The EU AI Act already applies to you. Your answer has to hold up.
When a customer, your board or a regulator asks whether you comply, “we think so” is not an answer. Conformly classifies every AI system deterministically — with the articles that decided it — captures the evidence behind each obligation, and exports it as a dated, audit-ready file you can hand over.
The Discovery screen — what your environment actually contains, versus what your inventory declared.
Which of these is your situation?
Almost nobody arrives asking for “AI governance”. They arrive because someone asked them a question they could not answer. Pick the one that sounds like your week.
“A customer is asking us for AI Act documentation before they'll sign.”
Answer the security questionnaire once and publish it: system inventory, risk classification with the articles behind it, and the transparency evidence buyers keep asking for.
For AI vendors“We ship a chatbot and generative features. Does Article 50 bind us?”
Seven deterministic questions tell you which paragraphs of Article 50 you owe — and hand you the disclosure wording to put in the product this week.
Check Article 50 readiness Get disclosure wording“We need a management system somebody can actually certify.”
ISO/IEC 42001 is the AI governance standard an accredited body can audit today. Build the Statement of Applicability, run the Annex A controls, and collect the evidence an auditor will ask for.
ISO 42001 readinessThe one AI standard someone can actually certify you against
The AI Act tells you what you owe. It does not hand you a certificate to show a customer. ISO/IEC 42001 is the accredited AI-management-system standard that does — and it is what enterprise procurement has started writing into contracts.
Statement of Applicability
All 38 Annex A controls, each either in scope with an owner or excluded with a written justification.
Machine evidence, not screenshots
Applicable controls are backed by scheduled, deterministic checks — every result captured and dated automatically.
Clause 9 records
Internal audit, management review and improvement records in the shape a certification auditor expects to read them.
To be clear: only an accredited certification body can issue an ISO/IEC 42001 certificate. Conformly is not one and never will be. We prepare the management system and the evidence your auditor will examine — the audit itself stays independent, which is the entire point of it.
Why this is where the budget is
The Act's high-risk obligations were moved to 2 December 2027 by the 2026 Digital Omnibus, so the Annex III work is a 2027 programme for most teams. What is live now is Article 50 — and what buyers are contractually demanding now is a certifiable management system.
If you're non-compliant today, that isn't a deadline
Prohibitions, AI literacy, the GPAI rules and Article 50 transparency have all taken effect. A missed deadline you can still plan for. This is live exposure, accruing now.
Do the transparency duties already bind you?
The high-risk dates moved. Article 50 did not. Its transparency duties are live today, and they catch ordinary products — not just the ones anyone would call high-risk. One of these four triggers is usually enough.
Article 50 · 2 August 2026You have a chatbot or AI assistant
People interacting with it must be told they are talking to AI, unless that is obvious to a reasonably informed person.
You generate text, images, audio or video
Outputs must be marked machine-readably as artificially generated — C2PA provenance or robust watermarking.
You publish deepfakes
Content resembling real people, places or events needs a visible disclosure, not just metadata underneath it.
You use emotion or biometric categorisation
The people exposed must be informed — and workplace or education emotion recognition is banned outright under Art. 5.
Seven questions tell you which paragraphs you owe
Free, deterministic, no sign-up — and it hands you a week-one plan, with the exact disclosure wording. One transition exists: generative systems already on the market have until 2 December 2026 for machine-readable marking. Nothing else waits.
You declared 3 AI systems. The scan found 6.
An inventory you filled in by asking around is not evidence — it is a memory test, and it is the first thing an auditor pulls a thread on. Conformly checks it against reality: a read-only agent runs where your code already is and reports the models, SDKs and AI services actually in there.
Every other platform asks for OAuth into your cloud, your code host and your identity provider — then waits for your security team to review it. Conformly inverts that.
One command, zero setup
npx conformly-scan reads the repo it runs in. No agent to install, no dashboard to wire up first.
Your credentials stay put
No OAuth, no cloud keys. The scanner posts a list of findings — it never gets access to anything.
Continuous by design
Drop it into CI and discovery re-runs on every push, so shadow AI shows up the day it lands.
Run --dry-run first — everything it prints is everything it would ever send.
$ npx conformly-scan --dry-runconformly-scan 0.1.0 — scanning /srv/acme/apiAI libraries (3) npm:openai (OpenAI SDK ^4.52.0) npm:@anthropic-ai/sdk (Anthropic SDK ^0.24.3) pypi:scikit-learn (scikit-learn ==1.5.0)Models referenced (2) openai:gpt-4o anthropic:claude-3-5-sonnet-20240620Managed AI services (1) aws:bedrockAI provider env keys (names only) (2) OPENAI_API_KEY (openai) BEDROCK_REGION (aws)Governance documents (1) acme/api:MODEL_CARD.md (model-card)Repository signals (1) acme/api (412 commits/90d, merge ratio 0.38)6 AI signal(s) across 10 finding(s).Dry run — nothing was sent. Re-run with --key=conf_xxx to report these.From unknown to audit-ready
Three steps — no spreadsheets, no guesswork.
Inventory your AI
List every AI system you build or use — purpose, data, owner. One clean register.
