Eight tested national-law routing overlays: BE, NL, DE, FR, ES, IT, FI and IE.
§
Article-level trace
Results link to the triggered rules.
0
0 LLM verdicts
LLM context, rules classify.
01 / Decision Dossier
What is in the Decision Dossier
A structured, review-ready record - not a simulation. Every field is traceable to facts and regulatory sources.
01System facts, purpose and affected persons
02Regulatory triggers and risk classification
03Applicable requirements by role
04Evidence and missing information
05Review questions, decision history and sources
Decision invariant
Same reviewed facts → same rule result. The LLM structures candidate facts; a human review happens before the deterministic classification is relied on.
One AI product can contain several different regulatory decisions.
Classification depends on intended purpose, operator role, deployment context, affected people, and the components that actually influence outcomes.
Illustrative system anatomy
AI Hiring Platform
Deployment context
CV screening before human review
#Component / functionRegulatory question surfaced
01
CV parser
Extracts applicant data
Supporting function — facts still matter
02
Ranking agent
Scores and orders candidates
Employment decision trigger / Annex III §4(a)
03
Biometric module
Analyses face or voice signals
Separate biometric / prohibited-practice check
04
Generative assistant
Drafts recruiter notes
Separate role and transparency assessment
Illustrative decomposition — AZComply evaluates each component against the reviewed facts instead of assigning one label to the product name.
03 / How it's decided
LLM is context. Engine is judge. Human signs.
AI agents structure compliance-relevant facts. Deterministic rules evaluate regulatory triggers. Your team reviews material findings and approves the final decision.
Stage 01Fact Extraction
AI extracts facts
Multilingual LLM on sovereign EU infrastructure (europe-west4) reads system material and structures facts. It never decides the risk level.
SOVEREIGN EU · NO TRAINING DATA
WORKFORCEINPUTFACTS
Stage 02Rule Evaluation
Rules determine the result
Deterministic Python rules evaluate reviewed facts against bounded EU AI Act triggers. Enabled national-law overlays are surfaced separately for review. Same reviewed facts produce the same EU AI Act rule result.
ART. 6 & ANNEX III · DETERMINISTIC
ART. 6ANNEX IIIRULES
Stage 03Evidence Trail
Evidence shows why
Sources, missing information and the specific legal trigger are shown beside each material finding.
SOURCED · FULL AUDIT TRAIL
SOURCEDEVIDENCETRACE
Stage 04Human Approval
Humans approve
DPO, legal and product teams review material findings, resolve open questions and approve the record before release.
HUMAN SIGN-OFF · GOVERNANCE
SIGN-OFFAUDITDECISION
Decision support, not legal advice. Review material findings and unresolved facts before relying on the dossier.
Enforcement is phased. Some obligations are already applicable; others have transition periods to December 2027 and August 2028. Your dossier tracks what applies now.
2 Feb 2025Art. 5 · Prohibited practices
Prohibitions & AI Literacy in force
In force
2 Aug 2025Arts. 51-55 · GPAI obligations
GPAI Obligations in force
In force
2 Aug 2026Art. 50 · Transparency
Transparency obligations (Art. 50) in force
In force
2 Dec 2027Art. 16 + Art. 26 · Annex III
High-Risk Annex III obligations in force
Next000Days
2 Aug 2028Art. 111(3) · Legacy systems
Legacy AI systems deadline
Later
Enforcement is phased. Some obligations are already applicable; others have transition periods to December 2027 and August 2028. Your dossier tracks what applies now.
No. AZComply is a detection tool: it identifies regulatory indicators and generates compliance analysis reports. It does not constitute legal advice, and its output should not be relied upon as a substitute for qualified legal counsel. The tool framing is 'Article X requires...' not 'you are compliant'.
02When does EU AI Act enforcement start?
Prohibited practices (Article 5) applied from February 2, 2025. General-purpose AI (GPAI) obligations apply from August 2, 2025. Full Annex III high-risk system obligations apply from 2 December 2027 (extended by the Digital Omnibus, in force 27 July 2026). GPAI systemic risk obligations apply from August 2, 2025. AZComply tracks all amendments.
03What is a FRIA and do I need one?
A Fundamental Rights Impact Assessment (FRIA) is required under Article 27 for deployers that are public bodies or private entities providing public services. It assesses impacts on fundamental rights including non-discrimination, privacy, and due process. AZComply automatically detects whether FRIA is required based on your system profile.
04What are the penalties for non-compliance?
Fines are tiered. Prohibited practices (Article 5): up to €35M or 7% of global annual turnover. High-risk violations: up to €15M or 3% of turnover. Incorrect information to authorities: up to €7.5M or 1% of turnover. SMEs and startups may receive proportionate penalties.
05How is AZComply different from hiring a law firm?
AZComply provides fast, structured regulatory detection at a fraction of the cost of legal counsel. A law firm consultation on EU AI Act compliance typically costs €5,000-€50,000+ and takes weeks. AZComply's deterministic engine delivers a preliminary risk classification in seconds and a full paid report in minutes, designed to prepare you for legal review, not replace it.
06Which national laws does AZComply cover?
AZComply publishes national routing overlays for 8 EU member states: Belgium (CAO 9/39/81/100), Netherlands (WOR Art. 27), Germany (BetrVG §87(1)(6), BNetzA), France (CSE, CNIL), Italy (Statuto Art. 4, Garante, INL), Spain (ET Art. 64.4(d), RDL 9/2021, AESIA), Finland (Traficom, FIN-FSA) and Ireland (AI Office of Ireland, WRC, DPC). Overlays add national obligations and authority routing; they never change the AI Act risk tier, which the deterministic engine owns.
07Do you use LLMs? I thought this was deterministic.
Both. Our multilingual extraction pipeline (hosted on sovereign EU infrastructure in europe-west4 with Zero Data Retention) extracts structured facts from your plain-language description in any of 6 languages. Those facts are then passed to our pure Python deterministic engine, which classifies risk against Articles 5, Annex III, GPAI, and national law overlays. The LLM never decides risk level. The engine is authoritative.
09 / The upgrade·Start free - upgrade when evidence matters
Start with a risk preview.
Upgrade when it needs to be defensible.
The free questionnaire returns preliminary signals. The Full Assessment turns real system material into a governed decision record - extraction, component separation, evidence, national overlays, and a review-ready dossier.