EU AI Act compliance software and automated model auditing
Every AI system inventoried, classified by risk tier under Regulation (EU) 2024/1689, and assessed against the obligations that follow, from a read-only connection.
The obligation almost nobody has mapped
The EU Artificial Intelligence Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and applies in phases. Prohibited practices and AI literacy duties took effect in February 2025. Obligations for general-purpose AI models followed in August 2025. Obligations for high-risk systems listed in Annex III phase in during 2026, and Annex I product-embedded systems follow in 2027.
The practical difficulty is that most regulated firms cannot answer the first question the Act asks: which AI systems do we operate, and what tier is each one. A crypto or financial services firm typically runs models for credit or leverage decisions, fraud detection, identity verification, customer support and pricing. Some of those are high-risk. Some are expressly carved out. Some carry only transparency duties.
Penalties reach EUR 35 million or 7 percent of total worldwide annual turnover for the most serious infringements.
Risk tiering is not obvious
The answers are frequently counter-intuitive, which is why generic governance tooling tends to get them wrong.
| System | Typical position | Reference |
|---|---|---|
| Creditworthiness assessment | High-risk | Annex III, 5(b) |
| Fraud detection in financial services | Expressly carved out of that heading | Annex III, 5(b) |
| Biometric identity verification | Contested, fact-dependent | Annex III, 1 |
| Customer-facing chatbot | Transparency obligations | Art 50 |
Getting the tier wrong in either direction is costly. Over-classifying imposes conformity obligations that do not apply. Under-classifying leaves a high-risk system ungoverned.
What Regulix assesses
Regulix inventories the AI systems a firm actually runs, classifies each against the Act's criteria, and then tests the obligations that follow for that tier, including data and data governance under Article 10, record-keeping and logging under Article 12, human oversight under Article 14, and transparency under Article 50.
Classification is rules-based by default. An optional language-model classifier can be applied to free-text system descriptions, and every result from it is flagged for human review with the rules engine as fallback. Contested classifications are surfaced as contested rather than resolved silently, because a borderline Annex III question is a legal judgment and belongs with counsel.
Findings cite the specific article engaged and carry a remediation, and the whole assessment sits alongside GDPR, MiCA, DORA and the other frameworks in the engine.
Why this is not covered by existing tools
Security compliance platforms automate SOC 2 and ISO 27001. They answer to an auditor and they prove that a firm's security posture is sound. They do not read the Artificial Intelligence Act, and they do not look at the models a firm runs.
Consultancies do read the Act, and they produce a considered assessment at a point in time, which is out of date once a model is retrained or a new one is deployed.
The gap is automated, continuous auditing of AI systems against the provisions of the Act itself. That is the subject of a United States non-provisional patent application filed by Regulix, application number 19/691,418.
Frequently asked questions
When do the EU AI Act obligations apply?
The Act entered into force on 1 August 2024 and applies in phases. Prohibited practices and AI literacy duties applied from February 2025, general-purpose AI model obligations from August 2025, Annex III high-risk obligations phase in during 2026, and Annex I product-embedded systems follow in 2027.
Which AI systems in a crypto firm are high-risk?
It depends on function rather than sector. Creditworthiness assessment used to extend leverage typically falls under Annex III, 5(b). Fraud detection is expressly carved out of that heading. Biometric identity verification is fact-dependent and often contested. Customer chatbots generally carry transparency obligations under Article 50.
What are the penalties under the EU AI Act?
Up to EUR 35 million or 7 percent of total worldwide annual turnover for the most serious infringements, with lower tiers for other breaches.
Does Regulix classify models automatically?
Yes, rules-based by default, with an optional language-model classifier for free-text descriptions whose output is always flagged for human review. Contested classifications are surfaced as contested rather than resolved automatically.
Can compliance software replace legal advice on the AI Act?
No. Regulix is decision support. It shows continuously where your systems stand against the provisions and produces the evidence. Interpretation of borderline classifications, and sign-off, remain with qualified counsel.
Related
See where your firm stands
Connect a read-only data source and get a provision-level assessment across EU AI Act and the other frameworks that apply to you.
Regulix provides decision support and evidence for compliance functions. It does not constitute legal advice, and it does not replace authorisation by a competent authority or sign-off by qualified counsel.