EU AI Act · DORA · GDPR · NIS2 · CORA™ · Getting started

FAQ

Answers to the most common questions about compliance obligations, Morclear services, pricing, and how to get started.

The questions organisations ask most often about the EU AI Act, GDPR, DORA, NIS2, and about working with Morclear.

Compliance Essentials

What is the difference between high-risk and low-risk AI?

The EU AI Act sets out high-risk uses in Annex III, primarily HR screening, credit decisions, law enforcement, biometric identification, and critical infrastructure. A CV screening tool falls in scope, a spam filter does not. The free assessment gives you an indicative classification in ten minutes.

Do I need to comply if I am not in the EU?

If you place AI systems on the EU market, or the output of your system is used in the Union, then yes. Article 2 reaches providers established outside the EU on the same terms. US, UK, and APAC organisations with EU customers are in scope.

Which EU AI Act dates actually apply now?

Article 5 prohibitions have applied since February 2025 and general-purpose AI model obligations since August 2025. Article 50 transparency obligations apply from 2 August 2026, alongside registration and market surveillance powers. Annex III standalone high-risk obligations were deferred to 2 December 2027, and AI embedded in regulated products to 2 August 2028, by Regulation (EU) 2026/1744, in force since 27 July 2026.

Is there a grace period for content marking?

A narrow one. Generative AI systems already placed on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking and detection obligation in Article 50(2). Anything placed on the market on or after 2 August 2026 had no transition at all. Content generated before that date does not need retroactive labelling.

What happens if we do not comply?

Breaches of transparency and most other obligations carry fines up to €15 million or 3% of total worldwide annual turnover, whichever is higher. The Article 5 prohibited practices carry up to €35 million or 7%. Supplying incorrect or misleading information to authorities carries up to €7.5 million or 1.5%. Beyond fines, non-compliant systems can be kept off the EU market.

How does the AI Act overlap with GDPR?

Both apply where personal data is processed using AI. GDPR governs the data handling, the AI Act governs the system itself. You need both, and the practical goal is one framework that satisfies each without duplicating the work.

Do I need to hire a legal team?

Not necessarily. Many mid-market organisations combine an external framework with a small internal team, and take legal review at the end. Morclear handles the compliance work rather than the legal opinion.

Morclear Services

How long does implementation take?

Gap Assessment, two weeks. Programme Build, eight to twelve weeks. After that, Managed Compliance runs continuously rather than as a point-in-time audit.

Do you provide legal advice?

No. We provide compliance frameworks, implementation, and managed oversight. All materials carry a disclaimer to that effect, and we recommend legal review of final documentation.

How is your pricing structured?

Engagement-based and confirmed in writing before work begins. Gap Assessment at €999. Programme Build and Managed Compliance are scoped individually. See the services page

Can we move from a gap assessment into a full programme?

Yes, and that is the intended route. The gap assessment establishes what applies to you, and its findings set the scope and price of any programme that follows. There is no obligation to continue.

Do you offer Virtual DPO separately?

Yes. Virtual DPO is available on its own for organisations that need GDPR support without a broader compliance engagement. Learn more

How do you differ from a large consulting firm?

The delivery model rather than the standard. Large firms staff engagements with a partner, managers, and analysts billed hourly over several months. Morclear uses AI for the documentation volume and expert review for the judgement, on a fee agreed before the work starts.

CORA™ in Detail

Is CORA™ self-serve or managed?

Fully managed. Morclear operates the AI modules on your behalf. It is not a tool you log into and run yourself. A client portal is planned as the business scales.

How does continuous monitoring work?

Obligations are tracked on an ongoing basis so that regulatory change and drift in your own programme are picked up as they happen rather than at annual audit. Morclear interprets what changed and updates the programme accordingly.

What happens when an issue is found?

You are notified, with a classification of the issue, the reporting templates that apply, and guidance on whether and how a regulator needs to be told.

Can CORA™ be adapted by sector?

Yes. EU AI Act, DORA, GDPR, NIS2, and ISO 27001 are covered as standard, and the work is adapted to your sector risks and the expectations of your own supervisory authority, whether that is fintech, healthcare, HR technology, or critical infrastructure.

Does CORA™ cover bias and fairness?

Yes, at the governance level. We define the fairness metrics that apply to your system, set out how and when they should be tested, and document the results as part of the evidence pack the AI Act expects for high-risk systems. The testing itself runs against your data and models.

What is Regulatory Radar?

A regulatory change digest covering EU AI Act, DORA, GDPR, NIS2, and ISO 27001, with impact analysis, key date tracking, and deadline alerts. Available on its own at €199 per month, or included in Managed Compliance.

What AI does Morclear use?

CORA™ is powered by the Anthropic Claude API, and every output is reviewed by a person before delivery. Client data is not used to train AI models. Data handling, retention, and processing location are set out in the data processing agreement provided at engagement.

Getting Started

What happens on a first call?

Thirty minutes, free. We go through your organisation, your AI systems, what you have already done, and your timeline. You leave knowing which frameworks apply and whether Morclear is the right fit. Fees and timelines are not quoted on that call, they follow in a written scope.

Who is Morclear built for?

Mid-market organisations of roughly 50 to 500 people, technology-enabled firms in fintech, HR technology, health technology, and critical infrastructure, and any organisation with AI systems in scope of the EU AI Act or with DORA and NIS2 obligations.

How do we start?

1 Free ten-minute assessment. 2 Free 30-minute scoping call. 3 Gap Assessment over two weeks. 4 Programme Build or Managed Compliance.

Can we pay monthly?

For Programme Build and Managed Compliance, payment terms are flexible and monthly instalments can be discussed during the scoping call.

Who this is for

Organisations deploying high-risk AI systems
Financial services firms making credit decisions
Healthcare providers using AI in diagnostics
HR technology companies doing employment screening
Mid-market organisations without a dedicated compliance team
Organisations that have received a regulatory enquiry
Firms preparing for a GDPR or audit review
Teams looking to automate compliance work

How it works

Start with the free ten-minute assessment to understand your scope, then book a 30-minute scoping call. We go through your situation and set out which engagement fits, whether that is a Gap Assessment, a Programme Build, or Managed Compliance.

Still have questions?

Book a free scoping call with the Morclear team. We will go through what applies to your organisation and what a sensible first step looks like.

Run Free AI Act Assessment Book a Scoping Call

Morclear compliance services are provided as practical compliance support and do not constitute legal advice.