Who classifies your AI system’s risk level and ships the audit log + technical file? LMXAI delivers the operational evidence pack from Leiden — not only a legal memo.
Also see: compliance deliverable insight · practical AI Act guide
LMXAI helps organisations turn EU AI Act requirements into an engineering workstream: system inventory, role and risk classification, technical evidence, audit logging, human-oversight controls and production documentation. The objective is to connect regulatory requirements to the way the AI system is actually designed, deployed and operated.
LMXAI is based in Leiden, the Netherlands, and works on production AI architecture, sovereign LLM infrastructure, agentic systems, RAG, evaluation and observability. This makes the compliance work technical by default rather than a policy document disconnected from the running system.
AI Act obligations depend on what the system does, how it is used, who places it on the market or puts it into service, and which role the organisation has in the AI value chain.
A practical assessment therefore starts with questions such as:
The output is a system-specific classification record rather than a one-size-fits-all compliance label.
We document the actual AI components, models, data flows, integrations, intended purpose and organisational ownership. This creates the base layer for deciding which AI Act requirements apply.
The system is mapped against the relevant AI Act categories and current European Commission guidance. Where a high-risk classification may be relevant, the assessment records the use case, reasoning, assumptions and evidence that should be reviewed and maintained.
LMXAI can structure the technical file around the system that exists in production, including:
The goal is to make documentation maintainable as the system changes, not produce a static PDF that becomes obsolete after the next release.
For AI systems that need stronger traceability, LMXAI can design logging across the application and model workflow. Depending on the architecture, this can include:
Sensitive content does not need to be logged indiscriminately. Retention, redaction and access to logs should follow the organisation's privacy and security model.
For systems that recommend or execute consequential actions, LMXAI can translate human-oversight requirements into concrete workflow controls: approval nodes, escalation paths, role-based permissions, review queues and explicit stop conditions.
A compliance claim is stronger when the organisation can show how the system was tested. LMXAI can create repeatable evaluation sets and release gates for model quality, retrieval grounding, tool use, safety behavior, latency and regressions.
Modern enterprise AI is often more than one model call. A user request may trigger retrieval, multiple tools, an agent workflow and several model decisions.
For these systems, traceability should cover the whole execution path, not just the final answer.
LMXAI works with technologies such as LangGraph, FastAPI, OpenTelemetry and Phoenix to make workflow state, tool execution, retrieval and model calls observable. For sovereign deployments, the same control layer can be combined with self-hosted inference using vLLM and Kubernetes.
The AI Act uses a risk-based framework. The European Commission's current guidance distinguishes prohibited practices, high-risk systems, transparency-related obligations and systems presenting minimal or no risk. High-risk classification is tied to the system's intended use and the categories in Article 6 and the relevant annexes, while separate rules apply to general-purpose AI models and certain transparency scenarios.
Commission guidance also emphasises documentation, logging and traceability, human oversight, robustness, cybersecurity and risk management for relevant high-risk systems. Transparency obligations under Article 50 started applying on 2 August 2026.
Because guidance and implementation timelines continue to evolve, LMXAI keeps the engineering evidence modular: classification assumptions, controls and documentation can be updated without rebuilding the AI product.
A typical engagement can be structured as:
The exact package depends on the system, but may include:
LMXAI combines AI architecture and implementation with AI Act-oriented technical evidence. That means the same partner can assess the system, identify missing controls and implement logging, evaluation, governance and production changes.
Discuss your AI Act engineering requirements with LMXAI
Need more detail? Chat with Savion’s AI legal assistants for EU AI Act questions — obligations, risk tiers and documentation checklists.