EU AI Act · GDPR · AI Governance

The compliance partner who reads the regulation, not the summary.

EU AI Act and GDPR compliance for AI startups from seed to Series B, read from the regulation and the standards committees themselves, not a second-hand summary. Here's the standard of work, and how I think about it.

Why founders come to us

Three things that keep AI founders up at night

If you're building or deploying AI that touches EU users, you already sense the exposure. The hard part is that the answers aren't where most people look for them.

You don't know if you're high-risk
Annex III is a list, not a verdict, and the exceptions are narrower than they read. Profiling of people quietly cancels most of them.
Art 6 · Annex III
Your vendor's certificate won't cover you
A compliant provider does not make you a compliant deployer. The duties split, and the ones that land on you can't be outsourced.
Art 26 · provider vs deployer
Enterprise tooling costs more than your runway
The Big Four quote a number with three commas. Compliance platforms price for companies ten rounds ahead of you. You need the work, not the overhead.
seed → Series B
Who's behind Voidborn Tech

An engineer who reads the primary source

Most compliance advice is a lawyer's reading of someone else's summary of the regulation. Voidborn Tech works from the regulation itself and the standards committees writing the detail, so you get nuance, not a checklist you could have downloaded.

  • 01
    MSc Applied AI & Data Analytics, University of Bradford (Distinction).
  • 02
    Co-author, AI Applications in Financial Markets.
  • 03
    Years inside heavily regulated financial services, where compliance is a live operational reality, not theory.
The usual offer
A lawyer who hired engineers. Reads the law, guesses at how the system works.
Voidborn Tech
An engineer who understands the law. Reads the system and the article number.
See the standard of work

"A compliant vendor doesn't make you a compliant deployer."

From the worked case study on recruitment AI

A full governance analysis of a CV-screening tool: how it classifies under the Act, why the Article 6(3) exceptions are unavailable once profiling enters, where provider and deployer duties split, and the practical steps an HR function should take before go-live. Every claim tagged to its article. This is what a Voidborn Tech assessment looks like.

Annex III · high-risk Deployer obligations GDPR intersection Human oversight
Read the full case study
How I work

Two stages: a read on where you stand, then the evidence to prove it

The method is the same one behind the case study: start with what the system actually does, classify it with the reasoning shown, and separate what the vendor owes from what you owe. No downloadable checklist could do this, because the answers turn on nuance.

The read

Compliance Check

  • An honest read on whether a system is likely high-risk under the Act
  • Which obligations actually attach: provider, deployer, or both
  • Where the GDPR layer runs in parallel, and where it stacks
  • The one or two things worth doing first
The evidence

Compliance Report

  • A written, primary-source assessment of your specific system
  • Risk classification with the reasoning shown, not just the verdict
  • Provider/deployer split, gap register, and a prioritised action list
  • Documented against the Act and the current standards landscape
  • The kind of trail that holds up in front of an investor or an auditor

Engagements are scoped to the system and the stage you're at. If you'd like to talk one through, get in touch.

Get in touch

Want this level of analysis on your own system?

If the case study is the standard you want reading your AI systems, I'd be glad to hear what you're building.

Email hello@voidborntech.com