EU AI ActThe AI literacy duty applies now to every organisation using AI·and Article 50 transparency since August 2026·high-risk follows in 458 daysCheck your exposure →
AI governance you can
put in front of an auditor.
Score your readiness, register every AI system, and prove the duties that actually apply — not the ones the Act puts on somebody else.
Not ready to answer 40 questions? Check your exposure in 3 questionsno sign-up
npm i -g e-ari-verifyverified by anyoneAnyone can verify a sealed export — no account, no trust required.see
Illustration: an animated demonstration of the E-ARI assessment pipeline scoring a sample organisation. It contains no information about your own assessment.
Most of the Act is not addressed to you
Duties attach to a specific operator. We show only the ones that attach to yours — each naming its article, so you can check the scoping rather than trust it.
Deploying a chatbot
limited risk
Live now
12obligations
Literacy, transparency, all eight prohibitions, value-chain duties.
Deploying a screening tool
high risk
From 2 Dec 2027
20obligations
Adds human oversight, monitoring, incident reporting, a FRIA.
Providing the model itself
high risk
From 2 Dec 2027
47obligations
Full Chapter III duties, Annex IV documentation, conformity assessment.
Each also names how it can be satisfied, so nothing sits on your list that you have no way to discharge.
Built for the organisation that deploys
Not the lab building foundation models — the company using AI in the business, whose compliance sits with one person who already owns GDPR.
From assessment to audit-ready artifacts
Collect AI Act evidence, maintain FRIA and technical files, bundle regulator-facing submission packs, and rely on an append-only admin trail — so governance teams ship filings without chasing screenshots.
- 01Evidence trailsEvery upload hashed, mapped to the articles it supports.
- 02FRIA & technical filesDrafted per system, versioned, finalized with an author.
- 03Submission packsRegulator-facing bundles assembled from the vault, not re-typed.
- 04Admin audit logsAppend-only — the trail of the trail.
The score is a snapshot.
These four keep it true.
An assessment tells you where you stand today. Pulse, Discovery, Literacy, and the Assistant are the continuous layer — watching drift, surfacing shadow AI, training your people, and answering the hard questions in between.
Pulse
Monthly readiness snapshots comparing your latest assessments — movement and drift show early.
Open PulseDiscovery
Scans SSO and expense exports for the AI tools nobody declared — before an auditor does.
Run DiscoveryAssistant
Answers grounded in your assessment and evidence vault — cites articles, flags gaps.
Ask AssistantThe 8-Pillar Framework
Eight critical dimensions, re-weighted for your sector, six cross-pillar adjustment rules, and an X-Ray engine that detects structural failure patterns from response combinations — not just an average.
Do not take the word “deterministic” on trust
Scoring is versioned at v5.4 and every regulatory engine records the date it was last read against the consolidated text of the Act — including the ones still pending. If we are behind, the page says which.
See what we work from →Don’t take our word for it. Recompute it.
A score you cannot check is a promise. Sealed exports, a public transparency log, an independent verifier and offline replay turn “deterministic” from a claim into something your auditor can run.
Illustration: the verifier’s offline replay output, using the worked example from the published scoring spec. It is not a live result and contains no information about your own assessment.
a demo bundle, sealed and log-anchored on request — no account, nothing to install
- 01Transparency logEvery sealed bundle is anchored in a public, append-only Merkle log — signed heads, inclusion and consistency proofs, RFC 6962-style. The mirror recipe is twenty lines of shell: run it from cron and a log that stops growing — or rewrites its history — trips your alarm, not ours.
- 02Public verifierDrop a sealed bundle on /verify and get a verdict: container, canonicalisation, signatures, artifact hashes, and whether the log anchor still holds in the live head. It computes in memory and stores and logs nothing. A FAIL is coded and specific; there is no partial pass.
- 03Independent CLIe-ari-verify was written against the sealed-export spec, not against our source — the third implementation of the pipeline, after the engine and the conformance corpus, sharing no code with the platform. Verdict parity is tested in both directions, and the CLI verifies fully offline.
- 04Audit ReplayThe auditor’s half: replay re-executes the entire scoring pipeline offline, from the exact answers sealed in the bundle, and compares. Exit 0 is REPLAYED-IDENTICAL. Exit 4 is REPLAY MISMATCH — the alarm. The report keeps the honesty boundary: match means reproducible, never correct.
