Applied AI
EU AI Act readiness for UK businesses
EU AI Act readiness is the work of classifying each AI system against the Act’s risk tiers, and building the risk management, technical documentation, logging, human oversight and post-market monitoring that high-risk systems must have before their deadline. Following the Digital Omnibus, standalone high-risk systems in hiring, credit, insurance, education and critical infrastructure must comply by 2 December 2027; AI inside regulated products by 2 August 2028; prohibited practices have applied since February 2025. Hexploits does the engineering side of readiness, and is the core team behind swarmd.ai, an EU AI Act readiness platform for governing AI agents in regulated industries.
A named engineer replies within one working day. A written scope and an indicative price within two.
Who this is for
- UK businesses whose AI output is used in the EU, or who sell AI-enabled software to EU customers.
- Deployers of hiring, credit-scoring, insurance-pricing, education or triage AI, bought or built.
- Providers of AI products and agents who carry the Act’s heavier provider obligations.
- Compliance functions asked to sign off systems they did not build.
What you get
Deliverables, not slogans. Each one appears in the statement of work.
- An inventory of every AI system, bought or built, with its risk classification under the Act and the reasoning written down.
- Provider or deployer determination per system, including whether fine-tuning or modification has made you a provider under Article 25.
- For high-risk systems: risk management records, technical documentation, automatic logging, human-oversight procedures and a post-market monitoring plan.
- Fundamental Rights Impact Assessment support where Article 27 requires it (credit scoring and life/health insurance pricing deployers, public bodies).
- Bias testing against your own data, with results, for systems that make or narrow decisions about people.
- Transparency notices for the people your systems decide about, and AI-literacy material for staff.
- A dated plan to each applicable deadline, and a completed AI section for customer due-diligence questionnaires.
Our engineers work across the major languages, frameworks and cloud platforms. We build on the stack you already run, with technology choices explained in writing before work begins.
How it is delivered
The same four stages as every Hexploits engagement, applied to this capability.
Stage 1
Inventory and classify
Two to four weeks. Every AI system is listed, its use mapped to the Act’s categories and prohibitions, and its role (provider or deployer) determined. Most systems turn out to be limited or minimal risk; the ones that are not get a dated plan.
Stage 2
Gap analysis
Current controls and documentation are compared with what the Act requires for each high-risk system, alongside ISO 42001 where certification is the goal, and gaps are prioritised by deadline and exposure.
Stage 3
Build the controls
Logging, oversight, testing and documentation are built into the systems and the release process, so the evidence is produced by the system running rather than assembled before an audit.
Stage 4
Monitor and maintain
Post-market monitoring, incident handling and periodic review under managed support, with the inventory kept current as systems and guidance change.
Built by the same team
We are the core engineering team behind swarmd.ai
swarmd.ai is an EU AI Act readiness platform for governing AI agents in highly regulated industries: policy enforced on every action an agent takes, tamper-evident audit trails a regulator will accept, per-tenant isolation and customer-owned identity. Hexploits designed and built it end to end in six months. The same patterns are what we apply to a client’s own systems.

How success is measured
Every engagement agrees its measures and the measurement period in writing before work starts.
- Every AI system classified, with the reasoning a regulator or customer can be shown.
- High-risk systems with complete documentation and logging before their applicable deadline.
- Bias and performance testing results on file, refreshed on a schedule.
- Customer and partner due-diligence questionnaires answered from evidence rather than assertion.
Proof
Case studies with numbers, and reviews linked to Google where they were left there.
swarmd.ai · Software vendor · 6 months
Enterprise AI control plane delivered in six months at 75% under budget for a UK software vendor
JobVantage · Recruitment technology · Duration TBC
99.9% availability and sub-100ms responses for a recruitment intelligence platform, at negligible infrastructure cost
Director, IO Solutions
“Fantastic to work with. High level of attention to detail and flawless communication throughout. Would recommend to anyone looking to develop or improve a software product.”

Director, JobVantage
“Working with Hexploits has genuinely been a pleasure, and I see them as my scaling partner for the foreseeable future as JobVantage grows. If you’re looking for a development team who combine strong AI/engineering capability with honesty, flexibility and a real interest in your business, I’d strongly recommend them.”

Questions we get asked
Does the EU AI Act apply to a UK company?
What are the deadlines?
Which systems are high-risk?
Are we a provider or a deployer?
Is this legal advice?
What is swarmd.ai and how is it relevant?
Related
Sectors where this is most often needed
- Compliance and regulation technology
- AI technology companies
- Financial services and payments
- Recruitment and HR technology
- Charities and education
Reading
EU AI Act High-Risk Series, Part 1: Recruitment & HR Tech
CV screening, candidate ranking and performance monitoring tools are high-risk under the EU AI Act, and one interview-scoring feature is banned outright. What a recruitment business or HR technology vendor has to build by December 2027, and why the commercial effect arrives sooner.
EU AI Act High-Risk Series, Part 2: Finance & Insurance
Credit scoring and life or health insurance pricing are high-risk under the EU AI Act, with a mandatory impact assessment for every deployer. What a lender, insurer or payments business has to build by December 2027, and how to do it once for every regulator.
EU AI Act High-Risk Series, Part 3: Education & EdTech
Admissions, grading and exam-monitoring tools are high-risk under the EU AI Act, and emotion recognition in proctoring is banned outright. What universities, exam boards and EdTech vendors have to build by December 2027, and why institutional buyers are already asking.
EU AI Act High-Risk Series, Part 4: Healthcare & MedTech
Healthcare AI has two EU AI Act deadlines eight months apart, and which applies depends on whether your product is legally a medical device. How to classify correctly, what goes in the technical file, and why health-system procurement is already asking.
EU AI Act High-Risk Series, Part 5: Critical Infrastructure
AI managing power grids, water supply or road traffic is high-risk under the EU AI Act only where it is a genuine safety component, and part of the scope test is still draft guidance. How utilities, operators and their vendors should classify, and what to build if they are in scope.
More in applied ai
Internal AI assistants and copilots for UK businesses
AI document and email processing
AI decision support and forecasting
Agentic AI workflows with governance
AI sovereignty: private and EU-hosted AI
AI governance and ISO 42001
AI in payments, credit and fraud under the EU AI Act
AI for recruitment: sourcing, screening and matching automation
EU AI Act for recruitment and HR: high-risk hiring AI explained
AI governance readiness for recruitment and HR businesses
Next step
Request a proposal.
Tell us about the system and the sector. A named engineer replies within one working day. A written scope and an indicative price within two working days of a short scoping call.