Small Business · 5–50 people

Compliance without a compliance team.

The EU AI Act doesn't care that you're a 12-person agency or a 30-person SaaS. Veritome gives you the same engine the enterprises use, with an onboarding that fits an afternoon — not a quarter-long programme.

Start the readiness check — 5 minSee pricing

No credit card · EU-hosted · 5-min

The reality

Read this and tell me it doesn't sound familiar.

We use eight AI tools and I genuinely don't know which ones the Act applies to.

Most teams default to 'all of them' or 'none of them'. The classification wizard puts a yes/no answer next to each system in under 10 minutes.

Our lawyer's quote was twenty thousand euro just to map our obligations.

The engine maps obligations from your classification automatically. You spend lawyer time on the things that actually need legal judgement, not on a glossary exercise.

An auditor showed up and we had no documentation, just folder names.

Every form fills evidence at the item level. Annex IV, FRIA and DoC documents assemble themselves; nothing lives in a Drive folder anyone can rename.
What you get

Built for teams that don't have a Chief Compliance Officer.

Onboarding in an afternoon

Add your AI systems, run the classification wizard, accept Aria's mapped obligations. No rollout programme, no consultancy.

No legal background needed

Every screen explains the obligation in plain English alongside the article reference. Legal judgement only where it actually matters.

Pay only for what you use

Starts at €0 (free tier, one system). Scales linearly. No 12-month minimum, no implementation fee.

Audit-prepared in weeks

By month-end of Month 1 you have a classified portfolio, mapped obligations, signed Annex IV and a public verify URL — what an auditor asks for first.

Vendor-AI covered

Most SMEs are deployers, not providers. The deployer journey is the simpler one — IFU receipt, oversight plan, worker notification — and it's the default in Veritome.

AI literacy that ticks Art. 4

Six role-based programmes, certificates per person, org-level dashboard. Tick the obligation without buying a separate LMS.

In practice

Three companies, three starting points.

USE CASE 01

A 25-person marketing agency using GenAI tools (ChatGPT, Midjourney, Jasper) on client work.

  • Each tool added to the system register in <2 minutes.
  • Classification: most fall under Limited Risk (Art. 50 transparency).
  • Obligation engine flags the disclosure-notice obligation; smart form drafts the text.
  • Done — no Annex IV, no FRIA, no high-risk burden.
Veritome guided classification — the five-step register wizard that walks Article 5, Annex I, Annex III and the Article 6(3) exception
USE CASE 02

A 40-person e-commerce SME using a recommendation engine that ranks suppliers.

  • Classification flags the system as Annex III §5 (essential services adjacent).
  • Engine materialises 9 high-risk provider obligations across 4 phases.
  • Quality Management System scaffolded from existing policies; sign-off ledger started.
  • Annex IV technical doc auto-assembled from the smart forms; DoC drawn up in the editor.
Veritome obligation workbench — engine-derived obligations across the six-phase journey, filterable by phase and system with per-item status
USE CASE 03

A 12-person professional-services firm receiving a high-risk provider's IFU package.

  • Provider sends an Art. 13 IFU sharing token by email.
  • Compliance lead pastes the token into Veritome; package imports in seconds.
  • Deployer obligations auto-populate — oversight plan template, monitoring schedule, worker notification.
  • Hash chain links the deployer's record back to the provider's seal.
Veritome Article 13 Instructions-for-Use package — provider identity, intended purpose and the nine required elements for provider-to-deployer handoff
What you'll lean on

The capabilities small teams use most.