Noēsiss

Strategic AI consulting · EU AI Act · GDPR

Every clean balance sheet can hide something.

Run the lens across the numbers. The problems you can't see are the ones that cost you: fines, failed audits, automation that never ships. Noēsiss either finds them first, or deploys systems that never need to be found.

Move the lens across the statement

Statement of financial position€ · audited

Assets

Cash & equivalents€ 2,140,000

Liabilities & Equity

Trade payables€ 2,880,000
Provisions€ 410,000
Shareholders' equity€ 12,700,000

Off balance sheet

Regulatory radar

We watch the laws so you don't have to. Hover a milestone.

CriticalAI Act · Feb 2025

Prohibited AI banned

Unacceptable-risk systems like social scoring and untargeted face-scraping are banned EU-wide. Using one is an immediate breach.

The price of getting it wrong

The fines are not theoretical.

AI Act · GDPR

Two regulations now set the ceiling for almost every European company that touches data or AI. The penalties are deliberately large enough to hurt, and they are levied on global turnover, not local profit.

EU AI Act

€35M or 7%

of global annual turnover, whichever is higher

Top tier: using a banned ('unacceptable-risk') AI system.

AI Act · high-risk

€15M or 3%

of global annual turnover, whichever is higher

HR, credit scoring, biometrics, critical infrastructure.

GDPR

€20M or 4%

of global annual turnover, whichever is higher

Unlawful processing, no valid legal basis, weak security.

How exposed you already are

  • A 200-person company using an AI CV-screenerHigh-risk under the AI Act: needs conformity assessment plus a DPIA, or faces up to €15M.
  • A retailer running a customer-service chatbotMust disclose it's an AI (Art. 50) and document its data use, or risk GDPR action.
  • Any firm buying an AI tool from a vendorYou stay liable as the deployer. 'The vendor handles it' is not a defence.

Most companies are already exposed and don't know where. That's the gap we close.

See how we fix it →

Services

One beam, four disciplines.

Through our lens, we use 4 services in order to deliver compliant systems and solutions.

EU AI Act compliance

We classify where each of your systems falls and produce the documentation regulators expect, so you ship AI your customers can trust.

  • Risk classification (Prohibited → High → Limited → Minimal)
  • Conformity assessment & technical documentation
  • Human-oversight and logging design
  • GPAI obligations & FRIA

GDPR alignment

Compliance as a design constraint, not a paperwork tax. We make data protection part of the architecture.

  • DPIA (Art. 35) & prior consultation (Art. 36)
  • Lawful-basis & special-category review
  • Data-flow mapping for AI processing
  • Vendor & sub-processor assessment

AI automations & systems

Tailor-made for each business. From pilot to production, we design, build, integrate and hand over, with monitoring in place and your team trained to run it.

  • Process automation & systems integration
  • Custom AI workflows, tailored to your business
  • Model fine-tuning where it pays
  • Team enablement & handover

AI strategy

We turn uncertainty into a prioritised roadmap with honest ROI, human judgement kept firmly in the loop.

  • Executive AI workshops
  • Use-case identification & readiness
  • Business-case modelling
  • Custom roadmap & tech-stack advisory

Deterministic · not generative

Check your exposure in four questions.

The verdict comes from the EU AI Act and GDPR regulations own logic. Noēsiss never lets an AI invent your compliance answer.

Four questions
AI Act classificationMinimal-risk

Under the EU AI Act this system is minimal-risk. Under the GDPR it requires no personal-data processing.

GDPR posture
Not in scope

Key obligations

  • Art 4

Exposure

the GDPR and AI Act tiers shown above

Regulation (EU) 2024/1689 (EU AI Act)

Indicative classification under Regulation (EU) 2024/1689 and the GDPR. Not legal advice.

Process

From first call to a running system.

  1. 01

    Strategic discovery call

    A focused conversation on your business, capabilities and ambitions. We leave with three to five viable opportunities.

  2. 02

    Full assessment

    A workshop auditing processes, data, compliance posture and realistic ROI. You walk out with an actionable roadmap.

  3. 03

    Implementation

    We build the highest-impact use case end-to-end, prove value in the real environment, and keep risk contained.

  4. 04

    Scale

    Roll proven solutions across the business, tune continuously, and hand the keys to a team trained to run it.

The Noēsiss Prism · Free analysis

See where you're exposed, before a regulator does.

The Prism is the deterministic engine behind this page. Request access, and once we approve you, you run your own confidential assessment, free. It scores every system against the EU AI Act and GDPR and shows you exactly where the light bends red.

What the Prism revealsAI credit scoring

Noēsiss Prism · scanHigh-risk
AI Act classHigh-risk · III(5)(b)
GDPR postureDPIA required (Art 35)
Automated decisionsArt 22 · no human review
FRIA (Art 27)Required, not done
Obligations to meet26 triggered

Where it landsEU AI Act risk tier

Exposed

HIGH-RISK

26 obligations · DPIA required (Art 35) · up to €15M or 3%

MinimalLimitedHigh-riskProhibited

Free once approved by the Noēsiss team.

Request your Prism analysis

We review every request by hand and send the Prism to the businesses we can genuinely help. No obligation, and we reply within 24 hours.

Prefer email? Write to contact@noesiss.eu

Indicative scoping read, not legal advice.

Let's bring your system into focus.

A focused 30-minute call, the discovery where you leave with a clearer sense of where AI pays off for you, and where it doesn't.