We Find It. We Fix It.
ICOSA doesn't just identify compliance gaps — we close them. From documentation deficiencies to governance frameworks, our remediation services bring your AI system into full EU AI Act compliance.
The Path to Compliance
Rapid 3-model advisory scan
Fix identified deficiencies
5-model pattern detection
Address remaining gaps
11-model BFT consensus
What We Fix
A continuous, iterative process run across the system's entire lifecycle, not a one-time document: identify and analyze known and foreseeable risks, evaluate them against acceptable-risk criteria, apply mitigations, then re-run the cycle as post-market data comes in. Regulators expect evidence of the cycle actually running, not just a risk register that was filled in once.
Training, validation, and testing datasets must be relevant, sufficiently representative, and examined for errors and gaps in light of the system's intended purpose -- including a documented bias examination. The obligation is on the dataset's fitness for purpose, not just its existence.
Documentation demonstrating compliance with Articles 8-15 must exist before the system is placed on the market, be kept current as the system changes, and be detailed enough for a market-surveillance authority to assess conformity without needing to interview the development team.
Automatic, tamper-resistant event logging throughout operation, sufficient to reconstruct the system's behavior for risk identification and post-market monitoring -- this is the specific requirement ICOSA's Audit Chain is built to satisfy directly, not just describe.
Deployers must be given enough information to interpret the system's output and use it appropriately -- concrete instructions, not marketing copy: capabilities, known limitations, expected performance, and the circumstances under which the system can produce misleading or wrong results.
The system must be designed so a human can actually intervene -- understand its output, remain aware of automation bias, and be able to override or halt it. Oversight has to be built into the design, not delegated after the fact to whoever happens to be watching the dashboard.
Appropriate accuracy, robustness, and cybersecurity for the system's intended purpose, maintained throughout its lifecycle -- including resistance to adversarial manipulation and graceful, safe behavior when errors or unexpected inputs occur, not just clean-room benchmark performance.
From 2 August 2026, output from generative/synthetic-content systems must be machine-detectable as AI-generated across every modality -- text, image, audio, video -- and users interacting with a chatbot-style system must be told they're talking to AI. This is a labeling obligation on the deployed system, distinct from Art. 53's model-level documentation below.
General-purpose AI model providers must maintain technical documentation (Annex XI) and deployer-facing information (Annex XII), a copyright-compliance policy, and a training-data summary using the AI Office's mandatory template. This is the actual "model card" obligation -- it sits at the model layer, not the deployed-system layer Art. 50 covers.
Remediation Packages
Essential
- ✓Single-article remediation
- ✓Documentation templates
- ✓Basic compliance guidance
- ✓Email support
Professional
- ✓Multi-article remediation
- ✓Custom documentation
- ✓Risk management framework
- ✓Human oversight design
- ✓Priority support
- ✓Re-assessment included
Enterprise
- ✓Full-system remediation
- ✓Complete documentation suite
- ✓Governance framework
- ✓Training & workshops
- ✓Dedicated account manager
- ✓Certification fast-track
Continuous
- ✓Ongoing monitoring
- ✓Regulatory change alerts
- ✓Monthly re-assessments
- ✓Documentation updates
- ✓Priority remediation
- ✓Compliance dashboard
Start with a Scan
Before we fix it, we need to find it. Start with a Sentinel Scan assessment to identify your compliance gaps.