EU AI Act compliance software, built for SMEs
Most compliance tools were built for SOC 2 and ISO 27001, then bolted on an “AI module”. SetAIComply is the opposite: AI-Act-native — built around the exact workflow the EU AI Act asks for, so a small team can get compliant without a consultant’s retainer.
Updated on August 16, 2026
Who actually needs this
The EU AI Act does not only regulate companies that build models. It regulates the role you play around an AI system. A recruiter running a CV-ranking tool, a lender scoring applicants, a clinic using triage software and a support team that wired a chatbot into its help desk are all in scope — most of them as deployers, some of them, without realising it, as providers.
The distinction is the single most consequential decision in your compliance file. Providers carry the heavy obligations: the risk management system, the Annex IV technical documentation, conformity assessment and registration. Deployers carry a lighter but real set: use the system according to its instructions, ensure human oversight, monitor operation, and — for certain public-facing and essential-service use cases — run a fundamental rights impact assessment. You can start as a deployer and become a provider by substantially modifying a system, putting it on the market under your own name, or changing its intended purpose. The provider vs deployer guide works through the Article 25 conditions with concrete SME examples.
Being an SME does not exempt you. The Act softens some fees and administrative burdens for small companies, and caps certain fines proportionately, but it does not remove the high-risk obligations themselves. A twelve-person company selling an Annex III system owes the same technical documentation as a multinational.
Two questions come up constantly alongside this one: whether calling a third-party model API puts you in scope — it usually does, as a deployer, and the Article 4 AI literacy duty applies whatever your risk tier — and how the Act sits alongside an ISO/IEC 42001 certification you may already hold.
The deadlines that actually apply
The AI Act applies in stages, and the stages have already moved once. These are the current dates — the platform reads them from a single source of truth, so every countdown, checklist and generated document stays in step with them.
| Applies from | What | Who |
|---|---|---|
| February 2, 2025 | Prohibited practices (Art. 5) and the AI literacy duty (Art. 4) | Every organisation that develops or uses AI — no risk tier required |
| August 2, 2025 | General-purpose AI model obligations (Chapter V) | Providers of GPAI models placed on the EU market |
| December 2, 2027 | Stand-alone high-risk obligations (Annex III) | Providers and deployers of Annex III systems — recruitment, credit scoring, education, essential services, biometrics |
| August 2, 2028 | High-risk AI embedded in regulated products (Annex I) | Manufacturers whose AI is a safety component of a product already covered by EU product law |
Two of these dates were rescheduled by the Digital Omnibus, which is why a large amount of guidance still circulating online quotes August 2026 and August 2027. See the full breakdown of the 2027 deadline changes.
Applicability scoping & Annex III classification
Work out your role (provider or deployer) and whether each system is high-risk under Annex III — guided, not guesswork.
Annex IV technical documentation
Auto-generate the technical documentation file high-risk providers must keep current and available to authorities on request.
24 official EU languages
The platform and the generated documents run in all 24 official EU languages — not English-only.
EU-hosted & GDPR-native
100% hosted in Amsterdam, encrypted end to end, with a DPA available — your compliance data stays in the EU.
DPIAs & evidence collection
Run structured data-protection impact assessments and attach audit-ready evidence to every obligation — included from the free tier.
Compliance Copilot (AI)
An assistant grounded in the official EU AI Act text, in all 24 EU languages — answers cite the articles they rely on. From the Starter plan.
Regulatory radar
Track guidance, delegated acts and deadline changes that affect your systems, with alerts for your team. From the Growth plan.
Shadow AI detection
Surface ungoverned AI use across the organisation before it becomes a compliance gap. From the Growth plan.
Vendor management
Keep your AI vendors’ documentation, DPAs and conformity evidence in one register. From the Growth plan.
Bias testing
Run fairness metrics on your models and keep the reports as compliance evidence. From the Scale plan.
Audit trail & SSO
Append-only logging of compliance-relevant changes, plus self-serve single sign-on from the Scale plan (audit log export on Enterprise).
What a high-risk system requires, article by article
“Get compliant” is not one task. For a high-risk system it is a dozen interlocking duties, each of which has to be evidenced and kept current. This is the chain, and where each link lives in the platform.
| Article | What the Act requires | Where it lives in SetAIComply |
|---|---|---|
| Art. 9 | A risk management system maintained across the whole lifecycle | Structured risk register per system, with residual-risk decisions recorded |
| Art. 10 | Data governance for training, validation and testing datasets | Data governance module with provenance, representativeness and bias checks |
| Art. 11 + Annex IV | Technical documentation, kept current and produced on request | Generated Annex IV file, versioned, exportable as PDF in 24 languages |
| Art. 12 | Automatic logging of events over the system’s lifetime | Record-keeping module plus an append-only compliance audit trail |
| Art. 13 | Transparency and instructions for use for deployers | Transparency workspace and model card generation |
| Art. 14 | Human oversight designed into the system | Human oversight module: measures, competencies, escalation paths |
| Art. 15 | Accuracy, robustness and cybersecurity | Robustness & security assessment, with bias testing evidence attached |
| Art. 17 | A quality management system for providers | QMS module mapped to the Article 17 sub-clauses |
| Art. 27 | Fundamental rights impact assessment for certain deployers | FRIA workflow, cross-referenced with the GDPR DPIA where both apply |
| Art. 43 | Conformity assessment before placing on the market | Conformity assessment and CE marking workflow with evidence gates |
| Art. 49 | Registration in the EU database for high-risk systems | EU database registration workspace with the required data fields |
| Art. 72–73 | Post-market monitoring and serious incident reporting | Monitoring plan plus an incident register with reporting deadlines |
Deeper reading: what makes a system high-risk, the Annex IV technical file, and conformity assessment and CE marking.
