Know what is on your site before a plaintiff’s firm does.Free website scanScan Your Site
Log in Sign up Book a demo
Solutions / EU AI Act Compliance Software

EU AI Act Compliance Software

Inventory AI systems, determine your role and risk classification, automate assessments, assign guardrails and preserve the evidence the EU AI Act requires.

EU AI Act compliance

Turn AI obligations into enforceable guardrails.

Inventory your AI systems, determine your role and risk classification, automate assessments, assign controls, preserve evidence and monitor compliance as the EU AI Act evolves.

Assess Your AI SystemsExplore AI Governance

// Software-powered workflows backed by real privacy and governance specialists.

AI system recordHigh risk · Annex III
Recruiting Screening Tool
Business ownerDirector, Talent
RoleDeployer
Intended purposeCandidate shortlisting
Risk classificationHigh risk (Annex III)
Model / vendorThird-party ATS model
Personal dataApplicant CVs, contact data
Affected individualsJob applicants
Human oversightRecruiter review required
Required assessmentFRIA + DPIA
Review statusAwaiting evidence
Next reviewScheduled
Evidence4 documents attached
Guardrail status
✓Inventory complete
✓Classification reviewed
✓Assessment required
✓Human oversight assigned
·Transparency notice active
·Monitoring enabled

Illustrative demonstration data

The EU AI Act is now being enforced

Most applicable provisions, including Article 50 transparency requirements and enforcement powers, began applying on 2 August 2026. High-risk obligations continue to phase in through 2027 and 2028.

// Updated for the AI Omnibus — Regulation (EU) 2026/1744, in force 27 July 2026.

Who it applies to

The AI Act can apply well beyond companies headquartered in Europe.

The EU AI Act assigns obligations according to an organization’s role in the AI value chain and the way an AI system is placed on the market, put into service or used.

Providers

Organizations that develop an AI system or general-purpose AI model — or have one developed — and place it on the market or put it into service under their name or trademark.

Deployers

Organizations using an AI system under their authority, except for certain personal, nonprofessional uses.

Importers

EU-established organizations placing an AI system bearing a non-EU provider’s name or trademark on the EU market.

Distributors

Organizations in the supply chain that make an AI system available in the EU but are not the provider or importer.

Product manufacturers

Manufacturers placing AI systems on the market or putting them into service with a regulated product under their own name or trademark.

Authorized representatives

EU-established representatives appointed by providers located outside the EU.

Organizations outside the EU may be covered when they place AI systems or models on the EU market, or when an AI system’s output is used in the EU.

Risk classification

Different AI systems create different obligations.

Prohibited AI practices

Certain practices are prohibited because they present unacceptable risks. Examples can include specific forms of manipulation, exploitation, social scoring, biometric categorization, emotion recognition and biometric identification — subject to the Act’s definitions and exceptions. Not every use of biometrics or emotion recognition is automatically prohibited.

High-risk AI systems

High-risk categories can include certain uses involving:

Employment and worker managementEducation and vocational trainingAccess to essential servicesCreditworthiness and insuranceBiometricsCritical infrastructureLaw enforcementMigration and border controlJustice and democratic processesAI embedded in regulated products

Transparency-risk systems

Certain AI interactions and generated or manipulated content can trigger transparency duties, including:

Chatbots and direct-interaction systemsAI-generated or manipulated synthetic contentDeepfakesEmotion-recognition systemsBiometric-categorization systemsCertain AI-generated text on matters of public interest

General-purpose AI

Providers of general-purpose AI models can have separate documentation, information, copyright, transparency and — in some cases — systemic-risk obligations.

Minimal or no additional risk

Many AI applications do not fall into a prohibited or high-risk category, but organizations should still inventory, review, document and monitor them under an internal governance program.

// Risk classification is fact-specific. Intended purpose, deployment context, affected individuals, organizational role and changes to the system can all affect the classification.

What to operationalize

The AI Act requires more than a policy document.

AI inventory

Maintain an authoritative record of internally developed, purchased, embedded and employee-adopted AI systems.

Role determination

Record whether the organization acts as a provider, deployer, importer, distributor, product manufacturer or authorized representative.

Risk classification

Evaluate prohibited-practice, high-risk, transparency and general-purpose AI requirements.

