeks to months.
Are you dealing with AI regulation? 

We have carried out dozens of analyses of AI systems for clients in IT, healthcare, fintech, and education, from sign language translation to financial tools. Arrange a no-obligation initial consultation - online, 30 minutes, free.


Contact us

Do you need help in this area?

Invalid phone number

Share this article on social media

Facebook ↗ Linkedin ↗