The EU AI Act doesn't ask if you're trying. It asks for evidence — Article by Article — that you meet the obligations that apply to your AI systems. Conformis produces that evidence. A defensible, audit-grade gap assessment for companies that deploy AI in the EU.
Article 99 establishes administrative fines on a sliding scale tied to the severity of the violation and the size of the offender. The maxima are real numbers. They are the higher of a fixed euro amount or a percentage of worldwide annual turnover.
The Act doesn't ask whether you've read it. It asks for evidence — by Article — that you meet the obligations applicable to your specific AI systems. The hard 90% is that gap between "the regulation applies" and "we can defend ourselves." That gap is what Conformis closes.
We treat your own risk classification as a claim to test — not a fact. Every finding is tied to a specific Article. Legal obligations are kept separate from good-practice recommendations, so your counsel knows exactly what's binding.
We inventory every AI system in actual use, identify your role (deployer, provider, or both) per system, and establish the EU nexus.
We pressure-test each system against Article 5 (prohibited), Annex III (high-risk), Article 50 (transparency), and minimal-risk categories. Self-classification is examined, not accepted.
For each applicable obligation — Art. 4 literacy, Art. 26 deployer duties, Art. 27 FRIA, Art. 50 transparency — we state what's in place, what's missing, and what evidence would close the gap.
A written report with an executive summary, eight required sections, and a prioritised action list. Final on first delivery for most clients; preliminary only where a classification question genuinely needs a follow-up call to settle.
Most "AI Act compliance" offers are content marketing for something else — a SaaS platform, a Big-Four upsell, or a generic GRC tool. Conformis is one thing: a written gap audit, conservative by default, scoped to what you actually deploy.
A single price for a single deliverable. If your exposure turns out to be small, we say so in writing — and you've still paid less than one hour of a Big-Four senior. Monitoring is available afterwards if useful.
A written, defensible gap assessment of your AI estate. Article-by-Article. Conservative by default. Delivered as PDF and Word.
For clients who want continuous coverage after the initial audit. Cancel anytime.
Six quick questions and an indicative read on your EU AI Act exposure, shown right here on the page.
Indicative only — a paid audit confirms it. ~2 minutes.
Does your organisation build AI systems, or use ones built by others?
This determines which set of obligations applies.
Is the AI used by people in the EU, or do its outputs affect people in the EU?
The Act applies even to non-EU companies if outputs reach the EU.
Does any system do any of these?
Social scoring · inferring emotions at work or school · biometric categorisation of sensitive traits · untargeted face scraping · subliminal manipulation · generating intimate or sexual images of real people without consent.
Does the AI operate in any of these areas?
Employment/hiring · credit scoring · insurance pricing · education · essential services · biometrics · critical infrastructure · law enforcement · justice.
What does the AI's output do?
Be honest about whether a person or the machine effectively decides.
Do staff who use the AI have any formal AI-literacy training?
Article 4 — in force since February 2025, applies broadly.
Your result is ready.
One step before your result — your name and work email. We use these only to follow up about a scoped next step for your situation.
This is an automated, indicative reading based on six answers — not a compliance determination and not legal advice. Real classification depends on specifics a short audit examines properly.
Book your scoping call before and your full Article-by-Article gap audit is instead of the standard . Same deliverable, same conservative method — nothing padded, nothing inflated.
One engagement, fixed fee, no retainer. We confirm scope on the call before anything is invoiced.
It depends on what you deploy. For a 100-person fintech with three or four well-defined AI use cases, €1,999 reflects roughly 10 business days of focused work, a structured methodology, and a written deliverable your lawyer can rely on. If your estate is much larger or more complex, we say so on the scoping call before quoting — we don't surprise you with scope creep. If your exposure is genuinely small, you still get a short, honest written report.
A law firm gives you a legal opinion. We give you a gap audit — a structured, evidence-based mapping of your actual AI estate to the obligations that apply. The two are complementary. Many of our clients pair our written report with a brief legal review from their existing counsel; the report makes that review faster and cheaper because the factual work is already done.
The report is conservative by default, which means if anything we lean toward flagging exposure, not dismissing it. But "conservative" doesn't mean "manufactured." If we conclude your AI use is genuinely limited or out of scope, we say so in writing — and we explain the reasoning. You can take that to your customer or DPO; that's often exactly what they're asking for.
No, and no. Conformis produces a compliance gap audit — a factual, structured assessment against the Act's provisions. It is not a legal opinion and does not establish a lawyer-client relationship. Where you need a binding legal view (for example, on an ambiguous classification), we will say so and recommend you take that specific question to counsel. The report is designed to make that handoff efficient.
Every audit includes an adjacent-regime check — primarily GDPR (because most AI systems process personal data and FRIA/DPIA obligations overlap), and sector-specific overlays where relevant (DORA for financial services, the EU Health Data Space for health, etc.). We flag where the AI Act adds obligations versus where it duplicates existing ones.
You answer six quick questions, then enter your name and work email to see your indicative result on the page. We use those details only to follow up within two business days with a scoped next step. The check itself is genuinely free; if your exposure looks minimal we'll tell you that and not pitch you an audit.
Find out where you stand. Two minutes, and you'll see your result right on the page.