EU AI ActThe AI literacy duty applies now to every organisation using AI·and Article 50 transparency since August 2026·high-risk follows in 464 daysCheck your exposure →
Most of the Act is not addressed to you
Duties attach to a specific operator. We show only the ones that attach to yours — each naming its article, so you can check the scoping rather than trust it.
Deploying a chatbot
limited risk
Live now
12obligations
Literacy, transparency, all eight prohibitions, value-chain duties.
Deploying a screening tool
high risk
From 2 Dec 2027
20obligations
Adds human oversight, monitoring, incident reporting, a FRIA.
Providing the model itself
high risk
From 2 Dec 2027
47obligations
Full Chapter III duties, Annex IV documentation, conformity assessment.
Each also names how it can be satisfied, so nothing sits on your list that you have no way to discharge.
Built for the organisation that deploys
Not the lab building foundation models — the company using AI in the business, whose compliance sits with one person who already owns GDPR.
From assessment to audit-ready artifacts
Collect AI Act evidence, maintain FRIA and technical files, bundle regulator-facing submission packs, and rely on immutable admin logs — so governance teams ship filings without chasing screenshots.
- AI Act evidence trails
- FRIA & technical documentation
- Submission-ready packs
- Admin audit logs
Technical file and FRIA drafts tied to systems; export packs for submissions; activity preserved in admin logs.
The score is a snapshot.
These four keep it true.
An assessment tells you where you stand today. Pulse, Discovery, Literacy, and the Assistant are the continuous layer — watching drift, surfacing shadow AI, training your people, and answering the hard questions in between.
Pulse
Monthly readiness snapshots comparing your latest assessments — movement and drift show early.
Open PulseDiscovery
Scans SSO and expense exports for the AI tools nobody declared — before an auditor does.
Run DiscoveryAssistant
Answers grounded in your assessment and evidence vault — cites articles, flags gaps.
Ask AssistantThe 8-Pillar Framework
Eight critical dimensions, re-weighted for your sector, six cross-pillar adjustment rules, and an X-Ray engine that detects structural failure patterns from response combinations — not just an average.
Do not take the word “deterministic” on trust
Scoring is versioned at v5.4 and every regulatory engine records the date it was last read against the consolidated text of the Act — including the ones still pending. If we are behind, the page says which.
See what we work from →Governance-grade signals, without the clutter
Certification tiers
Bronze through Platinum readiness badging tied to your composite score.
Regulatory mapping
Structured gap views across EU AI Act, NIST AI RMF, and ISO/IEC 42001.
Ongoing monitoring
Pulse checks and drift-oriented alerts when posture shifts.
Sector benchmarks
Percentile-style comparisons where benchmark data is available.
How Scoring Works
Eight steps from your answers to a defensible score. Every one of them is published, versioned, and reproducible — the same inputs always produce the same number.
- 01
Capture
Forty Likert items (1–5), five per pillar — validated complete before scoring runs.
- 02
Normalize
Each pillar mapped to 0–100 from its raw total using fixed bounds — transparent formula, no black box.
- 03
Adjust
Six documented cross-pillar rules fire — weak governance reins technology, weak data reins strategy, weak culture reins process, and three more.
- 04
X-Ray
Eight structural detectors scan the response combinations for failure patterns — Shadow IT Risk, Compliance Cliff, Pilot Purgatory, Ambition Gap, and more. Each finding carries evidence and a concrete next move.
- 05
Sector-weight
Pillar weights are re-balanced for your sector — healthcare emphasises governance and risk, retail emphasises data and process. Renormalised so weights still sum to 1.
- 06
Composite
Sector-weighted pillars combine into one E-ARI composite, alongside the unweighted baseline so you can see how sector context moved the number.
- 07
Classify
Overall maturity band — Laggard through Pacesetter — and every X-Ray finding is then handed to the agents as the grounding evidence for your tailored report.
- 08
Simulate
exact gains · e.g. +0.9 pts, up to +3.5 when it releases a cross-pillar penaltyThe pipeline re-runs with each answer improved one step, computing the exact score gain per move. Your results rank the highest-leverage improvements and the shortest simulated path to the next maturity band — reproducible arithmetic, not analyst opinion.
Same answers in, same score out — versioned v5.4, auditable end to end.
Six agents. None of them can change your score.
The rules engine runs first and decides everything that matters — the score, the risk tier, which obligations apply. The agents work after that, on the part where judgement helps: explaining the result, drafting the narrative, answering questions against your own evidence. Ask twice and the numbers are identical, because no model was ever asked.
Six agents arranged clockwise from the top following the orchestration pipeline. Hover or focus an agent to see its brief. Lines connect each agent to the central orchestrator hub.
Runs the seven-step pipeline: normalize, six cross-pillar adjustment rules, X-Ray detection of structural failure patterns, sector-specific re-weighting, composite, classify. Every score is reproducible and audit-replayable.
Strategic Insights Powered by AI
AI generates narrative context for your scores. It does not alter, inflate, or modify the calculated results — ever.
Generated by AI · grounded in your scores · never alters calculated results
Grounded in your scores
AI narratives are derived from your actual assessment data — no hallucinated metrics or invented benchmarks.
Privacy-first architecture
Your assessment data is processed securely and never used for model training. Enterprise-grade data isolation.
Deterministic fallback
If AI is unavailable, template-based insights are generated deterministically from your scores. You always get value.
Clearly labelled
Every AI-generated insight is explicitly marked. No ambiguity about what comes from algorithms versus AI narrative.
Against a static questionnaire
Most readiness tools are a spreadsheet with a form on top. Six places where that difference actually changes what you can do with the result.
Typical tool
A model reads your answers; ask twice, get two resultsE-ARI
Rules decide the score and the tier — same input, same output, versionedTypical tool
The model decides, and cannot show its reasoningE-ARI
Six agents explain and draft — none can alter a calculated resultTypical tool
No formal readiness certificationE-ARI
Bronze through Platinum tier badging systemTypical tool
Manual research across regulatory frameworksE-ARI
Auto-mapped to EU AI Act, NIST RMF & ISO 42001Typical tool
One-time point-in-time snapshotsE-ARI
Continuous drift detection with real-time alertsTypical tool
A score with nothing to compare it againstE-ARI
Sector baselines with modelled percentile positioningComparison is against the general category of static readiness questionnaires, not any named product.
From readiness score to continuous compliance
The assessment tells you where you stand. These four modules keep you defensible — every week, not once a year.
Shadow AI Discovery
Import an SSO or expense export and surface every AI tool in use — including the ones nobody declared. One click registers them for risk classification.
AI Vendor Risk
Send vendors a 10-minute AI risk questionnaire. Deterministic scoring, critical flags for training-on-your-data and missing DPAs, evidence uploads per vendor.
Article 4 Literacy
Assign staff training via magic links — no accounts needed. Completions carry tamper-evident hashes and export as a regulator-ready evidence report.
Continuous Controls
Every applicable EU AI Act obligation with a live state: passing, failing, or awaiting evidence — derived from your evidence vault, never self-declared.
Included with the Autopilot plan — plus a read/write API for your GRC stack (API reference).
Questions, answered
Straight answers on scoring, agents, and compliance — before you sign up.
Pricing and billing questions? See the pricing FAQ.