No certification to hide behind — receipts instead.
A badge cannot tell you whether a score survives scrutiny. What we publish instead: a versioned engine, a changelog that says what we work from — and where we are behind — connectors that wear their real status (every connector is labeled, even the ones that are still experimental), and sealed exports your auditor can recompute without us. Put that in the checklist.
We can tell you if you’ll miss the deadline — while there’s still time to fix it.
Every other platform tells you whether you are compliant today. This one projects, from your own recorded evidence history, whether each future obligation will be evidenced on the date it bites — and names the exact day each workstream must start. No model wrote the sentence: it is deterministic arithmetic, replayable like a score.
Illustration: the countdown screen’s verdict sentence, with 458 days remaining to the Annex III milestone. The obligation figures are the worked example from the published countdown spec, not your own — sign in to see yours.
A projection, not a promise — confidence bands stated, insufficient-data mode honest
- 01Evidence velocityFrom your real ingestion history, not a survey — every upload deduplicated by hash and measured per month over a published 90-day window. An organisation that has never collected a class of artifact is projected to miss every obligation that needs it.
- 02The critical pathEvery missed obligation with the exact start-by date — deadline minus collection effort minus a published buffer. The last responsible moment to start each workstream, ranked by urgency.
- 03The accuracy ledgerEvery prediction audited against reality — the first compliance product that grades its own forecasts. Each passed milestone reconciles stored projections against what actually happened, in an append-only ledger.
Ask the Act·Ask the AI Act a question — every answer cites its article and the date it was last verified. Ask it nowno sign-up, no model
How Scoring Works
Eight steps from your answers to a defensible score. Every one of them is published, versioned, and reproducible — the same inputs always produce the same number.
- 01
Capture
Forty Likert items (1–5), five per pillar — validated complete before scoring runs.
- 02
Normalize
Each pillar mapped to 0–100 from its raw total using fixed bounds — transparent formula, no black box.
- 03
Adjust
Six documented cross-pillar rules fire — weak governance reins technology, weak data reins strategy, weak culture reins process, and three more.
- 04
X-Ray
Eight structural detectors scan the response combinations for failure patterns — Shadow IT Risk, Compliance Cliff, Pilot Purgatory, Ambition Gap, and more. Each finding carries evidence and a concrete next move.
- 05
Sector-weight
Pillar weights are re-balanced for your sector — healthcare emphasises governance and risk, retail emphasises data and process. Renormalised so weights still sum to 1.
- 06
Composite
Sector-weighted pillars combine into one E-ARI composite, alongside the unweighted baseline so you can see how sector context moved the number.
- 07
Classify
Overall maturity band — Laggard through Pacesetter — and every X-Ray finding is then handed to the agents as the grounding evidence for your tailored report.
- 08
Simulate
exact gains · e.g. +0.9 pts, up to +3.5 when it releases a cross-pillar penaltyThe pipeline re-runs with each answer improved one step, computing the exact score gain per move. Your results rank the highest-leverage improvements and the shortest simulated path to the next maturity band — reproducible arithmetic, not analyst opinion.
Same answers in, same score out — versioned v5.4, auditable end to end.
Six agents. None of them can change your score.
The rules engine runs first and decides everything that matters — the score, the risk tier, which obligations apply. The agents work after that, on the part where judgement helps: explaining the result, drafting the narrative, answering questions against your own evidence. Ask twice and the numbers are identical, because no model was ever asked.
Six agents arranged clockwise from the top following the orchestration pipeline. Hover or focus an agent to see its brief. Lines connect each agent to the central orchestrator hub.
Runs the eight-step pipeline: normalize, six cross-pillar adjustment rules, X-Ray detection of structural failure patterns, sector-specific re-weighting, composite, classify. Every score is reproducible and audit-replayable.
Strategic Insights Powered by AI
AI generates narrative context for your scores. It does not alter, inflate, or modify the calculated results — ever.
Generated by AI · grounded in your scores · never alters calculated results
Grounded in your scores
AI narratives are derived from your actual assessment data — no hallucinated metrics or invented benchmarks.
Privacy-first architecture
Your assessment data is processed securely and never used for model training. Enterprise-grade data isolation.
Deterministic fallback
If AI is unavailable, template-based insights are generated deterministically from your scores. You always get value.
