A rules engine for the law — not a chatbot guessing at it.
Most tools either hand you a static checklist or ask a language model to improvise your obligations. Veritome does neither. The legal core is a structured, article-by-article model of the Act that reads each system's role, risk tier and characteristics, and returns the precise set of obligations, deadlines and evidence it owes — and nothing it does not.
The engine's internal logic is Veritome intellectual property. What we share openly is the outcome — the exact article references behind every obligation — so your record is fully auditable without exposing how the mapping is built.
From first classification to live monitoring, in six phases.
Every system moves through the same journey. Phases are gate-locked — you cannot register a system you have not assessed — and a phase with nothing that applies to your role is passed automatically. The bar at the top of each system shows exactly where it stands.
Classify
Know exactly what you are holding.
Answer a short set of questions per system. The engine returns a risk tier — prohibited, high, limited or minimal — anchored to the articles that decide it, plus the Art. 6(3) exception where it applies.
Scope
See only the obligations that are actually yours.
Your role (provider, deployer, importer, distributor) and risk tier resolve to the exact obligation set — nothing generic, nothing missing. A deployer of a limited-risk chatbot and a provider of a high-risk system get two different, correct lists.
Implement
Put the controls in place, with the proof attached.
Work each obligation as a guided checklist — human oversight, logging, data governance, technical documentation — attaching evidence as you go. Evidence carries expiry dates, so coverage stays honest over time.
Assess
Run the assessments the Act requires, on the record.
Guided fundamental-rights (FRIA) and conformity assessments, with a sealed report at the end. Where a DPIA already exists under the GDPR, the overlap is mapped so you do not do the same work twice.
Register
Hand the regulator a dossier with every decision traced to its article.
Annex VIII registration fields pre-filled from your system record, a Declaration of Conformity, and a hash-sealed dossier with a public verify URL your auditor can check independently.
Monitor
Keep the obligations live after go-live, not just at launch.
Post-market monitoring, serious-incident reporting inside the Art. 73 window, scheduled reviews, and a regulatory-change watch that flags when the law — or your obligation set — moves under you.
Switch a framework on and it becomes a programme.
The EU AI Act and the GDPR are statutory and always on. ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF are yours to enable, and when you do, each becomes a programme: ordered steps in gated phases, one record per step, credit wherever a requirement is already evidenced by something you did for another framework.
The coverage matrix shows every requirement and what closes it. The Statement of Applicability is generated from the programme. The certificate, for any standard, comes from an accredited body — never from us.
The five frameworks and their crossoverWhat the engine will and will not do
Four questions we are asked on most evaluation calls, answered as the product ships today.
Is the obligation mapping done by an AI model?
No. The mapping is a deterministic rules engine: role, risk tier, Annex III area and behavioural flags resolve to the obligation set, and every obligation cites its article. Aria, the assistant, drafts and proposes; it never decides a classification or files anything.
What happens to the other frameworks?
The EU AI Act and the GDPR are statutory and always on. ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF are voluntary; switch one on and it runs as a programme of ordered steps, with credit wherever a record you already produced satisfies a clause.
Can I skip a phase?
Phases are gate-locked — you cannot register a system you have not assessed — but a phase with no applicable obligations for your role is complete by definition and the journey moves past it.
Is any of this legal advice?
No. Veritome structures the work and cites the law; the judgement calls belong to you and your counsel. Every screen names the article it rests on so that review is possible rather than guesswork.
Want the article-by-article view? Read the EU AI Act guide.
