REGULIX.ai
Regulix › EU AI Act compliance software
Regulation (EU) 2024/1689

EU AI Act compliance software and automated model auditing

Every AI system inventoried, classified by risk tier under Regulation (EU) 2024/1689, and assessed against the obligations that follow, from a read-only connection.

Start a free assessment Browse the regulation library

The obligation almost nobody has mapped

The EU Artificial Intelligence Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and applies in phases. Prohibited practices and AI literacy duties took effect in February 2025. Obligations for general-purpose AI models followed in August 2025. Obligations for high-risk systems listed in Annex III phase in during 2026, and Annex I product-embedded systems follow in 2027.

The practical difficulty is that most regulated firms cannot answer the first question the Act asks: which AI systems do we operate, and what tier is each one. A crypto or financial services firm typically runs models for credit or leverage decisions, fraud detection, identity verification, customer support and pricing. Some of those are high-risk. Some are expressly carved out. Some carry only transparency duties.

Penalties reach EUR 35 million or 7 percent of total worldwide annual turnover for the most serious infringements.

Risk tiering is not obvious

The answers are frequently counter-intuitive, which is why generic governance tooling tends to get them wrong.

SystemTypical positionReference
Creditworthiness assessmentHigh-riskAnnex III, 5(b)
Fraud detection in financial servicesExpressly carved out of that headingAnnex III, 5(b)
Biometric identity verificationContested, fact-dependentAnnex III, 1
Customer-facing chatbotTransparency obligationsArt 50

Getting the tier wrong in either direction is costly. Over-classifying imposes conformity obligations that do not apply. Under-classifying leaves a high-risk system ungoverned.

What Regulix assesses

Regulix inventories the AI systems a firm actually runs, classifies each against the Act's criteria, and then tests the obligations that follow for that tier, including data and data governance under Article 10, record-keeping and logging under Article 12, human oversight under Article 14, and transparency under Article 50.

Classification is rules-based by default. An optional language-model classifier can be applied to free-text system descriptions, and every result from it is flagged for human review with the rules engine as fallback. Contested classifications are surfaced as contested rather than resolved silently, because a borderline Annex III question is a legal judgment and belongs with counsel.

Findings cite the specific article engaged and carry a remediation, and the whole assessment sits alongside GDPR, MiCA, DORA and the other frameworks in the engine.

Why this is not covered by existing tools

Security compliance platforms automate SOC 2 and ISO 27001. They answer to an auditor and they prove that a firm's security posture is sound. They do not read the Artificial Intelligence Act, and they do not look at the models a firm runs.

Consultancies do read the Act, and they produce a considered assessment at a point in time, which is out of date once a model is retrained or a new one is deployed.

The gap is automated, continuous auditing of AI systems against the provisions of the Act itself. That is the subject of a United States non-provisional patent application filed by Regulix, application number 19/691,418.

Frequently asked questions

When do the EU AI Act obligations apply?

The Act entered into force on 1 August 2024 and applies in phases. Prohibited practices and AI literacy duties applied from February 2025, general-purpose AI model obligations from August 2025, Annex III high-risk obligations phase in during 2026, and Annex I product-embedded systems follow in 2027.

Which AI systems in a crypto firm are high-risk?

It depends on function rather than sector. Creditworthiness assessment used to extend leverage typically falls under Annex III, 5(b). Fraud detection is expressly carved out of that heading. Biometric identity verification is fact-dependent and often contested. Customer chatbots generally carry transparency obligations under Article 50.

What are the penalties under the EU AI Act?

Up to EUR 35 million or 7 percent of total worldwide annual turnover for the most serious infringements, with lower tiers for other breaches.

Does Regulix classify models automatically?

Yes, rules-based by default, with an optional language-model classifier for free-text descriptions whose output is always flagged for human review. Contested classifications are surfaced as contested rather than resolved automatically.

Can compliance software replace legal advice on the AI Act?

No. Regulix is decision support. It shows continuously where your systems stand against the provisions and produces the evidence. Interpretation of borderline classifications, and sign-off, remain with qualified counsel.

Related

MiCA compliance software DORA compliance software Regulatory intelligence library The Regulix platform

See where your firm stands

Connect a read-only data source and get a provision-level assessment across EU AI Act and the other frameworks that apply to you.

Regulix provides decision support and evidence for compliance functions. It does not constitute legal advice, and it does not replace authorisation by a competent authority or sign-off by qualified counsel.