Skip to content

The EU AI Act already applies to you. Your answer has to hold up.

When a customer, your board or a regulator asks whether you comply, “we think so” is not an answer. Conformly classifies every AI system deterministically — with the articles that decided it — captures the evidence behind each obligation, and exports it as a dated, audit-ready file you can hand over.

No credit card No sales call Evidence, not opinions
Conformly · Discovery
3
Declared
6
Signals found
3
Not reconciled
Undeclared AI (3)
conformly-scan@0.1.0
npm:openai
OpenAI SDK ^4.52.0
Undeclared
openai:gpt-4o
Model referenced
Undeclared
aws:bedrock
Managed service
Undeclared
npm:@anthropic-ai/sdk
Anthropic SDK
Support Chatbot
anthropic:claude-3-5-sonnet
Model referenced
Support Chatbot
pypi:scikit-learn
scikit-learn 1.5.0
Demand Forecaster

The Discovery screen — what your environment actually contains, versus what your inventory declared.

EU AI ActAnnex IVISO 42001NIST AI RMFArt. 50 TransparencyGPAIHosted in the EUDeterministic classificationEU AI ActAnnex IVISO 42001NIST AI RMFArt. 50 TransparencyGPAIHosted in the EUDeterministic classification
Start where you actually are

Which of these is your situation?

Almost nobody arrives asking for “AI governance”. They arrive because someone asked them a question they could not answer. Pick the one that sounds like your week.

A customer is asking us for AI Act documentation before they'll sign.

Answer the security questionnaire once and publish it: system inventory, risk classification with the articles behind it, and the transparency evidence buyers keep asking for.

For AI vendors

We ship a chatbot and generative features. Does Article 50 bind us?

Seven deterministic questions tell you which paragraphs of Article 50 you owe — and hand you the disclosure wording to put in the product this week.

Check Article 50 readiness Get disclosure wording

We need a management system somebody can actually certify.

ISO/IEC 42001 is the AI governance standard an accredited body can audit today. Build the Statement of Applicability, run the Annex A controls, and collect the evidence an auditor will ask for.

ISO 42001 readiness
ISO/IEC 42001:2023

The one AI standard someone can actually certify you against

The AI Act tells you what you owe. It does not hand you a certificate to show a customer. ISO/IEC 42001 is the accredited AI-management-system standard that does — and it is what enterprise procurement has started writing into contracts.

Statement of Applicability

All 38 Annex A controls, each either in scope with an owner or excluded with a written justification.

Machine evidence, not screenshots

Applicable controls are backed by scheduled, deterministic checks — every result captured and dated automatically.

Clause 9 records

Internal audit, management review and improvement records in the shape a certification auditor expects to read them.

To be clear: only an accredited certification body can issue an ISO/IEC 42001 certificate. Conformly is not one and never will be. We prepare the management system and the evidence your auditor will examine — the audit itself stays independent, which is the entire point of it.

Why this is where the budget is

The Act's high-risk obligations were moved to 2 December 2027 by the 2026 Digital Omnibus, so the Annex III work is a 2027 programme for most teams. What is live now is Article 50 — and what buyers are contractually demanding now is a certifiable management system.

1Article 50 — in force since 2 August 2026. Not a project plan; a live obligation.
2ISO 42001 — the certificate procurement asks for, backed by the same evidence.
3Annex III high-risk — 2 December 2027. Build the register now, not the panic later.
Already in force

If you're non-compliant today, that isn't a deadline

Prohibitions, AI literacy, the GPAI rules and Article 50 transparency have all taken effect. A missed deadline you can still plan for. This is live exposure, accruing now.

In force
Transparency obligations (Art. 50) — since 2 August 2026
€35M / 7%
max fine — of global annual turnover
110
days until content-marking transition for existing systems
Content-marking transition for existing systems
Art. 50 · 2 December 2026
In force since 2 August 2026 · Article 50

Do the transparency duties already bind you?

The high-risk dates moved. Article 50 did not. Its transparency duties are live today, and they catch ordinary products — not just the ones anyone would call high-risk. One of these four triggers is usually enough.

Article 50 · 2 August 2026
Art. 50(1)

You have a chatbot or AI assistant

People interacting with it must be told they are talking to AI, unless that is obvious to a reasonably informed person.