AI assessments

Run configurable assessments based on role, risk, use case, jurisdiction, personal data and affected groups.

Human oversight

Assign accountable individuals, document intervention procedures and preserve evidence of meaningful oversight.

Transparency controls

Track required notices, AI interaction disclosures, synthetic-content labeling and accessibility requirements.

Incident and change management

Capture incidents, complaints, material changes, new vendors, model updates and changes in intended use.

Evidence and reporting

Maintain policies, approvals, technical documentation, training records, assessments, decisions, controls and audit evidence.

Implementation timeline

EU AI Act implementation timeline.

1 August 2024

The EU AI Act entered into force.

2 February 2025

Definitions, prohibited AI practices and AI-literacy requirements began applying.

2 August 2025

Governance provisions and obligations for general-purpose AI models began applying.

2 August 2026

Most remaining provisions began applying, including Article 50 transparency obligations and enforcement for applicable requirements.

2 December 2026

New prohibitions introduced through the AI Omnibus apply, along with the transition deadline for certain existing synthetic-content systems under Article 50(2).

2 August 2027

Member States should have at least one AI regulatory sandbox operational.

2 December 2027

Requirements for high-risk AI systems covered by Annex III begin applying under the amended timeline.

2 August 2028

Requirements for high-risk AI embedded in regulated products covered by Annex I begin applying.

// Last legally reviewed: August 2026. Dates reflect the AI Omnibus, Regulation (EU) 2026/1744. The Act continues to develop through implementation measures, standards, guidance and codes of practice.

AI literacy

AI literacy is already an active obligation.

Providers and deployers must take measures to ensure a sufficient level of AI literacy among relevant staff and other persons operating or using AI systems on their behalf, considering their technical knowledge, experience, education, training and the context in which the systems are used.

Role-based AI training assignmentsPolicy acknowledgmentsCompletion recordsSystem-specific guidanceDocumented competencyPeriodic refresh requirementsEvidence for internal and external review

// One generic employee training course does not satisfy every organization’s obligation. The required level depends on role, system and context. This duty has applied since 2 February 2025 and was not postponed by the AI Omnibus.

Assessments

Connect AI assessments to privacy assessments.

AI systems frequently raise overlapping questions involving the EU AI Act, GDPR, data protection impact assessments, security, vendors, fundamental rights and internal risk policies. Captain Compliance connects these reviews so organizations do not have to answer the same questions repeatedly.

AI system intake assessmentsProhibited-practice screeningRisk-classification assessmentsProvider and deployer assessmentsFundamental Rights Impact AssessmentsData Protection Impact AssessmentsVendor assessmentsGeneral-purpose AI reviewsHuman-oversight assessmentsChange and reassessment workflows

// Not every organization or high-risk system requires a Fundamental Rights Impact Assessment. Article 27 applies to specified deployers and use cases. Where applicable, an FRIA complements rather than automatically replaces a GDPR DPIA.

Explore Privacy Assessments

The workflow

From AI discovery to defensible governance.

01
Discover
Collect AI systems through questionnaires, integrations, vendor records, employee submissions and organizational data.
02
Classify
Determine the use case, organizational role, risk category, affected people and applicable requirements.
03
Assess
Launch the correct assessment using conditional and branching questions.
04
Remediate
Assign control gaps, owners, deadlines, approvals and escalation paths.
05
Govern
Apply approved-use rules, human-oversight requirements, transparency controls and operational guardrails.
06
Monitor
Track system changes, model updates, new uses, incidents, complaints and reassessment dates.

Software capabilities

AI governance software with experts behind it.

Central AI inventory

Keep every approved, restricted, experimental and retired AI system in one governed record.

Configurable assessments

Use conditional questions, reusable templates, approval routing and supporting evidence.

AI-assisted workflows

Use AI agents to organize responses, identify missing information, suggest classifications and help draft remediation tasks — with human review and approval.

Control mapping

Connect requirements to policies, risks, systems, vendors, owners and evidence.

Guardrail management

Define acceptable use, restricted uses, human-review requirements, data restrictions and escalation procedures.

Continuous monitoring

Trigger reassessment when an AI system, model, vendor, purpose, geography or risk profile changes.

