Skip to main content
EU AI Act risk assessment

Understand your AI risk. Document your deployment decision.

Start with a free risk preview. Upgrade to classify individual components, review supporting evidence, and prepare a decision dossier for your team.

No account, no documents, no AI-generated report.

Illustrative preview

CASE AZC-00147Deployer
Analysing
Source: p.4 PDFOverlays: BE, NL, FRRuleset: v10.1.7
4 system componentsSelect a component to inspect its trigger
CMP-02 · High riskAnnex III §4(a) · High Risk

Scores and ranks candidates. Evaluated deterministically by statutory filter without LLM intervention.

CASE AZC-00147 · DeployerIllustrative preview
01Decision Dossier

ACT II · THE DETERMINISTIC ENGINE

From unvetted source specification to immutable, signed statutory dossier. One unified workbench binds decomposed multi-agent systems, anchored source spans, statutory Python rules, and DPO sign-offs into an auditable record.

System specification·Ref: AZC-00147
Rules engine v10.1.7No LLM verdicts
Ingested Operational Architecture SpecDoc: system-description.pdf · p.4
Modular decomposition (4 sub-agents)Select to inspect
Inspectable decision fragment
Deterministic verdictAnnex III §4(a)

CMP-02 · Shortlisting & Ranking · Scores and ranks candidates · Annex III §4(a) · High Risk

[01] Source factsystem-description.pdf · p.4
[02] VerificationDPO concurrence

FACT-017 verified by DPO lead (no automated assumption)

[03] Deterministic triggerArticle triggered

Annex III §4(a): Employment access trigger active

Predicate: scores_candidates=true AND before_human_review=true
[04] Open evidence gapBlocker

Art. 11 technical documentation not yet deposited by vendor

DPO / Privacy lead

M. Dupont · 2026-08-14

Signed off

Regulatory counsel

H. Van Damme · 2026-08-15

Signed off

AI product owner

Action required

Pending evidence
Record hash: 0x8f4b...3e19Jurisdictions: BE, NL, FRInspect full sample dossier
02DECISION ENGINE
Ruleset v10.1.7

AI extracts facts. Humans validate facts. Rules classify risk. Humans sign the record.

Regulation:Regulation (EU) 2024/1689 & (EU) 2026/1744
Ruleset:v10.1.7 deterministic
Overlays:8 EU jurisdictions (BE, NL, DE, FR…)
Invariant:Reviewed facts, same result

system-description.pdf · p.4

Candidate fact — not a verdict

Legal counsel · BE
03 Sep 2026 16:02 CET
FACT APPROVED

Human validation before rule execution.

Mandatory Human GateSTAGE 02 · VERIFICATION
EU-hosted · Reviewed facts only · Ruleset v10.1.7 · Hash-sealed record
03Governance Stack Fit

Compare the approaches to classification, evidence, review, and documentation.

Classification

Basic LLM checkers
Prompt-based risk estimates; outputs vary by tool
Enterprise GRC platforms
Policy management, questionnaires, and review workflows; capabilities vary by platform
AZComply engine
Deterministic statutory rules applied to reviewed facts

Evidence traceability

Basic LLM checkers
Conversational summaries; source links vary by tool
Enterprise GRC platforms
High-level policy attestations; depth varies by platform
AZComply engine
Anchored source excerpts with open evidence gaps listed

Human review

Basic LLM checkers
Optional human check; process varies by tool
Enterprise GRC platforms
Review workflows included; scope varies by platform
AZComply engine
Fact confirmation and sign-off workflow before the record is complete

Deliverable

Basic LLM checkers
Summary text for orientation
Enterprise GRC platforms
Policy dashboards for ongoing management
AZComply engine
Versioned decision dossier (PDF) for team review

Stack Positioning

Start with one decision. Govern the portfolio as you grow.

Once your team has a governed decision record, AZComply extends that workflow across your AI systems, evidence and reassessments — when you need it.

Single System Assessment → Portfolio Inventory → Evidence Operations → Continuous Governance
04Pricing

Assessments start at 1 credit. Scale to your AI portfolio as deployments grow.

Entry Tier

Questionnaire-based risk signals. No LLM-generated report.

€0Stateless
  • Preliminary risk level and article signals
  • Main reasons behind the preview
  • Limited obligation preview
  • No LLM extraction or compliance dossier
Start risk preview
Core Governance Plan

1 active AI system, 8 assessment credits per month

€99/ month

1 system included, full dossier PDF generation

Assessments start at 1 credit. Document assessments use 2 credits; trilingual dossiers add 4 credits. Credits are deducted only after the PDF is generated and stored.

