Regulatory readiness

EU AI Act readiness starts with a list you do not have

Teams rarely stumble on the AI Act because a model misbehaved. They stumble because nobody can produce a current list of every AI system in use, who owns it, what data it touches and who signed off. That list is the work — and it starts with what your own product already leaks to the outside.

What this usually looks like

  • Asked "how many AI systems do we run?", the honest answer is a Slack thread and a guess.
  • The risk-classification spreadsheet was last updated before three new agents shipped.
  • Human-oversight obligations exist in a policy document that nothing in the stack can evidence.
  • Every customer security questionnaire now has an AI section, and each one eats days of engineering time.

What Tvijo does about it

Every capability on this page carries its real status: shipped code, work we do inside a pilot, or a design we have not built yet.

Start from what is already visible

Live today

The External AI Exposure Check reads your product from the outside and reports what anyone could already determine about its AI: provider keys in client bundles, direct browser-to-provider calls, exposed source maps, missing governance pages. Free, no account, full report shown.

An inventory with owners and risk classes

Pilot scope

Built with you during a pilot: each system, its owner, its risk class and the reasoning behind that class, kept where the next person can find it. This is assembled work today, not a self-serve product.

Oversight decisions written down

Pilot scope

Who reviewed a system, when, and what they decided — recorded next to the system it describes, which is the part auditors ask for and most stacks never store.

Inventory derived from traffic

Design intent

The design is that governed requests keep the list current by themselves. The gateway that would produce those records is not built — we will not sell you a routing story we cannot run today.

How a first month actually goes

1. Scan your own product

Live today

Two minutes, free. It usually surfaces something specific — a key in a bundle, a direct provider call — that makes the rest of the conversation concrete.

2. Scope one system, not the estate

Pilot scope

Pick the workflow that would be hardest to explain to a regulator, and document that one end to end.

3. Put the records where they will be found

Pilot scope

Inventory, risk class and oversight decisions in one place, with an owner — so next quarter is an edit rather than a repeat.

What exists today

  • External AI Exposure Check: live, free, no account; every report keeps a permanent link you can reopen or share.
  • A daily USD cap and per-call cost logging on our own model router — the practice we run on our own spend, described honestly on the cost-control page.
  • Published pricing and a form that reaches a person, not a sequence.

What we do not claim

  • This is not legal advice and we are not your counsel.
  • No product makes you "AI Act certified" — there is no such certificate.
  • SOC 2 is on the roadmap, not attested.
  • There is no gateway you can point production traffic at today. Governed lanes and traffic-derived inventory are design intent.
  • We do not publish an enforcement-date table — dates shift, and a stale table on a vendor site is worse than none.

Questions people actually ask

Does Tvijo make us compliant with the EU AI Act?

No product can. Compliance is a legal assessment your counsel signs. What we contribute is the operational material that assessment needs — what AI you actually run, how it is classified, who reviewed it — plus a free external check that finds the parts nobody registered.

What can we get in the first week, concretely?

A scan report on your own product, and a scoped plan for one system. Nothing in week one requires you to route traffic through us, because that product does not exist yet.

How is this different from hiring a consultancy?

A consultancy delivers a document. We start from a technical scan of your live product and leave the record structure behind. Many teams need both — several advisors use the check to open their own engagements.

We already run Langfuse or LangSmith. Do we need anything else?

Observability answers "what did the model do". Readiness work also needs "who authorised it, under which risk class, and can you show that months later". Different question, usually different tool — the comparison pages spell out where each one wins.

We are not in the EU. Is this irrelevant?

The same records answer customer security questionnaires and internal audit. The AI Act is the deadline that makes teams start; the underlying need is not jurisdictional.

Ask for a readiness walkthrough

Tell us which AI systems you run today. We will walk through what the records would look like and say plainly which parts we cannot cover yet.

Prefer to check us first? The record structure is written out field by field on the evidence page, and the external check shows its full report without an email.

Request a readiness walkthrough

Email or Telegram is enough. A person replies; there is no automated sales sequence.

Also useful

Other problems we cover