Executive reporting

Give leadership visibility into AI adoption, risk levels, unresolved findings and governance status.

Expert support

Access Captain Compliance privacy, assessment and governance specialists.

// AI agents support human review. They do not make final legal determinations autonomously.

Penalties

EU AI Act penalties can reach global-turnover levels.

Prohibited practices

€35M or 7%

Up to €35 million or 7% of worldwide annual turnover, whichever applies under the Act’s rules.

Other operator and transparency violations

€15M or 3%

Up to €15 million or 3% of worldwide annual turnover.

Incorrect or misleading information

€7.5M or 1%

Up to €7.5 million or 1% of worldwide annual turnover.

// Different calculations apply to SMEs, including startups, and penalties must account for the circumstances of the infringement. Maximum penalties are not automatic. Source: Article 99, official AI Act Service Desk.

Connected solutions

Build one connected governance program.

Questions

The EU AI Act, answered plainly.

What is the EU AI Act?

It is the European Union’s horizontal regulation for artificial intelligence, assigning obligations by risk level and by the organization’s role in the AI value chain. It entered into force on 1 August 2024 and applies in phases, most recently amended by the AI Omnibus, Regulation (EU) 2026/1744.

Does the EU AI Act apply outside Europe?

It can. Organizations established outside the EU may be covered when they place AI systems or general-purpose AI models on the EU market, or when the output of an AI system is used in the EU.

What is the difference between a provider and a deployer?

A provider develops an AI system or model — or has one developed — and places it on the market or into service under its own name or trademark. A deployer uses an AI system under its own authority. The same organization can be a provider for one system and a deployer for another, and the obligations differ.

What counts as a high-risk AI system?

High-risk categories include certain uses in employment, education, essential services, creditworthiness and insurance, biometrics, critical infrastructure, law enforcement, migration, and justice, as well as AI embedded in certain regulated products. Whether a specific system qualifies depends on its intended purpose, the applicable annex and the organization’s role.

Are all AI systems regulated in the same way?

No. The Act is tiered: prohibited practices, high-risk systems, transparency-risk systems, general-purpose AI models, and everything else. Obligations differ substantially between tiers.

What are the EU AI Act’s transparency requirements?

Article 50 covers duties such as disclosing that a person is interacting with an AI system, labeling AI-generated or manipulated content, and disclosures for deepfakes, emotion recognition and biometric categorization. Most Article 50 obligations began applying on 2 August 2026; certain existing synthetic-content systems have until 2 December 2026 under Article 50(2).

What is an AI literacy program?

Article 4 requires providers and deployers to ensure a sufficient level of AI literacy among staff and others operating AI systems on their behalf, taking account of their knowledge, experience, training and the deployment context. It has applied since 2 February 2025 and was not postponed.

Does every organization need a Fundamental Rights Impact Assessment?

No. Article 27 applies to specified deployers and use cases rather than to every organization or every high-risk system. Where an FRIA is required, it complements a GDPR DPIA rather than automatically replacing it.

How does the EU AI Act interact with GDPR?

They operate in parallel. An AI system processing personal data can trigger obligations under both, and a single system may require an AI Act assessment and a GDPR DPIA covering different questions. Connecting the two reviews avoids duplicated effort.

What are the maximum penalties?

Up to €35 million or 7% of worldwide annual turnover for prohibited practices; up to €15 million or 3% for other operator and transparency violations; and up to €7.5 million or 1% for supplying incorrect or misleading information. Different calculations apply to SMEs, and maximums are not automatic.

How can Captain Compliance help?

The platform maintains your AI inventory, records organizational role and risk classification, runs the applicable assessments, assigns guardrails and owners, tracks remediation, monitors material changes and preserves the evidence behind each decision — with privacy and governance specialists available for the harder judgments.

Get started

Turn the EU AI Act into an operating system for responsible AI.

Inventory your AI systems, classify risks, automate assessments, assign guardrails and maintain the evidence your organization needs.

Assess Your AI SystemsBook an AI Governance Demo

Captain Compliance provides privacy and AI governance technology, implementation and support. It does not provide legal advice and does not guarantee compliance with the EU AI Act. Classification, applicable obligations and required assessments depend on your systems, role, intended purpose and jurisdiction, and warrant review by qualified counsel.