Assessment & classification
A guided questionnaire routes each system through Annex I vs Annex III, the Article 6(3) filter, Article 25 provider-status changes, and Article 2 exclusions — returning a defensible risk tier and the date it applies.
Product
Not a checklist and not a score — a live register, an obligations engine, and an evidence trail that stays current as the law phases in.
A guided questionnaire routes each system through Annex I vs Annex III, the Article 6(3) filter, Article 25 provider-status changes, and Article 2 exclusions — returning a defensible risk tier and the date it applies.
Every requirement carries its source article, purpose, compliant-if criteria, concrete actions and expected evidence — scoped to your role so you only see the duties that bind you.
Attach documents per obligation, capture a dated sign-off, and lock records with a tamper-evident audit trail. The bridge from “we think we comply” to “here is the proof.”
One register of every AI system: owner, risk tier, frameworks, lifecycle stage, readiness and open gaps — the inventory the Act assumes you already keep.
A regime-aware calendar counts down each application date; incident timelines encode the real reporting clocks, from 2-day critical-infrastructure alerts to the 15-day serious-incident window.
An indicative crosswalk maps obligations onto AI-management and information-security controls — so AI Act work moves you toward standards readiness too.
How it works
Add your AI systems and run a guided assessment. Get each system's risk tier and the exact regimes and articles that apply to your role.
Each system gets a scoped list of obligations with owners, due dates and status. Attach evidence, resolve gaps, sign off.
The register, evidence and audit trail stay current as dates arrive and systems change.
Register your first system in minutes and get the obligations that actually apply to you.