Clearly labelled
Every AI-generated insight is explicitly marked. No ambiguity about what comes from algorithms versus AI narrative.
From readiness score to compliance that keeps itself current
The assessment tells you where you stand. These four modules keep you defensible — every week, not once a year.
- FINDShadow AI DiscoveryImport an SSO or expense export and surface the AI tools it reveals — including the ones nobody declared. One click registers them for risk classification.
- ASSESSAI Vendor RiskSend vendors a 10-minute AI risk questionnaire. Deterministic scoring, critical flags for training-on-your-data and missing DPAs, evidence uploads per vendor.
- TRAINArticle 4 LiteracyAssign staff training via magic links — no accounts needed. Completions carry tamper-evident hashes and export as a regulator-ready evidence report.
- PROVELive control statesEvery applicable EU AI Act obligation with a live state: passing, failing, or awaiting evidence — recomputed from your evidence vault the moment it changes, never self-declared.
Included with the Autopilot plan — plus a read API for your GRC stack (API reference).
Reuse·Upload once — link everywhere: evidence is content-addressed, so one artifact links into every system that needs it, with no copy and no re-upload.
Evidence flows in from wherever work happens.
Pull connectors, push APIs and two open-source agents deliver artifacts to the vault — every path through the same ingestion core and the same integrity rules, so provenance never depends on how a file arrived.
- 01GitHubPolicies, model cards and docs pulled straight from a repo — click plus token, nothing scraped.Live
- 02JiraIssue and workflow exports pulled into the same vault.Experimental
- 03ServiceNowGRC and CMDB artifacts pulled under the same rules.Experimental
- 04Microsoft 365Compliance-center artifacts pulled under the same rules.Experimental
- 05CI / API pushAnything that can call an endpoint or run a CI step ships bytes to the ingestion API.Live
- 06Folder watcherThe open-source collector watches scheduled export drops — one watcher instead of N integrations.Open source
- 07Runtime captureA local proxy turns every AI exchange into a hash-addressed artifact — capture-only, fail-open, never a control plane.Open source
Labeled honestly, open by construction
Every connector is labeled — experimental stays experimental until a real tenant validates it. And the destination is one published schema: anything that can call an endpoint or drop a file can deliver evidence.
Your engineers will actually like this.
Evidence-by-default from live AI traffic: the open-source capture proxy turns every AI exchange into a hash-addressed vault artifact. One sidecar container next to your app — that is the whole deployment.
services: app: image: your-app environment: OPENAI_BASE_URL: http://capture:8787/v1 capture: image: node:22-alpine working_dir: /agent command: node agent.mjs --host 0.0.0.0 --upstream https://api.openai.com environment: EARI_API_KEY: eari_live_… EARI_SYSTEM_ID: sys_… volumes: - ./runtime-capture:/agent:ro - spool:/agent/.e-ari-capture-spool volumes: spool: {}
Verbatim from the runtime-capture README
- 01One env varPoint any OpenAI-compatible client at it — OPENAI_BASE_URL=http://127.0.0.1:8787/v1 — and evidence ships itself. No SDK, no code change, no build step; everything else streams through untouched.
- 02Zero depsPlain ESM JavaScript, Node built-ins only — node:http, node:crypto, global fetch. One file, zero npm dependencies, Node >= 18.17.
- 03Capture-only, fail-openNo policy engine, no approvals, no rewriting — it never blocks or delays your app. Evidence may be lost under sustained outage; your traffic never is.
A witness, not a control plane — we record, we never enforce.
The screens behind the claims
Real captures from the running product — not mockups. The countdown verdict, the public verifier doing its checks, and the transparency log anyone can read. Click through: two of the three need no account.
Questions, answered
Straight answers on scoring, agents, and compliance — before you sign up.
Pricing and billing questions? See the pricing FAQ.
Ready to measure your AI readiness?
Start with a free assessment. Get your E-ARI score across 8 pillars in about 15 minutes. No credit card required.
Three ways in: measure yourself, see the projection on your evidence, or see how the verification works — the last one needs no account.
Ships in five languages — English · Français · Português · Español · Deutsch — kept in parity by the same tests that guard this page.
Published pricing·No certifications we don’t hold·Every connector labeled honestly·54 obligations verified against the consolidated Regulation


