AI assurance FAQs: cost, deadlines and scope
Cost is at the top, because that is the question everyone opens with.
How much does AI assurance documentation cost?
Documentation packs are quoted after a 30-minute scoping call, with every deliverable listed before you approve anything. AI oversight for payroll, AP and EOR is $20 per reviewer hour, or $3,000 per reviewer per month. Model testing and code audits are scoped the same way, on our pricing page.
Did the EU AI Act deadline move?
Yes, in part. The Digital Omnibus on AI moved standalone Annex III high-risk obligations to 2 December 2027, and product-embedded high-risk systems to 2 August 2028. The Article 50 transparency obligations were not deferred and applied from 2 August 2026, so disclosure duties are already live.
Which AI assurance service should I start with?
AI Model Testing Services, in almost every case. A risk register, a model card or an EU AI Act file is only as good as the measurement behind it, and writing documentation first usually means rewriting it. Start with a code audit instead if AI wrote most of your codebase.
Do you certify our AI system?
No. We are not a notified body and we do not issue certificates or CE marks. We produce the test evidence and the documentation your own conformity assessment, auditor, insurer or customer security review will ask for, and we say plainly where a gap remains.
Does this replace our lawyer?
No. We prepare technical and process documentation; legal interpretation of how a regulation applies to your business stays with your counsel. Most clients give the pack to their lawyer, who then reviews positions instead of building the whole record from scratch.
What is inside a documentation pack?
A scope statement, a system description, the risk register, data and model cards, the test evidence with dates, the human-oversight design, the monitoring plan and a named owner for each control. Everything is delivered as editable files, not a locked PDF.
Can you test a model you did not build?
Yes, and that is the usual case. We test through your API or a copy of the system, using cases you supply plus adversarial prompts we write. You receive the test set, the scripts and the results, so your team can re-run them later.
How do you handle our data during testing?
NDA and DPA first, then least-privilege named access that is removed at handover. We prefer synthetic or masked records for test sets, and where real records are needed the processing terms, the retention period and the deletion date are written into the contract.