In July 2026 the Digital Omnibus softened the AI literacy obligation to one of effort. It left Article 26(2) untouched: by 2 December 2027, deployers of high-risk AI must assign oversight to named people with the necessary competence, training and authority.
Most institutions completed AI literacy training in 2025. Very few could name the people overseeing each high-risk system and show they were competent to do it. These are not the same artefact.
What most institutions have
What a supervisor asks for
Three weeks. Fixed scope, fixed fee. It produces the evidence file — not a training proposal.
Week One
We map every role that operates an AI system, and every system it operates. Population in scope, high-risk classification, and the roles nobody had counted — usually the largest finding of the three weeks.
Week Two
We calibrate the competence standard to your institution and assess a defensible sample of each role tier. Self-rating establishes confidence; the assessed component establishes competence. The distance between them is itself a finding.
Week Three
Gap register, remediation plan with owners and dates, and a draft attestation formatted for CRO and CCO sign-off. Delivered to your Compliance function, not to L&D.
Every role, every AI system it operates, high-risk flag, headcount, named role owner.
Thirty competencies across six domains, with the required level differentiated by role tier — because oversight competence under Article 26(2) attaches to named individuals and the systems they actually operate, not to a uniform course.
A defensible sample of each tier, scored against the standard, with the confidence gap surfaced separately.
Each competency below standard, the population affected, the action, the owner, the committed date.
Method statement, coverage, residual gaps, change triggers, and a sign-off block. Ready to take to committee.
This is for you if
This is not
We will come back with scope, fee and the earliest start date. If the review is not the right fit, we will say so.