AI governance and compliance · Netherlands
From AI Act obligation to evidence that holds up.
Embed AI is the Dutch advisory firm for AI governance. We map where AI is used and bought across your organisation, classify it against the EU AI Act, and build the dossier you answer your customers, your board and regulators with.
4 minutes. No form, no email address.
What you are left with
The dossier
- AI inventory with named ownership per system
- Risk classification per usecase, against Annex III and Article 50
- Gap analysis with priorities and a 30-60-90 day roadmap
- Supplier evidence and the contractual control points
- Article 4 evidence per role, with demonstrable measures
- An evidence pack that answers a customer question within a day
Fixed scope. Delivery guarantee after scope freeze. No vendor lock-in.
Trusted by
Banks, publishers, municipalities, utilities and public services.

Who you get at the table
Zahed Ashkara
Lawyer · Certified AI Compliance Officer · AI governance consultant
Zahed sits on the NEN standards committee for Artificial Intelligence & Big Data, the Dutch mirror committee of ISO/IEC JTC 1/SC 42 and CEN-CENELEC JTC 21. Those are the bodies where the standards under the EU AI Act are written. You get it first hand, not as the summary of a summary.
No junior team and no hand-off: you work with the specialist who actually builds your dossier.
- Embed AI: training institution recognised by the NOvA (2026)
- CAICO, Certified AI Compliance Officer (ICTRecht)
- Certified AI Meets Law
- Member, NEN standards committee AI & Big Data
- Master of Public Law, Vrije Universiteit Amsterdam
The four questions
What a board wants answered before AI goes ahead
Every engagement answers the same four questions. If one is left open, the dossier is not finished.
- 01
Where is AI, actually?
An inventory of what runs, what was bought and what staff started using on their own, with an owner per system.
- 02
What is it, legally?
Classification per usecase against Annex III and Article 50, and the split of roles between provider and deployer.
- 03
What comes first?
A gap analysis that orders obligations by risk rather than by chapter number.
- 04
What do you prove it with?
An evidence pack: documentation, supplier evidence, Article 4 evidence per role and the human oversight points.
Approach
Three steps, fixed scope
Every engagement runs the same line, so you know upfront what lands and when.
- 01
Intake
We walk through your AI use, suppliers and first obligations and set the scope. After that it is fixed.
- 02
Sprint
Inventory, classification, gap analysis and ownership, built with your people rather than around them.
- 03
Dossier
The evidence is handed over in a form your own team can maintain, without depending on us.
Fixed scope · Delivery guarantee after scope freeze · One-time rework guarantee · No vendor lock-in
Starting points
Three ways to begin
From a free call to a parallel engagement that builds the full dossier in one run.
Gap call
A short call about your AI use, your suppliers and the obligations that come with them.
You know the logical first step: inventory, classification, supplier evidence, Article 4 or DPIA and FRIA.
No obligation. For organisations that use, buy or supply AI.
Request the callMost chosenAI Act Readiness Sprint
From scattered AI signals to one shared baseline: inventory, classification, gap analysis, ownership and roadmap.
You know what is running, where ownership is missing and which risks need attention first.
The starting point when you want governable control without pulling the full dossier immediately.
Plan the readiness intakeFull engagementAI Act Compliance Bundle
Readiness, supplier evidence, Article 4 evidence, policy and implementation in one engagement with one plan.
For organisations that do not only want to know where they stand, but want to build the dossier straight away.
Logical when several AI systems, suppliers or decision lines are involved.
Discuss the bundleTwo tracks under the EU AI Act
Which track affects you?
The regulation splits your obligations. The track decides what you have to demonstrate, and when.
High-risk AI
AI that co-decides about people: biometrics, critical infrastructure, education, work, essential services, law enforcement, migration and justice.
View the high-risk domainsArticle 50Transparency obligation
Not high-risk AI, but a chatbot, AI-generated content, deepfakes or emotion recognition? Then the transparency obligations apply.
View the transparency obligationThe ecosystem
We build the tools we use ourselves
Three platforms that together cover the knowledge layer, the evidence layer and the implementation layer. Our clients get access to all of it.
EU AI Act per domain
High-risk AI and the transparency obligation worked out per domain, with risk check, evidence pack and human oversight.
LearnWize
The platform for Article 4 evidence. Role-based training, certification and progress per employee.
Praxikon
Knowledge platform with more than 200 articles, practical guides and an extensive glossary on the EU AI Act.
Frequently asked questions
We sell AI to organisations. What does this give us commercially?
Customers and public procurement increasingly ask for demonstrable AI Act and GDPR compliance of your system. The evidence pack makes that story usable for sales, legal and product, so you stop losing deals to compliance doubt.
We do not know whether our AI is high-risk. Can you determine that?
Yes. We classify your concrete usecases against Annex III and determine whether you fall under high-risk, under the Article 50 transparency obligation, or both. You then get an improvement plan with priorities.
How does this compare to Big Four and law firms?
You get a working dossier rather than a memo, and you work directly with the specialist instead of a junior team. We combine the legal framework, practical AI adoption and demonstrable AI literacy in one engagement, with our own tools for the evidence.
What does an engagement cost?
Scope and investment are set after the intake, based on the number of AI systems, processes and suppliers and the evidence layer required. Every engagement has a fixed scope and a delivery guarantee after scope freeze, so no open end and no billing surprises.
Do you work for the public sector?
Yes. Part of our client base sits with municipalities, utilities and public services, where the GDPR, principles of good administration and the FRIA apply alongside the AI Act. That combination is built into the approach.
Next step
Start with the question you cannot answer today
Book a short gap call, or take the quickscan first and bring the outcome into the conversation.
