Three conversations every founder has had this year.
The shape of compliance when you ship the AI yourself.
Three startups, one engine.
A 14-person HR-tech startup with a CV-screening product — Annex III §4, high-risk provider.
- Classification places the system in §4 in under ten minutes; Aria reasons through the §4 versus §5 split.
- The engine materialises the full provider obligation set across the six phases.
- Annex IV assembles from the model card, the training-data record and the risk plan.
- The DoC is drawn up in the editor; the dossier goes into the Series A data room.
A 22-person legal-tech startup fine-tuning an open-source LLM for contract review.
- GPAI provider duties (Art. 53) sit beside the high-risk provider set; Art. 55 appears only above the systemic-risk threshold.
- The training-data summary and copyright policy are filed in the GPAI tab.
- Compute and energy figures are recorded once and carried into the model documentation.
- Downstream-developer documentation is generated in the same flow.
A 9-person healthtech startup pre-launch — CE marking under the MDR and EU AI Act conformity in parallel.
- The Annex I product route is recorded, so the notified-body procedure carries the EU AI Act conformity assessment with it.
- The notified body's certificate reference is tracked beside the conformity assessment.
- Annex IV is reused as the MDR technical-file annex — same evidence, two regulations.
- The FRIA runs because the system reaches end users; deployer hospitals can import it.
The capabilities that get you to ship.
Questions founders ask
We build the AI product. Are we the provider?
If you place an AI system on the EU market or put it into service under your own name, yes — and the Article 16 provider duties land on you before they reach your customer. Article 25 also makes a deployer the provider when they put their name on a system or substantially modify it; the classification tests both.
What does an investor's 'EU AI Act readiness pack' actually contain?
There is no button by that name. What a data room wants is a classification record per system, the mapped obligations with their status, the Annex IV technical file, the Declaration of Conformity where one applies, and the dossier with a public verify URL. Veritome produces each of those from the register; one link goes in the data room.
Do we need ISO/IEC 42001 as well?
Not by law — it is voluntary. Enterprise procurement increasingly asks for it, so Veritome runs it as a programme pre-credited from your EU AI Act work, and the certificate comes from an accredited body. The pricing page says which plan carries it.
We fine-tune an open model. Which duties apply?
Placing a general-purpose model on the market brings the Article 53 documentation, copyright-policy and training-summary duties; the Article 55 systemic-risk duties apply only above that threshold. The GPAI tab records them alongside the high-risk provider set.



