Most AI consultants are selling a deadline that moved.
We're here about the one that already arrived. Nuria Labs helps regulated European organisations prove their AI is compliant — and then make it genuinely useful.
One deadline moved. The other one landed.
In June 2026 the Digital Omnibus deferred the Annex III high-risk obligations to December 2027. The market heard "AI Act delayed" and a great deal of compliance work quietly stopped. But the transparency duties under Article 50 were not deferred — and they apply far more broadly than the high-risk rules ever did.
One obligation is live today. The other has sixteen months. Most of the market is preparing for the wrong one.
Article 50 transparency
Any AI that interacts with people or generates content, at any risk tier. Disclosure of AI interaction, machine-readable marking of synthetic content, deepfake disclosure. Exposure up to €15 million or 3% of worldwide turnover.
Annex III high-risk
Risk management across the lifecycle, data governance, technical documentation, logging, human oversight, conformity assessment. Sixteen months is less time than it sounds — but it is not this month's problem.
The obligation attaches to the organisation deploying the system — not to the vendor who built it.
Start small. Prove it. Then go further.
Nobody should buy a transformation programme from someone they met last week. Every engagement starts with something small enough to say yes to.
We call it the Nuria Method: an X-ray that shows you where you stand, a prescription that closes the gaps, and a therapy schedule that keeps them closed. You never have to take our word for anything — you can test every claim we make on your own organisation.
Read the Method, then watch it run →Readiness Check
Ten questions, two minutes. A scored result with each gap mapped to the specific obligation behind it. No account, no sales sequence.
Compliance Pack
The finished documents. Working inventory register with obligation logic, disclosure copy in four languages, marking brief for engineering, gap register, board template.
Transparency Audit
Two days. We inventory every AI touchpoint including what's embedded in your purchased software, map each to its obligations, and hand you a remediation plan with named owners.
Remediation Sprint
Closing the gaps: disclosure written and placed, machine-readable marking specified with your engineers, inventory built and handed over, evidence pack assembled, internal owner trained.
Copilot & AI Adoption
Once the estate is catalogued, most organisations discover they're using far more AI than they knew — and using it badly. Adoption assessment, 90-day plan, prompt library, training, community launch.
AI Governance Advisory
Quarterly re-assessment as the estate changes, regulatory monitoring through to December 2027, review of new systems before deployment, and a named advisor on call.
Article 50 is the front door. It is not the whole house.
Compliance is where most organisations meet us, because it has a date attached. It is rarely where the work ends — once the AI estate is catalogued, the same organisations discover they are using far more AI than they knew, governing none of it, and training nobody to use it well. Five capabilities, one method.
AI Governance & Compliance
EU AI Act readiness across both regimes — the transparency obligations live since August 2026, and the high-risk requirements landing December 2027. Inventory, obligation mapping, evidence trails, named owners, quarterly re-test.
Start with the free X-ray →AI Adoption & Copilot
Most organisations have bought the licences and stopped there. Adoption assessment, a 90-day rollout plan, prompt libraries built for your actual work, champion networks and the change management that makes any of it stick.
Talk about adoption →AI Transformation
Where AI changes the operating model rather than the toolbar. Opportunity mapping across functions, business cases with defensible numbers, sequencing, and the governance to keep it safe as it scales.
Talk about transformation →AI Fluency Academy
Article 4 of the AI Act obliges organisations to ensure AI literacy among staff. Six tracks, twenty-eight modules, four certifications — foundation to practitioner, delivered live or licensed for you to run internally.
Talk about the Academy →The Vault
The assessment engine behind the method, productised — stored assessments, evidence capture, scheduled re-tests, before-and-after deltas and anonymised sector benchmarks. It is what turns a one-off report into a compliance position you can prove twelve months later. Currently in development and not yet available to clients.
Request early access →One AI transformation partner. From governance to adoption, from strategy to fluency — measured through one method.
Regulated, mid-sized, and short of AI governance capability
200 to 5,000 people. Large enough to have genuine AI exposure, small enough that nobody internally owns it yet.
Insurance, financial services, pharma, public sector — anywhere a regulator already pays attention.
Operating anywhere the EU AI Act reaches — including organisations outside the EU that serve European customers.
Where compliance carries the exposure — we work with DPOs, risk and legal, not only with IT.
Two minutes will tell you
whether you have a problem.
Run the free readiness check. If the score is uncomfortable, we should talk. If it isn't, you've spent two minutes and learned something.