When you generate an Annex IV documentation section, you can now ground it in the evidence SetAIComply already collected for that system — MLflow model cards, GitHub/GitLab CI test logs and bias-test results. Turn on "Ground with collected evidence" and the most relevant items are woven into the draft (or pick specific ones); each generated section records exactly which evidence grounded it, and flags when any of it was still pending review. External evidence text is treated as untrusted and every draft stays yours to review and edit.
Link your GitHub Actions or GitLab CI integration to a governed AI system and SetAIComply pulls its recent pipeline runs and files a dated test-log summary as Article 11 technical-documentation evidence (Annex IV asks for exactly that: test logs, dated and attributed). The summary now details the most recent run — job-level results on GitHub Actions, JUnit test-report totals (passed, failed, skipped) on GitLab CI. Synced on demand and every six hours — no manual upload.
When SetAIComply auto-discovers an AI system from your connected MLflow registry, it now files that model's card — description, versions and stages — as Article 11 technical-documentation evidence automatically, ready for your team to review. No manual upload, refreshed on every sync.
Enterprise SSO (OpenID Connect) arrives on the Scale and Enterprise plans: connect Microsoft Entra ID, Okta or Google, verify your domain with a DNS record, and your team signs in from a dedicated SSO login page — new members are provisioned automatically on first login, with every security guardrail enforced.
Compliance checks now re-run automatically on a daily schedule. When a previously passing check starts failing, the regression is flagged and an alert is raised in-app and to your connected channels — no one has to remember to re-audit.
New incidents, risk classifications, approval decisions, due deadlines, failed compliance checks and fresh regulatory alerts now dispatch to Slack, Microsoft Teams, Jira, Linear and custom webhooks — pick the events per integration and keep your team in the loop where they already work.
Connect MLflow and SetAIComply pulls your registered models and turns them into governed AI systems in your inventory — deduplicated, synced every six hours, and ready to classify.
Shadow AI detection now plugs into Microsoft Entra ID, Okta and Google Workspace: OAuth-connected apps are pulled from your IdP, matched against our AI tool catalog, and surfaced as findings — with a configuration wizard, on-demand sync and a six-hour schedule.
Every completed bias test automatically attaches its result as Article 10 evidence on the tested system — no manual upload, ready for review in your evidence library.
Agent mode now goes end-to-end: the Copilot can register an AI system, run its risk classification, attach compliance evidence and re-evaluate compliance — the full discover, classify, evidence, re-check cycle, with every action permission-gated and audit-logged.
New guided workspaces for record-keeping (Article 12), human oversight (Article 14), accuracy, robustness and cybersecurity (Article 15), transparency (Article 50) and GPAI obligations (Articles 53 and 55) — plus an Article 5 prohibited-practices screening covering all nine prohibition categories, including the incoming Digital Omnibus additions, and a new Article 5 column on the compliance heatmap.
The 24 interface languages now load on demand instead of shipping in one bundle — cutting the heaviest first-page download by 69% on the same fully localized platform.
Subscribe from any page footer — with GDPR-compliant double opt-in — to receive regular regulatory digests drawn from our EU AI Act Regulatory Radar, each summarizing the latest official updates in your own language.
Generate eighteen board- and regulator-ready report types — including an Article 43 audit pack, Article 73 serious-incident reports, the EU database registration payload, a GPAI downstream package, executive and quarterly board digests, a risk register and period-over-period deltas — exported as PDF, DOCX, CSV, JSON or a bundled ZIP.
A free, self-paced course with a knowledge check issues per-employee attestations and generates an organization-wide usage policy, helping you meet the Article 4 AI-literacy obligation — available in all 24 EU languages.
Opt in to a public, per-organization trust page that shares your aggregate compliance posture and cross-framework coverage with customers and partners — no login required to view.
A new free tier covers up to three AI systems with risk classification, DPIA, Annex IV documentation and the Article 4 course, the Compliance Copilot now reaches the Starter plan, and every paid trial gracefully reverts to the free tier instead of locking you out.
Your Article 27 Fundamental Rights Impact Assessment now derives GDPR Article 35 Data Protection Impact Assessment coverage automatically, surfaced directly on the FRIA page.
Beyond answering questions, the Compliance Copilot now acts on your behalf — drafting Annex IV sections, populating compliance workspaces, scheduling regulatory deadlines and preparing approvals for you to sign. Every write action is gated by role-based permissions and recorded in the audit trail, with a new chat-vs-agent mode selector built into the composer.
The work you complete for the EU AI Act now automatically derives coverage for the NIST AI Risk Management Framework and ISO/IEC 42001, surfaced on a new multi-framework coverage page so you can see where you stand across all three at a glance.
A new read-only Model Context Protocol (MCP) server lets external AI agents query your compliance data, and a scoped public read API exposes your registered AI systems to your own tooling.
Bias datasets can now be re-tested on a schedule, with per-metric alert thresholds that notify you when a model drifts out of tolerance between formal assessments.
The Copilot now grounds every answer in the official text of Regulation (EU) 2024/1689 — 113 articles, 180 recitals and 13 annexes across all 24 EU languages — with verified, clickable citations, real-time streaming and a redesigned twin-panel console.
Serious-incident handling now includes a tamper-evident, hash-chained timeline, an evidence vault for Article 73 records, server-side official report PDFs and automatic deadline tiers — including the two-day clock for widespread incidents.
A new vendor risk suite tracks your third-party AI providers, links them to your systems under Article 25 obligations and keeps assessments in sync across the workspace.
Classify any AI system's risk tier for free, with no signup — enriched with the obligations and article references that apply — alongside a new resources hub and dedicated solutions pages.