EU
AI Act Compliance Platform
Regulation (EU) 2024/1689 — high-risk obligations apply 2 August 2026

EU AI Act compliance
without the Big Four invoice.

We turn the EU AI Act into a checklist you can finish. Tell us about your AI, and we tell you which rules apply, what's missing, and hand you the documents a regulator expects to see.

It starts with a 15-minute check to see if the Act even applies to you. If it does, we walk you through the rest — reusing your existing GDPR work, chasing your vendors for you, and ending with proof you can show any customer.

Start with the 15-minute triageSee how it worksNo credit card · out-of-scope users leave with a signed certificate
Regulation coverage
113 Articles
Classification framework
6-gate engine
Built-in artefacts
FRIA · PMM · Art. 73
Literacy training (Art. 4)
6 modules · 37 Qs
Member State authorities
EU-27 + EEA
Process

From ‘what’s AI?’ to audit-ready in five stages.

The platform takes you through the compliance lifecycle in the same order the Act itself is structured.

STEP 01

Discovery

An AI-guided interview identifies every AI system you provide, deploy, or integrate — including the ones hidden inside your SaaS.

STEP 02

Classification

A six-gate engine maps each system against Articles 5, 6, 50 and Annex III with traceable reasoning at every step.

STEP 03

Gap assessment

Role-aware analysis for providers and deployers across Articles 9–15 and 26, with priorities and deadlines.

STEP 04

Human validation

Every material classification is reviewed before it becomes your compliance record.

STEP 05

Audit evidence

Generate Annex IV documentation, FRIAs, post-market monitoring plans, and Article 73 incident reports on demand.

Capabilities

Every Article the SMB needs. Nothing it doesn’t.

The platform ships with the specific obligations every provider and deployer must meet — not a generic GRC toolkit.

Art. 3

Intelligent discovery

Conversational AI + document intelligence surfaces every AI system in your organisation, including vendor-embedded features most inventories miss.

Arts. 5, 6, 50

Six-gate classification

Deterministic rules for clear cases; LLM reasoning with citations for edge cases; mandatory human validation on every material output.

Arts. 9–15, 26

Role-aware gap assessment

Different obligations apply to providers and deployers. Each gap maps to a specific Article, with recommended actions, priorities, and deadlines.

Art. 27

FRIA workflow

Guided Fundamental Rights Impact Assessment for public authorities, private entities providing public services, and Annex III points 5(b)/(c).

Art. 73

Serious incident reporting

2-day / 10-day / 15-day SLA countdown, EU-27 + EEA authority directory, structured Commission-template report generator.

Art. 72

Post-market monitoring

Default metric catalogue grounded in Arts. 9–15, threshold-driven alerts, periodic reviews with Art. 79 risk escalation, Annex IV-ready plan PDF.

Art. 25

Value-chain contracts

Six grounded templates (Provider–Deployer, GPAI, Art. 25(4) addendum, substantial modification, purpose change, supplier bundle). Track counterparties and role-switching events.

Art. 4

AI literacy programme

Six role-based training modules with 37 quiz questions, completion certificates, and org-wide coverage tracking — auditable Art. 4 evidence.

Annex IV

Audit-ready exports

Technical documentation, conformity evidence, incident reports, literacy certificates, and monitoring plans in PDF and JSON formats.

Built for Marta, not McKinsey

Four things you won’t find in a generic GRC tool.

The AI Act SMBs face the same obligations as the Fortune 500 — but with a fraction of the budget. These are the four entry-points we built because no one else did.

15-min path

Express Triage

Am I even in scope?

A structured 11-question wizard that gives you a deterministic scope verdict in a coffee break. Out-of-scope users leave with a signed PDF certificate — no upsell, no funnel trap.

Arts. 2, 3(1), 5, 6, 50, 51
Onboarding accelerator

GDPR → AI Act Bridge

Reuse what you already did.

Import your Art. 30 ROPA entries and Art. 35 DPIAs. One click turns ROPA-with-AI into inventory entries; one click syncs your DPIA into a pre-filled FRIA. Article 27(4) exists for exactly this.

Art. 27(4)
Value-chain evidence

Vendor AI Act DDQ

Answer the Art. 25(4) question.

Send a 47-question DDQ to your AI vendors via a tokenised public link — no account for them to create. Responses auto-file into your Art. 25 dossier. Vendors answer once, share with every customer.

Arts. 25(4), 25(5)
Procurement-ready

Public Trust Profile

Answer procurement once.

Publish a versioned, SHA-256-signed attestation at a shareable URL. Enterprise buyers see your compliance posture without an NDA; you stop filling in the same RFP questionnaire twice a month.

Attestation + growth loop
15-minute first value
Triage certificate in one sitting
Zero re-entry
Your GDPR work imports directly
Network-effect vendor portal
Answer once, share with every customer
Signed attestation
SHA-256 tamper-evident, versioned
Pricing

Priced for SMBs

Free forever to understand your exposure. A subscription to run the programme. A one-time pack to download your paperwork. Pick what you need — they stack, none requires the other.

Start free
€0forever

Triage, discovery, classification and your Trust Profile. No card.

Subscriptions
from €149/ month

Run the ongoing programme — literacy, vendor DDQs, monitoring, incidents.

Compliance Pack
€499one-time

Unlock every signed, downloadable document a regulator asks for.

See all plans & pricing
Who it’s for

Different roles. Different obligations. Same platform.

The Act treats providers and deployers differently. The platform knows the difference — and the value chain between you.

Art. 3(3)

Provider

You develop, train, or place AI systems on the EU market. Providers carry the bulk of the compliance load: conformity assessment, documentation, post-market monitoring.

  • Risk management system (Art. 9)
  • Technical documentation (Art. 11 + Annex IV)
  • Conformity assessment (Art. 43)
  • Post-market monitoring (Art. 72)
  • Serious incident reporting (Art. 73)
Art. 3(4)

Deployer

You use AI systems under your authority in the EU. Deployers are responsible for operational governance, human oversight, and transparency to affected persons.

  • Use per instructions (Art. 26(1))
  • Human oversight assignment (Art. 26(2))
  • Log retention for 6+ months (Art. 26(6))
  • FRIA where applicable (Art. 27)
  • Transparency to affected persons (Arts. 26(9), 50)

Start before the deadline finds you.

Most SMBs will need months of work to meet the 2 August 2026 high-risk deadline. Begin with a free discovery session. No credit card required.

Create free accountSee pricing
EU Sovereign Infrastructure

Your data stays in Frankfurt, Germany.
Fully EU-sovereign.

Synaptico’s application hosting and data storage run exclusively from EU infrastructure in Frankfurt — under EU jurisdiction and European data-protection law. Your AI-Act evidence lives where your regulators do.

  • EU-resident data · EU-resident processing
  • EU-only transit · no cross-border egress
  • End-to-end TLS 1.3 · AES-256 at rest
  • 24/7 monitoring · EU operations
  • GDPR · Schrems II · DPA-aligned
frankfurt · online99.98% uptime