EU AI Act compliance, built for the companies that can least afford consultants
SetAIComply is a European compliance operating system for the EU AI Act. It classifies AI systems against the Act's risk tiers, generates the Annex IV technical documentation high-risk providers must keep current, tracks the obligations that follow, and holds the evidence behind each one.
Why we built it
The AI Act applies to organisations that never thought of themselves as AI companies: a recruiter running a CV-ranking tool, a lender scoring applicants, a clinic using a triage model, a support team that wired a chatbot into its help desk. Most of them discover the obligations late, and their first quote is from a consultancy billing by the day.
The staggered deadlines made that worse rather than better. Prohibited practices and the AI literacy duty have applied since February 2025. GPAI model obligations followed in August 2025. The Digital Omnibus then pushed stand-alone high-risk obligations to 2 December 2027 and product-embedded high-risk to 2 August 2028 — which bought time, but also left a great deal of published guidance quoting dates that no longer exist. A tool that reads the deadlines from a single source of truth is worth more than a slide deck that was accurate last year.
The Act is the product, not a checklist module
Most compliance platforms started somewhere else — SOC 2, ISO 27001, privacy — and added an AI Act module once the regulation landed. The data model shows it: obligations become generic controls, and the specifics of Annex III classification, Annex IV technical documentation or Article 27 fundamental rights impact assessments get flattened into tasks. SetAIComply is modelled on the Act's own structure, so a system carries its role, its risk tier and its obligation set as first-class objects.
Built for the size of company that actually has to comply
The AI Act does not exempt SMEs from high-risk obligations; it only softens some of the fees and paperwork. That leaves thousands of European companies with 10 to 200 employees, no compliance department, and the same technical documentation duty as a multinational. Pricing, onboarding and defaults are set for that company, not for an enterprise procurement cycle.
European by architecture, not by marketing claim
Data is hosted in the EU (Amsterdam), the platform and the generated documents run in all 24 official EU languages, and a DPA is available to every customer. A compliance tool that ships your regulatory evidence outside the EU is solving one problem by creating another.
Evidence over assertions
Every obligation in the platform can carry the artefacts that prove it — documents, assessments, test results, audit trail entries. Compliance is a file you can hand to a market surveillance authority, not a percentage on a dashboard.
Where to go next
What the platform does, module by module, and how it maps to the Act.
OpenThe guidesLong-form explainers on classification, documentation, penalties and deadlines.
OpenThe free risk checkerWork out your role and risk tier in a few minutes, no account required.
OpenEditorial policyHow the regulatory content is sourced, reviewed and corrected.
OpenTrust centreHosting, encryption, sub-processors and the DPA.
OpenPricingPlans, limits and what is included from the free tier upward.
OpenTalk to us
Questions about scope, a classification you are unsure of, or whether the platform fits your stack — write to support@setaicomply.com. We answer from Europe, in your language.