You want to use AI in your business and need a sound basis for a decision. The application helps you identify risks and obligations, record measures and document your assessment. Find out how to get started, even without an in-house legal team.
4 sections in the quick check
62 obligations in the compass
live demo without sign-up
Legal status Reg. (EU) 2026/1744
As of September 2026
The starting point
Most companies of this size have no legal department and no dedicated function for AI governance. The task lands with IT management, information security or an appointed member of staff, usually on top of their actual work. A months-long implementation project is not an option.
At the same time the EU AI Act applies regardless of company size. Whether the obligations apply is decided by the risk class of the system and the role of the company, not by headcount. So the first question is not what must be done, but whether anything must be done at all.
Whether the obligations apply is decided by the risk class of the system and the role of the company, not by headcount.
Assessments step by step (2)
Each step links to the relevant features and information.
Answers with sources and links for further review.
Does the EU AI Act apply to our company?
It applies regardless of company size. Whether the obligations apply is decided by the risk class of the system and the role of the company. The quick check classifies a system in four short sections and states the result with its reasoning, without sign-up and with a print version for the file.
Nothing to get to know it: the live demo shows the complete Community Edition with example data in the browser, without sign-up. For your own work inside the company the Professional edition applies: €2,490 once per licence, with twelve months of updates and no running costs after that. The free Community Edition itself is reserved for non-commercial use.
Anyone using a bought-in system is a deployer. For deployers the obligations compass lists 24 of the 62 obligations, depending on the risk class. They include use in line with the instructions, suitable input data, human oversight by suitable persons, retention of the logs, and informing the persons affected.
That depends on the risk class. Since Regulation (EU) 2026/1744 the requirements for high-risk systems under Annex III apply from 2 December 2027 and under Annex I from 2 August 2028. Two new prohibitions already take effect on 2 December 2026. The timeline calculates all eight dates against today.
What do we do about tools staff use on their own initiative?
The catalogue lists this as a threat in its own right. Confidential information flows to external providers, and gaps arise that nobody knows about. The catalogue names seven mitigations, among them a usage policy with internal communication, a register of approved tools, and monitoring of outbound traffic.
What does the application explicitly not do for us?
It replaces neither legal advice nor an assessment of the individual case. It does not manage an inventory of systems over time and replaces no management system. It notifies nothing to authorities. And it does not tell you whether to buy a tool; it tells you which obligations come with it.
Limits of the application (4)
These tasks require additional tools or professional review.
Tasks outside the application
It replaces neither legal advice nor an assessment of the individual case.
It does not manage an inventory of systems over time and replaces no management system.
It notifies nothing to authorities and files no notification.
It does not decide on a purchase. It names the obligations attached to a decision.
Suitable editions
€2,490 once
Professional Offline
For regular work across several systems: reports as PDF and workbook, machine-readable exports, extended evidence packages.
The complete Community Edition with example data, directly in the browser and without sign-up. For trying out the method; your own work inside a company or a public body is not covered by the Community licence.