For legal counsel
The determination is yours. The technical facts it turns on are ours.
Technical classification analysis · audit side of the wall · counsel owns the determination

01 / What we establish
Four things a datasheet will not tell you.
Each is a question of technical fact that a legal determination turns on. Each is answered with evidence and with the method used to obtain it, so your advice rests on the system rather than on the vendor's description of itself.
Is it an AI system at all?
Whether the thing infers from inputs how to generate outputs, or is deterministic software wearing the label. Article 3(1) is a technical question before it is a legal one.
Provider, or deployer?
Whether your client's fine-tuning, rebranding, or change of purpose has made them the provider of a system they believed they were merely using. The facts sit in the engineering, not the contract.
What the risk tier turns on
Annex III area, safety-component status, and whether the Article 6(3) derogation genuinely applies: narrow procedural task, preparatory work, or real influence over the outcome. Evidence, not assertion.
General-purpose and systemic risk
Whether a model is general-purpose within Chapter V, and whether training compute, capability, and reach put it near the systemic-risk threshold.
02 / How the analysis runs
Across the full parameter space, not just the model.
The dimensions are the OECD's[02], adopted into the NIST AI Risk Management Framework[01]. A classification that looked only at the model would miss where most of the legal exposure actually sits.
03 / What you receive, and what you do not
A report written to be cited, and to be pulled on.
What you receive
A technical classification report: the evidence, the method used to obtain it, and the limits of what it establishes. Written to be cited in your advice, and to hold up when a regulator or an opposing party pulls on it.
What we will not do
Issue the classification, or give legal advice. We do not tell you the tier your client falls in. We tell you what the system does, and you reach the conclusion you are qualified and insured to reach.
This work sits on the audit side of our independence wall, because it establishes facts rather than building or remediating anything, so it does not bar a later audit of the same system. The safeguards are disclosure before the audit engagement is accepted, and re-performance of the analysis rather than reliance on it. The self-interest threat is named in the IESBA framework[05], and naming it is how it gets managed.
Acting for a client who needs this established?
Tell us the determination you need to reach and what you have been given so far. We will tell you which facts are establishable, which are not, and what the analysis would cost to run.