- AI system purpose and intended use
- Risk classification
- Human oversight
- Transparency notice
AI governance compatibility workspace
Check a website or document against the EU AI Act.
Scan policy text, product pages, procurement notes, or website copy for AI governance readiness. The checker maps evidence to major frameworks, flags risks, and turns each gap into a practical mitigation.
Compatibility verdict
Not compatible yet
Based on 5 frameworks and 4 active risk findings.
Initial sample check
Assessment report
Compatibility by framework
- Lawful basis and privacy notice
- Data subject rights
- DPIA and automated decisioning
- Retention and minimization
- AI management objectives
- Defined roles and accountability
- Supplier and lifecycle control
- Internal audit cadence
- Govern function
- Map function
- Measure function
- Manage function
- Access controls
- Logging and monitoring
- Incident response
- Vendor and data retention controls
Risk register
Risks and mitigations
Unclear EU AI Act risk classification
Document intended use, affected persons, prohibited-use screening, and whether the system falls into high-risk Annex III categories.
Bias and representativeness evidence not visible
Maintain dataset lineage, representativeness checks, protected-class testing, and remediation thresholds.
Transparency notice is not evidenced
Add plain-language AI disclosure, system purpose, limitations, and user recourse where AI materially affects outcomes.
Ongoing monitoring and audit trail are weak
Create monitoring metrics, incident thresholds, audit logs, review cadence, and assigned control owners.
Sub-agent validation
Official Validation Agent
This sub-agent checks the submitted URL and pasted document text against official compliance sources and flags where official evidence is missing.
EUR-Lex
Regulation (EU) 2024/1689, Artificial Intelligence Act
No direct source evidence: no official terms found in submitted textEUR-Lex
Regulation (EU) 2016/679, General Data Protection Regulation
No direct source evidence: no official terms found in submitted textEuropean Data Protection Board
EDPB guidance and opinions on data protection compliance
No direct source evidence: no official terms found in submitted textNIST
AI Risk Management Framework
No direct source evidence: no official terms found in submitted textISO
ISO/IEC 42001 AI management systems
No direct source evidence: no official terms found in submitted textEvidence pack
Gather model purpose, data lineage, risk classification, privacy notice, DPIA, evaluation results, and monitoring logs.
Control owners
Assign named Legal, Security, Product, and AI Governance owners for every open finding.
Residual risk
Re-score after mitigations and record accepted residual risk before production or procurement approval.