Get your obligations
A deterministic engine classifies each system and generates the exact tasks the Act requires.
Stay audit-ready
Track tasks, attach evidence, and export a dated, audit-ready report on demand.
Everything the Act asks for
One platform — from inventory to the Annex IV technical file.
Deterministic risk classification
Prohibited, high, limited or minimal — with the exact articles and reasons. No black box.
AI system inventory
One register for every system.
Obligation tracking
Tasks with owners, due dates, recurrence.
Evidence vault
Versioned, signed, audit-ready evidence.
Live regulation alerts
Get notified when a change affects your systems.
Audit-ready reports & Annex IV
Export your inventory, classifications, obligations and evidence as one dated PDF — plus the Annex IV technical file.
Price-lock guarantee
Your renewal price never jumps. What you sign up for is what you pay.
AI Act, done deeper
We do one thing — the EU AI Act — thoroughly. Not a diluted checkbox tool.
Free risk checker
Know your risk class in two minutes, before you ever create an account.
EU-only hosting
Stored exclusively on EU servers — no US region, no replication outside the EU.
Not just the AI Act
Land on the EU AI Act, then reuse the same evidence against the AI-relevant controls of SOC 2, ISO 27001 and the rest — through crosswalks, without duplicating a single control. Crosswalks map your AI Act work across; they are not a SOC 2 or ISO 27001 audit in themselves.
Real prices, written openly
No “contact sales” wall. Every plan carries our price-lock guarantee.
A one-off, audit-ready AI Act risk & obligations report for a single system.
- Risk classification for one AI system
- Full obligations breakdown
- Annex IV starter + PDF report
- No subscription
- Optional: expert review call (+$290)
For a small team getting AI Act–ready before the deadline.
- Up to 5 AI systems
- Obligation tracking + evidence vault
- 15 policy templates
- Live regulation alerts
- Audit-ready reports
- Email support
The complete platform for companies serious about AI governance.
- Unlimited AI systems
- Everything in Starter
- AI compliance copilot
- Public Trust Center page
- ISO 42001 + NIST AI RMF mapping
- Vendor assessments
- Compliance score trends
- Priority support
For regulated organisations needing SSO, audit support and more.
- Everything in Growth
- SSO / SAML
- Unlimited team members
- Dedicated onboarding & audit support
- Custom frameworks & SLAs
Prices in USD. Launch pricing — locked for existing customers.
Proof, not logos
We'd rather earn your trust than borrow it. Instead of a wall of logos, here is what you can verify about Conformly yourself, right now.
Classification is rule-based and deterministic. Same inputs, same class — with the articles that decided it.
Your compliance record is stored exclusively on EU servers, with no replication outside the EU. Verifiable on our security page.
Discovery runs as a read-only CLI in your repo. No OAuth app, no keys handed over, nothing to review.
Run the free checker, add a system, and you have a live obligation checklist the same afternoon.
Frequently asked questions
Who is in scope of the EU AI Act?+
Any provider or deployer whose AI system is used, or whose output is used, in the EU — regardless of where the company is based. The free risk checker tells you in two minutes.
What are the key deadlines?+
Prohibited practices and AI literacy have applied since 2 Feb 2025; GPAI rules since 2 Aug 2025; Art. 50 transparency duties since 2 Aug 2026 — those three are already in force. Still ahead: the content-marking transition for systems already on the market ends 2 Dec 2026, and the 2026 Digital Omnibus moved high-risk (Annex III) obligations to 2 Dec 2027 and high-risk product-safety components (Annex I) to 2 Aug 2028.
How much does it cost?+
Transparently: a one-time $390 Compliance Report, Starter at $1,490/yr, Growth at $4,990/yr (or $490/mo), and Enterprise from $9,900. Every plan carries our price-lock guarantee.
Will my price go up at renewal?+
No. Our price-lock guarantee means the price you sign up for stays the same for as long as you remain a customer.
Can Conformly certify us to ISO/IEC 42001?+
No — and no software vendor can. An ISO/IEC 42001 certificate is issued only by an accredited certification body after an independent audit. What Conformly does is prepare exactly what that audit examines: a Statement of Applicability across all 38 Annex A controls, machine evidence from scheduled deterministic control checks, and the Clause 9 internal audit and management review records.
Where is my data hosted?+
On EU servers only. Conformly is a cloud product — your workspace lives in our EU-hosted database. There is no US region, no replication outside the EU, and no third-party processor holding a copy of your compliance record. The details are on our security page.
Does the discovery agent see my code or secrets?+
No. It reports package names, model ids, env-var names, and file hashes — never file contents, source code, or secret values. Run npx conformly-scan --dry-run to see exactly what would be sent.
Does an AI make the risk decision?+
Never. Classification is fully deterministic and rule-based. Our optional AI assistant only explains obligations and drafts documents — it never decides your risk class.
Is this legal advice?+
No. Conformly automates the organisational and documentation work of compliance and is not a substitute for qualified legal counsel.
Know your AI Act risk in 2 minutes
Run the free risk checker and get an instant classification plus the obligations that apply to you.
Run free risk check