AI governance compatibility workspace

Check a website or document against the EU AI Act.

Scan policy text, product pages, procurement notes, or website copy for AI governance readiness. The checker maps evidence to major frameworks, flags risks, and turns each gap into a practical mitigation.

23/100

Compatibility verdict

Not compatible yet

Based on 5 frameworks and 4 active risk findings.

Initial sample check

Assessment report

Compatibility by framework

Not compatible yet
EUAIEU AI Act
32%Not ready
  • AI system purpose and intended use
  • Risk classification
  • Human oversight
  • Transparency notice
GDPRGDPR
59%Partial
  • Lawful basis and privacy notice
  • Data subject rights
  • DPIA and automated decisioning
  • Retention and minimization
AIMSISO/IEC 42001
36%Not ready
  • AI management objectives
  • Defined roles and accountability
  • Supplier and lifecycle control
  • Internal audit cadence
RMFNIST AI RMF
51%Not ready
  • Govern function
  • Map function
  • Measure function
  • Manage function
SOC2SOC 2 / Security
39%Not ready
  • Access controls
  • Logging and monitoring
  • Incident response
  • Vendor and data retention controls

Risk register

Risks and mitigations

4 findings
High

Unclear EU AI Act risk classification

Document intended use, affected persons, prohibited-use screening, and whether the system falls into high-risk Annex III categories.

Owner: LegalTarget: 7 days
Medium

Bias and representativeness evidence not visible

Maintain dataset lineage, representativeness checks, protected-class testing, and remediation thresholds.

Owner: AI GovernanceTarget: 14 days
Medium

Transparency notice is not evidenced

Add plain-language AI disclosure, system purpose, limitations, and user recourse where AI materially affects outcomes.

Owner: ProductTarget: 14 days
High

Ongoing monitoring and audit trail are weak

Create monitoring metrics, incident thresholds, audit logs, review cadence, and assigned control owners.

Owner: AI GovernanceTarget: 30 days

Sub-agent validation

Official Validation Agent

18% source confidence
Not source-validated yet

This sub-agent checks the submitted URL and pasted document text against official compliance sources and flags where official evidence is missing.

EUR-Lex

Regulation (EU) 2024/1689, Artificial Intelligence Act

No direct source evidence: no official terms found in submitted text
Official source

EUR-Lex

Regulation (EU) 2016/679, General Data Protection Regulation

No direct source evidence: no official terms found in submitted text
Official source

European Data Protection Board

EDPB guidance and opinions on data protection compliance

No direct source evidence: no official terms found in submitted text
Official source

NIST

AI Risk Management Framework

No direct source evidence: no official terms found in submitted text
Official source

ISO

ISO/IEC 42001 AI management systems

No direct source evidence: no official terms found in submitted text
Official source
01

Evidence pack

Gather model purpose, data lineage, risk classification, privacy notice, DPIA, evaluation results, and monitoring logs.

02

Control owners

Assign named Legal, Security, Product, and AI Governance owners for every open finding.

03

Residual risk

Re-score after mitigations and record accepted residual risk before production or procurement approval.