EU AI Act Compliance Accelerator

EU AI Act enforcement begins in 121 days.
Is your organization ready?

The EU AI Act (Regulation (EU) 2024/1689) takes full effect on August 2, 2026. Penalties reach €35 million or 7% of global turnover. The EU AI Act Compliance Accelerator is 11 article-mapped compliance documents that deploy a complete governance framework — covering prohibited practices, deployer obligations, risk classification, and fundamental rights assessment.

Instant download · 11 editable documents · EU AI Act article-level mappings

EU_AI_Act_Compliance_Accelerator/
01 Acceptable Use Policy
Art. 5 prohibited practices · Art. 50 transparency
11 FRIA Template
Art. 27 fundamental rights impact assessment
07 AI Risk Register
24 risks incl. Art. 5, Annex III, Art. 26 deployer
+ 8 more documents included
Vendor risk · incident response · training · board statement
V3 · Updated April 2026 · 11 documents · Article-level mappings
Built for
Legal & Compliance
CISO & Security
HR & People Ops
General Counsel
Privacy Officers
salishsecurity.ai
The Problem

AI adoption outpaced AI governance.

Every organization using AI is accumulating policy debt. Most won't discover the cost until a regulator, a vendor breach, or a board question forces the documentation they never wrote.

01
📋

No written policies

Employees are using AI tools — for work tasks, with company data, on personal devices — and most organizations have no documented rules governing any of it.

02
⚖️

Regulators are moving

EU AI Act, CPRA ADMT, NYC Local Law 144, Colorado SB 205, FTC enforcement — the regulatory moment for AI governance is here. Undocumented organizations are exposed.

03
🏛️

The board needs documentation

Post-Caremark, directors carry an affirmative oversight obligation for material AI risks. Without a governance framework on paper, that obligation exists but goes unfulfilled.

What's Inside

Ten documents. Complete coverage.

Every layer of AI governance — from employee acceptable use to board oversight — in professionally drafted, fully editable Word documents.

01

Acceptable Use Policy for AI Tools

14 prohibited use categories, disciplinary proportionality framework, trade secret protections, automated decision-making rights, and regulatory monitoring obligations.

Foundation
02

AI Vendor Risk Assessment Framework

Tiered vendor assessment methodology, GDPR Article 28 checklist, no-training breach remedies, $500K liquidated damages template, and insurance/indemnification requirements.

Vendor Risk
03

Data Classification & AI Input/Output Controls

Four-class data taxonomy, CPRA ADMT opt-out requirements, GDPR transparency obligations, DPIA triggers, copyright review workflow, and employment AI law compliance.

Data
04

Incident Response Addendum for AI Systems

AI-specific incident classification, concrete breach notification timelines (GDPR 72h, HIPAA 60d, SEC 4BD), vendor AI breach procedure, and litigation hold requirements.

IR
05

Employee AI Acknowledgment & Training Checklist

Signed acknowledgment form with baseline disclosure attestation, ADA carve-out for access suspension, personal liability notice, and annual recertification framework.

HR / Training
06

AI Vendor Security Questionnaire

50+ questions across 8 sections: vendor overview, data handling, security controls, AI-specific security, compliance certifications, contractual terms, EU AI Act, and FCRA/ECOA.

Procurement
07

AI Risk Register Template

17 pre-populated risks across 6 categories with likelihood, impact, current controls, control gaps, and treatment — covering data exposure, security attacks, compliance, and governance.

Risk
08

Shadow AI Discovery & Remediation Runbook

Step-by-step IT procedures for finding unauthorized AI tools, trade secret triage process, severity triage matrix, three remediation paths, and monthly reporting framework.

Operations
09

AI Governance Quick Reference Card

Single-page employee-facing reference: data decision matrix, approved tools reminder, incident response steps, emerging law alert, and board oversight summary.

Reference
10

Board AI Risk Oversight Statement

Board-level governance instrument documenting Caremark director oversight obligations, materiality thresholds for immediate notification, and reporting cadence — with signature block.

Governance
Who It's For

Built for the people who own this problem.

AI governance sits at the intersection of legal, security, and operations. This pack gives each team what it needs to move.

Role

Legal, GRC & Compliance

AI-specific law is landing fast and your existing frameworks weren't built for it. Each document maps explicitly to GDPR, CPRA, EU AI Act, SOC 2, ISO 27001, and NIST AI RMF.

Board asking about AI risk exposure
Regulator or auditor requesting AI governance docs
No written AI policies in place
Role

CISO & Security

You have the technical controls. Now you need the legal and policy infrastructure to match — vendor DPA requirements, incident response timelines, shadow AI procedures, and board documentation.

Vendor risk program needs AI-specific controls
Shadow AI proliferating without governance
IR process doesn't cover AI incidents
Role

HR & People Operations

Employees are using AI tools for work with no documented rules. You need signed acknowledgments, training records, a disciplinary framework, and ADA-compliant suspension procedures.

No employee AI acceptable use policy
AI used in hiring or performance decisions
Training and acknowledgment records needed
How It Works

Templates, not theory.

No setup, no software, no consulting engagement. Download, customize with your organization details, and implement.

01

Download & review

Instant access to 10 Word documents. Each includes regulatory citations, an implementation checklist, and compliance alignment tables.

02

Customize with your details

Fill in your organization name, contacts, dates, and any organization-specific thresholds. Most documents can be customized in under 30 minutes.

03

Execute & document

Collect employee acknowledgments, document board approval, and file governance instruments. Exit with a documented, auditable AI governance program.

Pricing

Choose Your Implementation Level

All tiers include the complete 11-document compliance framework with EU AI Act article-level mappings. Higher tiers add structured implementation guidance and expert advisory.

GRC consultants build this for $15,000–$25,000 over 6–8 weeks.

Compliance Document Library
$997
One-time payment
  • 11 compliance documents with article-level mappings
  • FRIA template (Art. 27)
  • 90-day implementation roadmap
  • Article-to-obligation mapping reference
  • 12 months of quarterly updates
  • 7-day money-back guarantee
Accelerator + Advisory
$4,997
One-time payment
  • Everything in Guided Implementation
  • Custom compliance gap assessment
  • 2× 60-minute live advisory sessions
  • Custom policy review with written feedback
  • Priority support through Aug 2, 2026
  • 7-day money-back guarantee

Secure checkout via Paddle · Instant document delivery · 7-day money-back guarantee

About
We built the governance framework we wished existed when the regulators were already asking questions and the policies were already overdue.

Salish AI Security Lab produces vendor-agnostic research, frameworks, and policy templates for organizations deploying AI. Our work is grounded in applied security research and legal analysis — built for compliance, legal, and security teams who need to implement governance, not just understand it.

We work selectively with organizations deploying AI on assessments and advisory engagements. The EU AI Act Compliance Accelerator is how we make our methodology available to teams who need the tools to implement governance themselves — without a consulting engagement.

Policy documents included 10 documents · V2
Regulatory frameworks covered GDPR · CPRA · EU AI Act · NYC LL144
Framework alignment SOC 2 · ISO 27001 · NIST AI RMF
Document format Editable Word (.docx)
Assessment engagements Referral · selective
Region Salish Sea · Pacific NW