Art. 50(2)

You generate text, images, audio or video

Outputs must be marked machine-readably as artificially generated — C2PA provenance or robust watermarking.

Art. 50(4)

You publish deepfakes

Content resembling real people, places or events needs a visible disclosure, not just metadata underneath it.

Art. 50(3)

You use emotion or biometric categorisation

The people exposed must be informed — and workplace or education emotion recognition is banned outright under Art. 5.

Seven questions tell you which paragraphs you owe

Free, deterministic, no sign-up — and it hands you a week-one plan, with the exact disclosure wording. One transition exists: generative systems already on the market have until 2 December 2026 for machine-readable marking. Nothing else waits.

Check Article 50 readiness
The differentiator · one command, no integrations

You declared 3 AI systems. The scan found 6.

An inventory you filled in by asking around is not evidence — it is a memory test, and it is the first thing an auditor pulls a thread on. Conformly checks it against reality: a read-only agent runs where your code already is and reports the models, SDKs and AI services actually in there.

Every other platform asks for OAuth into your cloud, your code host and your identity provider — then waits for your security team to review it. Conformly inverts that.

One command, zero setup

npx conformly-scan reads the repo it runs in. No agent to install, no dashboard to wire up first.

Your credentials stay put

No OAuth, no cloud keys. The scanner posts a list of findings — it never gets access to anything.

Continuous by design

Drop it into CI and discovery re-runs on every push, so shadow AI shows up the day it lands.

Run --dry-run first — everything it prints is everything it would ever send.

acme/api — zsh
$ npx conformly-scan --dry-run
conformly-scan 0.1.0 — scanning /srv/acme/api
AI libraries (3)
npm:openai (OpenAI SDK ^4.52.0)
npm:@anthropic-ai/sdk (Anthropic SDK ^0.24.3)
pypi:scikit-learn (scikit-learn ==1.5.0)
Models referenced (2)
openai:gpt-4o
anthropic:claude-3-5-sonnet-20240620
Managed AI services (1)
aws:bedrock
AI provider env keys (names only) (2)
OPENAI_API_KEY (openai)
BEDROCK_REGION (aws)
Governance documents (1)
acme/api:MODEL_CARD.md (model-card)
Repository signals (1)
acme/api (412 commits/90d, merge ratio 0.38)
6 AI signal(s) across 10 finding(s).
Dry run — nothing was sent. Re-run with --key=conf_xxx to report these.
How it works

From unknown to audit-ready

Three steps — no spreadsheets, no guesswork.

Step 1

Inventory your AI

List every AI system you build or use — purpose, data, owner. One clean register.

Step 2

Get your obligations

A deterministic engine classifies each system and generates the exact tasks the Act requires.

Step 3

Stay audit-ready

Track tasks, attach evidence, and export a dated, audit-ready report on demand.

The platform

Everything the Act asks for

One platform — from inventory to the Annex IV technical file.

Deterministic risk classification

Prohibited, high, limited or minimal — with the exact articles and reasons. No black box.

AI system inventory

One register for every system.

Obligation tracking

Tasks with owners, due dates, recurrence.

Evidence vault

Versioned, signed, audit-ready evidence.

Live regulation alerts

Get notified when a change affects your systems.

Audit-ready reports & Annex IV

Export your inventory, classifications, obligations and evidence as one dated PDF — plus the Annex IV technical file.

Price-lock guarantee

Your renewal price never jumps. What you sign up for is what you pay.

AI Act, done deeper

We do one thing — the EU AI Act — thoroughly. Not a diluted checkbox tool.

Free risk checker

Know your risk class in two minutes, before you ever create an account.

EU-only hosting

Stored exclusively on EU servers — no US region, no replication outside the EU.

One control library

Not just the AI Act

Land on the EU AI Act, then reuse the same evidence against the AI-relevant controls of SOC 2, ISO 27001 and the rest — through crosswalks, without duplicating a single control. Crosswalks map your AI Act work across; they are not a SOC 2 or ISO 27001 audit in themselves.

EU AI Act
Annex III · IV · GPAI
ISO 42001
AI management
SOC 2
Trust Services
ISO 27001
Information security
GDPR
Data protection
HIPAA
Health data
PCI DSS
Payment security
NIST CSF
Cyber risk
Pricing

Real prices, written openly

No “contact sales” wall. Every plan carries our price-lock guarantee.