Software, consultant, or spreadsheet?
There are four honest ways to approach this, and they are not mutually exclusive. The question is which one carries the continuous obligations once the initial assessment is done.
| Approach | Cost shape | Where it wins | Where it breaks |
|---|---|---|---|
| Spreadsheets and shared drives | Free, until an authority asks | No procurement, starts today | No versioning of the technical file, no evidence chain, no way to prove what you knew when |
| Compliance consultancy | Typically five figures per engagement | Judgement on the genuinely ambiguous calls | The output is a point-in-time report; the obligations are continuous |
| A GRC suite with an AI module | Enterprise contract, annual | Strong if you also need SOC 2 or ISO 27001 | AI Act obligations are modelled as generic controls, not as the Act’s own objects |
| AI-Act-native software | Free tier, then from a monthly subscription | Classification, Annex IV and the obligation chain are the product | Not a substitute for legal advice on contested interpretations |
Why “AI-Act-native” beats a bolted-on module
Vanta, Drata and OneTrust are strong security and GRC platforms — but the EU AI Act is not a security framework, so it asks different questions. A SOC 2 platform models the world as controls and evidence requests. The AI Act models it as systems that carry a role, a risk tier, an intended purpose, a technical file and a post-market monitoring duty. When you flatten the second into the first, the classification logic and the document lineage are the parts that get lost — and those are precisely what an authority asks for.
If your priority is Annex III classification and Annex IV documentation rather than SOC 2 evidence collection, an AI-Act-native tool fits better. Many teams run both, and that is a reasonable answer: keep the security posture where it is, and put the AI Act obligations somewhere that understands them.
Compliance by sector
The obligations are the same everywhere, but the Annex III entry that catches you — and therefore the evidence you need — is not. These walkthroughs start from the use case rather than from the article number.
Pricing
Free from €0 (3 AI systems, 3 DPIAs, PDF export), then Starter from €39.00/mo, plus Growth, Scale and Enterprise. Self-serve — no demo required.
See all plans and what’s includedSecurity & hosting
- 100% EU-hosted in Amsterdam, GDPR-native, end-to-end encrypted, DPA available.
- Not SOC 2 or ISO 27001 certified — and we don’t claim to be (those are postures by design, not a certificate).
- Compliance evidence never leaves the EU, which matters when the evidence itself is the regulated artefact.
Details in the trust centre, and how we source the regulatory content in our editorial policy.
FAQ
Is there a free tier?
Yes — SetAIComply is free from €0, and the Risk Checker and Snapshot need no account at all.
We only call the OpenAI or Anthropic API. Does the AI Act still apply to us?
Usually yes, as a deployer rather than a provider — and the AI literacy duty in Article 4 applies regardless of risk tier. If you substantially modify a system, put it on the market under your own name, or change its intended purpose, you can become the provider and inherit the full high-risk obligation set. The Risk Checker walks through exactly that role question.
Does it generate Annex IV technical documentation?
Yes — generating the Annex IV technical file is a core part of the workflow, alongside Annex III risk classification. The file is versioned and exportable as a PDF.
When do the high-risk obligations actually bite?
The Digital Omnibus rescheduled them: stand-alone Annex III systems from December 2, 2027, and AI embedded in regulated products (Annex I) from August 2, 2028. Prohibited practices and the AI literacy duty have applied since February 2, 2025. A lot of published guidance still quotes the superseded August 2026 and August 2027 dates.
Which languages are supported?
All 24 official EU languages, including the generated compliance documents. That matters because a market surveillance authority may ask for documentation in the language of its member state.
How does this relate to ISO/IEC 42001 and the NIST AI RMF?
They overlap but do not substitute for each other. ISO 42001 is a voluntary AI management system standard and NIST AI RMF is a voluntary risk framework; the AI Act is binding law with specific documentary duties. Work done for either standard — risk registers, data governance, oversight design — is reusable evidence, but neither produces an Annex IV technical file or an Article 49 registration.
How does it relate to GDPR?
They are separate regimes that meet in practice. Many Annex III systems process personal data, so a GDPR DPIA and an AI Act fundamental rights impact assessment (Art. 27) are often needed for the same system. The platform cross-references the two so you do not answer the same question twice.
Is SetAIComply SOC 2 or ISO 27001 certified?
No — SetAIComply is not SOC 2 or ISO 27001 certified, and does not claim to be. Data is EU-hosted in Amsterdam, GDPR-native, encrypted end to end, and a DPA is available.
Is this legal advice?
No. The platform structures the work and produces the artefacts; it does not replace counsel on contested interpretations such as role attribution or what counts as a substantial modification. Our editorial policy sets out how the underlying guidance is sourced and reviewed.
Do we need a demo to get started?
No. Every plan is self-serve, and the Risk Checker and Compliance Snapshot run without an account.