Skip to content
AIRAS Cloud

EU AI Act compliance

EU AI Act compliance, run as an operating process

Policies do not evidence compliance; records do. AIRAS Cloud runs the full sequence — discovery, inventory, role, screening, classification, obligations, controls, review, decision, monitoring and export — with deterministic criteria and an append-only audit trail.

Why EU AI Act programmes stall

Almost every stalled programme we see has the same three characteristics: an incomplete inventory that excludes embedded and staff-adopted AI, classification decisions that two competent people would reach differently, and evidence scattered across spreadsheets, ticket systems and email. Each one is survivable in isolation. Together they make any readiness statement indefensible.

The fix is not more policy. It is a single governed path that every AI use must travel, with the same criteria applied every time and the record produced as a by-product of doing the work.

  • Incomplete inventory — vendor and embedded AI never entered the register
  • Inconsistent classification — outcomes depend on who assessed
  • Unowned controls — obligations mapped but never assigned
  • Self-approval — the assessor and the approver are the same person
  • Static assessment — no trigger when a model, data source or threshold changes
  • Unrehearsed evidence — nobody has tried to export the pack

The compliance operating model

AIRAS Cloud implements the Regulation as a workflow rather than a questionnaire. Each stage has an owner, a required input, a recorded outcome and a gate that cannot be skipped.

  • Discover — extract AI systems, models and vendor features from your documents and contracts
  • Register — one authoritative inventory with named accountable owners
  • Screen — Article 5 prohibited practices answered before design effort is spent
  • Determine role — provider, deployer, importer or distributor, per system, with reasoning
  • Classify — deterministic, version-controlled risk classification with mandatory floors
  • Derive — applicable obligations and controls, with dates and evidence completeness
  • Review — independent human reviewer, separated from the assessor
  • Decide — recorded approval, conditions or refusal, attributable to a named person
  • Monitor — logging, incidents, drift and material-change reassessment triggers
  • Evidence — exportable assessment and decision packs from append-only history

Deterministic classification, not model opinion

Classification in AIRAS Cloud is produced by ARIE, a deterministic regulatory reasoning engine with versioned rulesets. Identical inputs produce an identical outcome and an identical readable explanation trace, mandatory floors prevent contexts that cannot be rated low from being scored down, and a prohibited-practice signal cannot be overridden by a favourable score.

That property is what makes the record defensible two years later: you can show which ruleset version applied on the day the decision was made, and reproduce the result.

Evidence a regulator, auditor or customer will accept

Enterprise procurement, insurers and auditors now ask AI questions before contract. The evidence pack AIRAS Cloud exports answers them from the record rather than from marketing claims: what the system is, who owns it, what was assessed and under which criteria, which controls applied and whether their evidence is complete, who approved it, what has been monitored and what has changed.

Where to go next

If you are still establishing what the Regulation requires, start with the guide. If you are implementing in Ireland, use the Irish hub. If you want a number before a conversation, the readiness check scores nine dimensions in three minutes.

Frequently asked questions

What does EU AI Act compliance software actually do?
It runs and records the operating process the Regulation assumes you already have: a complete AI register, per-system role determination, prohibited-practice screening, risk classification under versioned criteria, derived obligations and controls, independent human review, monitoring, material-change reassessment and an exportable evidence pack. It does not interpret the law for you and it does not approve anything.
Where should an organisation start?
With discovery and the inventory. Until there is one authoritative register of AI systems, models, agents and embedded vendor features with named owners, no role determination, classification or readiness statement can be relied upon. AIRAS Cloud can build that register from your existing documents and contracts rather than from a blank form.
How long does an EU AI Act compliance programme take?
Our controlled enterprise pilot runs for eight weeks and is designed to prove the process on your real obligations, with a costed roadmap to production. The pace after that depends on the size of the estate and how much high-risk and Article 50 exposure it contains.
Does using AIRAS Cloud make us compliant?
No. Compliance is a legal conclusion about your organisation, reached with your own advisers. AIRAS Cloud makes the work repeatable, consistent and evidenced so that conclusion can be defended.

See EU AI Act compliance operate on real workflows.

Thirty minutes, no confidential information required: discovery, classification, obligations, review and the evidence export, shown end to end.

No commercial commitment. No confidential information required.