Price-lock guaranteeNo surprise renewal increases — your price is locked for as long as you stay.
Compliance Report
$390one-time

A one-off, audit-ready AI Act risk & obligations report for a single system.

  • Risk classification for one AI system
  • Full obligations breakdown
  • Annex IV starter + PDF report
  • No subscription
  • Optional: expert review call (+$290)
Get your report — $390
Starter
$1,490/year

For a small team getting AI Act–ready before the deadline.

  • Up to 5 AI systems
  • Obligation tracking + evidence vault
  • 15 policy templates
  • Live regulation alerts
  • Audit-ready reports
  • Email support
Start free
Most popular
Growth
$4,990/year
or $490/mo

The complete platform for companies serious about AI governance.

  • Unlimited AI systems
  • Everything in Starter
  • AI compliance copilot
  • Public Trust Center page
  • ISO 42001 + NIST AI RMF mapping
  • Vendor assessments
  • Compliance score trends
  • Priority support
Start free
Enterprise
from $9,900

For regulated organisations needing SSO, audit support and more.

  • Everything in Growth
  • SSO / SAML
  • Unlimited team members
  • Dedicated onboarding & audit support
  • Custom frameworks & SLAs
Contact us

Prices in USD. Launch pricing — locked for existing customers.

Why trust us

Proof, not logos

We'd rather earn your trust than borrow it. Instead of a wall of logos, here is what you can verify about Conformly yourself, right now.

0black boxes

Classification is rule-based and deterministic. Same inputs, same class — with the articles that decided it.

EUonly, no US region

Your compliance record is stored exclusively on EU servers, with no replication outside the EU. Verifiable on our security page.

0credentials shared

Discovery runs as a read-only CLI in your repo. No OAuth app, no keys handed over, nothing to review.

1day to live

Run the free checker, add a system, and you have a live obligation checklist the same afternoon.

Answers

Frequently asked questions

Who is in scope of the EU AI Act?+

Any provider or deployer whose AI system is used, or whose output is used, in the EU — regardless of where the company is based. The free risk checker tells you in two minutes.

What are the key deadlines?+

Prohibited practices and AI literacy have applied since 2 Feb 2025; GPAI rules since 2 Aug 2025; Art. 50 transparency duties since 2 Aug 2026 — those three are already in force. Still ahead: the content-marking transition for systems already on the market ends 2 Dec 2026, and the 2026 Digital Omnibus moved high-risk (Annex III) obligations to 2 Dec 2027 and high-risk product-safety components (Annex I) to 2 Aug 2028.

How much does it cost?+

Transparently: a one-time $390 Compliance Report, Starter at $1,490/yr, Growth at $4,990/yr (or $490/mo), and Enterprise from $9,900. Every plan carries our price-lock guarantee.

Will my price go up at renewal?+

No. Our price-lock guarantee means the price you sign up for stays the same for as long as you remain a customer.

Can Conformly certify us to ISO/IEC 42001?+

No — and no software vendor can. An ISO/IEC 42001 certificate is issued only by an accredited certification body after an independent audit. What Conformly does is prepare exactly what that audit examines: a Statement of Applicability across all 38 Annex A controls, machine evidence from scheduled deterministic control checks, and the Clause 9 internal audit and management review records.

Where is my data hosted?+

On EU servers only. Conformly is a cloud product — your workspace lives in our EU-hosted database. There is no US region, no replication outside the EU, and no third-party processor holding a copy of your compliance record. The details are on our security page.

Does the discovery agent see my code or secrets?+

No. It reports package names, model ids, env-var names, and file hashes — never file contents, source code, or secret values. Run npx conformly-scan --dry-run to see exactly what would be sent.

Does an AI make the risk decision?+

Never. Classification is fully deterministic and rule-based. Our optional AI assistant only explains obligations and drafts documents — it never decides your risk class.

Is this legal advice?+

No. Conformly automates the organisational and documentation work of compliance and is not a substitute for qualified legal counsel.

Hosted in the EU

Know your AI Act risk in 2 minutes

Run the free risk checker and get an instant classification plus the obligations that apply to you.

Run free risk check