From risk classification to an audit-ready dossier. Handled.
Meeting the EU AI Act shouldn’t mean drowning in spreadsheets. This is a guided, four-step compliance pipeline that maps the obligations of Regulation (EU) 2024/1689 straight onto your tech, design, PM, and legal workflows.
- 01Classify
- 02ALTAI gap audit
- 03Evidence backlog
- 04Compliance Passport
Lawyers don’t write code. Engineers don’t read 400-page regulations.
So compliance falls in the gap between them: legal advice that never becomes a ticket, and engineering work that never makes it into the dossier. The Act doesn’t care which side dropped it.
The traditional legal route
- Expensive external auditors
- Disconnected Notion templates
- Static spreadsheets no one maintains
- Advice that never becomes UI or tickets
A product-led compliance engine
- Automated risk tiering
- Role-tagged backlogs: [TECH] [DES] [PM] [LEG]
- Obligations linked to real PRs and Figma specs
- Instant, audit-grade dossier generation
Treat the Act as engineering and design quality (concrete, role-based, evidence-driven) and compliance stops being a separate project you dread and becomes something you can actually ship.
Four steps, from classification to a signed dossier
Each step hands a concrete output to the next: no restart, no re-keying. You always know where the system stands and what’s left to prove.
Risk & role classification
Answer a short set of questions to place your system in its risk tier (e.g. high-risk under Annex III) and settle your legal role: Provider or Deployer.
Output: Clear legal standing and the applicable assessment route: e.g. Annex VI internal control.
ALTAI trustworthy-AI gap audit
Evaluate the system across the seven Trustworthy-AI dimensions: human agency, technical robustness, privacy, transparency, diversity, societal well-being, and accountability.
Output: An unfiltered gap index that surfaces the operational controls you're missing.
Role-based obligation register
Each gap becomes a concrete, assigned task, tagged to the discipline that owns it:
- [TECH]Stop/abort controls (Art 14), decision logging (Art 12), accuracy monitoring (Art 15).
- [DES]AI-disclosure components (Art 50), user guidance and instructions-for-use (Art 13).
- [PM]Bias-testing metrics (Art 10), risk-management logs (Art 9).
- [LEG]Privacy intake, auditability packages, standards mapping.
Output: A verifiable evidence trail, each task linked to a GitHub PR, Jira ticket, or doc.
Market readiness & Compliance Passport
Generate the final regulatory artefacts for market authorisation and executive sign-off, assembled from the evidence you've attached.
Output: A downloadable Annex V EU Declaration of Conformity and a full EU AI Act Compliance Passport (PDF).
Outputs built for internal risk boards and external auditors
EU AI Act Compliance Passport
A clean, single-page summary: readiness badges, evidence lineage, and gated sign-off blocks a risk board can read at a glance.
Annex V Declaration of Conformity
A pre-filled legal template referencing Regulation (EU) 2024/1689 and the standards you applied, such as ISO/IEC 42001.
Evidence logbook
Traceable proof linking every Article requirement directly to the code PR, design file, or policy doc that satisfies it.
Continuous oversight tracker
A post-market monitoring plan, serious-incident response playbooks, and the triggers that should prompt a retrain.
Built for teams launching AI in Europe
Product managers & tech leads
Turn dense regulatory articles into a clear engineering backlog, without hiring specialised legal staff to translate them first.
Design & UX leads
Make sure AI components, user disclosures, and human-oversight controls actually satisfy Articles 13, 14, and 50.
Founders & in-house legal
Hand an enterprise buyer, auditor, or regulator an instant, verifiable Compliance Passport instead of a promise.
Compliance isn’t a legal tax. It’s product quality.
Proving your AI meets the rules isn’t a separate chore bolted on at the end: it’s the natural close of building it well. It’s one of four questions every AI team keeps asking, in no fixed order: what you anticipate, whether people trust it, and who’s actually in front of it all shape what you have to comply with. Get those right and the dossier mostly writes itself: compliance becomes evidence of quality you already built, not a scramble to manufacture it.
Before you start
Does this tool replace formal legal counsel or a Notified Body?
No. It's a structured self-assessment engine, not legal advice. It gets you to a defensible, evidence-backed position fast, but for a binding opinion, or where a Notified Body conformity assessment is required, you still involve qualified counsel and the designated body. The tool makes their job faster by handing over an organised dossier instead of a blank page.
What's the difference between a Provider and a Deployer under the Act?
A Provider develops an AI system (or has it developed) and places it on the market under its own name; a Deployer uses an AI system under its own authority in the course of its activity. The obligations differ sharply: Providers carry the bulk of the conformity, documentation, and post-market duties. Step 01 settles which role you're in first, because it changes the entire obligation set.
How does self-assessment under Annex VI (Internal Control) work here?
For high-risk systems eligible for the internal-control route, you self-assess conformity without a Notified Body. The tool walks that path: it maps your classification to the applicable route, runs the ALTAI gap audit, and assembles the technical documentation and Declaration of Conformity that Annex VI expects, with the evidence trail to back each claim.
Can I attach real development evidence: GitHub PRs, Figma files, Jira tickets?
Yes, that's the point. Each obligation in the register is a slot you attach real proof to: the PR that added the stop control, the Figma frame with the AI disclosure, the Jira ticket for bias testing. The evidence logbook keeps that lineage, so every Article requirement traces to the artefact that satisfies it.
Is the tool updated as new harmonised standards and guidelines are released?
Yes. The Act is a moving target: CEN-CENELEC harmonised standards and Commission guidance are still landing. The tool tracks the regulation and its applied standards (e.g. ISO/IEC 42001) and updates the obligation set and templates as official guidance is published, so your assessment reflects the current expectation, not last year's.
More questions? See the full FAQ →
Ready to clear the EU AI Act without the drag?
Classify your system and run your initial gap assessment in under five minutes. Free to start.
Self-assessment ready · Annex V & Passport generation included · No credit card required