Complete production capability

  • 1 active AI system with full dossier history
  • Deterministic classification + review-ready dossier (PDF + evidence)
  • Evidence Vault + versioned decision history
  • Reassessment when system or context changes
  • Workspace collaboration for DPO / Legal
  • Audit trail and control attestation
  • 8 assessment credits included per month
  • Additional systems available
Enterprise Tier

For teams managing several AI systems

CustomPortfolio Scope
  • Several or custom active AI systems
  • Team seats and contract terms
  • Custom generation allowance
  • Advisor, API, and white-label entitlements
  • Procurement and security review

Start with one decision. Govern the portfolio as you grow.. Once your team has a governed decision record, AZComply extends that workflow across your AI systems, evidence and reassessments — when you need it.

05Timeline

Enforcement is phased. Some obligations are already applicable; others have transition periods to December 2027 and August 2028. Your dossier tracks what applies now.

Phase 01: NowIn force

Status as of 24 September 2026

Prohibited AI practices, biometric categorisation bans, and transparency disclosures for synthetic media and conversational AI are legally binding across all EU member states.

Full active liability
Phase 02: Next

Annex III high-risk systems

Mandatory conformity assessments, technical documentation, human oversight logging, and works council consultations for employment, critical infrastructure, and credit scoring AI.

Dossier generation required
Phase 03: LaterFuture horizon

Annex I product safety

Integration deadline for AI embedded into regulated physical products (medical devices, machinery, civil aviation) subject to existing third-party EU harmonisation legislation.

Harmonised standards gate
06FAQ

Clear answers on statutory classification, legal validity, GDPR overlap, and platform architecture.

What is AZComply and what does it do?

AZComply is a regulatory detection tool for EU 2024/1689 (EU AI Act). It classifies your AI system against the regulation's risk framework — Annex III high-risk categories, prohibited practices under Article 5, GPAI obligations, and national law overlays for Belgium, Germany, France, Netherlands, Italy, and Spain. It does not provide legal advice.

What is an Annex III high-risk AI system?

Annex III lists 8 categories of AI systems classified as high-risk: biometric identification, critical infrastructure safety components, education and vocational training, employment and worker management, access to essential services, law enforcement, migration and border control, and administration of justice. High-risk systems face the most extensive compliance requirements.

Do you use LLMs? I thought this was deterministic.

Both. Our multilingual extraction pipeline (hosted on sovereign EU infrastructure in europe-west4 with Zero Data Retention) extracts structured facts from your plain-language description in any of 6 languages. Those facts are then passed to our pure Python deterministic engine, which classifies risk against Articles 5, Annex III, GPAI, and national law overlays. The LLM never decides risk level. The engine is authoritative.

Which national laws does AZComply cover?

AZComply publishes national routing overlays for 8 EU member states: Belgium (CAO 9/39/81/100), Netherlands (WOR Art. 27), Germany (BetrVG §87(1)(6), BNetzA), France (CSE, CNIL), Italy (Statuto Art. 4, Garante, INL), Spain (ET Art. 64.4(d), RDL 9/2021, AESIA), Finland (Traficom, FIN-FSA) and Ireland (AI Office of Ireland, WRC, DPC). Overlays add national obligations and authority routing; they never change the AI Act risk tier, which the deterministic engine owns.

How does AZComply handle data privacy and security?

AZComply processes all data within the EU. The LLM pipeline runs on dedicated sovereign LLM infrastructure in europe-west4 (Netherlands) with Zero Data Retention verified. Database and storage use Supabase in eu-central-1 (Frankfurt). Uploaded documents are processed in-memory and never written to disk. Document text is deleted from memory immediately after extraction. No personal data from assessments is retained beyond the generated report.

What is a FRIA and do I need one?

A Fundamental Rights Impact Assessment (FRIA) is required under Article 27 for deployers that are public bodies or private entities providing public services. It assesses impacts on fundamental rights including non-discrimination, privacy, and due process. AZComply automatically detects whether FRIA is required based on your system profile.

What are the penalties for non-compliance?

Fines are tiered. Prohibited practices (Article 5): up to €35M or 7% of global annual turnover. High-risk violations: up to €15M or 3% of turnover. Incorrect information to authorities: up to €7.5M or 1% of turnover. SMEs and startups may receive proportionate penalties.

Is this legal advice?

No. AZComply is a detection tool: it identifies regulatory indicators and generates compliance analysis reports. It does not constitute legal advice, and its output should not be relied upon as a substitute for qualified legal counsel. The tool framing is 'Article X requires...' not 'you are compliant'.

07The upgrade

The free questionnaire returns preliminary signals. The Full Assessment turns real system material into a governed decision record - extraction, component separation, evidence, national overlays, and a review-ready dossier.

No account, no documents, no AI-generated report