Read this and tell me it doesn't sound familiar.
“We use eight AI tools and I genuinely don't know which ones the Act applies to.”
“Our lawyer's quote was twenty thousand euro just to map our obligations.”
“An auditor showed up and we had no documentation, just folder names.”
Built for teams that don't have a Chief Compliance Officer.
Onboarding in an afternoon
Add your AI systems, run the classification wizard, accept Aria's mapped obligations. No rollout programme, no consultancy.
No legal background needed
Every screen explains the obligation in plain English alongside the article reference. Legal judgement only where it actually matters.
Pay only for what you use
Starts at €0 (free tier, one system). Scales linearly. No 12-month minimum, no implementation fee.
Audit-prepared in weeks
By month-end of Month 1 you have a classified portfolio, mapped obligations, signed Annex IV and a public verify URL — what an auditor asks for first.
Vendor-AI covered
Most SMEs are deployers, not providers. The deployer journey is the simpler one — IFU receipt, oversight plan, worker notification — and it's the default in Veritome.
AI literacy that ticks Art. 4
Six role-based programmes, certificates per person, org-level dashboard. Tick the obligation without buying a separate LMS.
Three companies, three starting points.
A 25-person marketing agency using GenAI tools (ChatGPT, Midjourney, Jasper) on client work.
- Each tool added to the system register in <2 minutes.
- Classification: most fall under Limited Risk (Art. 50 transparency).
- Obligation engine flags the disclosure-notice obligation; smart form drafts the text.
- Done — no Annex IV, no FRIA, no high-risk burden.
A 40-person e-commerce SME using a recommendation engine that ranks suppliers.
- Classification flags the system as Annex III §5 (essential services adjacent).
- Engine materialises 9 high-risk provider obligations across 4 phases.
- Quality Management System scaffolded from existing policies; sign-off ledger started.
- Annex IV technical doc auto-assembled from the smart forms; DoC drawn up in the editor.
A 12-person professional-services firm receiving a high-risk provider's IFU package.
- Provider sends an Art. 13 IFU sharing token by email.
- Compliance lead pastes the token into Veritome; package imports in seconds.
- Deployer obligations auto-populate — oversight plan template, monitoring schedule, worker notification.
- Hash chain links the deployer's record back to the provider's seal.


