Skip to content
EU AI Assurance OS

Product

Everything a release decision needs, in one place

AI system registry, risk classification, cited evidence, eval gates, data-contract drift, approvals, and a sealed evidence pack in one release decision. Not a notified body.

What Assurance OS is

EU AI Assurance OS is software for teams that ship AI into the EU market. It turns the system register, risk class, cited evidence, evals, data contracts, and approvals into one PASS, REVIEW, or BLOCKED decision — then seals the pack.

Policy GRC tools inventory many frameworks. This product is a release gate: if evidence, scores, contracts, or promotion files fail, the system does not pass.

EU AI Act work stalls when evidence lives in inboxes

Evidence chasing before every audit

DPIAs, model cards, and vendor docs live in shared drives and inboxes, scattered across teams — until someone has to find them all at once.

Unclear obligations per risk tier

Each risk classification implies a different set of controls, but tracking which apply to which system is manual and easy to get wrong.

No single release decision

Eval scores, contract drift, and approvals live in different tools, so “is this safe to ship?” doesn't have one clear answer.

What's in the control plane

AI System Registry
The AI system register: owner, purpose, risk class, deployment context, vendor and model, data sources, and release status — the inventory EU AI Act work actually starts from.
Risk Classification
Record prohibited, high, limited, or minimal risk with rationale, affected users, sector, and decision impact. The tier sets which controls must be on file before release.
Evidence RAG
Cited answers from DPIAs, model cards, vendor docs, incident records, and data contracts. Technical documentation stays attached to the system, not lost in a shared drive.
Eval Gates
Datasets, model and prompt versions, scores, and thresholds feed the gate. The latest completed run must meet the bar or the release does not pass.
Data Contract Monitor
Input schemas, lineage, and drift events with severity. An open breach-severity event blocks the release until it is remediated.
Approval Workflow & Audit Ledger
Route REVIEW and BLOCKED systems through owner, compliance, legal, and human-oversight sign-off. Every decision is written to a hash-chained audit ledger.
Certification readiness automation
A 0–100 readiness score and gap report toward Annex IV-shaped documentation. It is a worklist, not a certificate and not a notified-body attestation.
Evgraph promotion & dataset gates
A separate library checks approval-before-deploy and dataset licenses. Missing timestamps or licenses fail closed. We do not invent the fields.

What this is not

  • Not a notified body

    We do not assess conformity for placing a high-risk system on the market, and we do not issue a certificate or CE mark.

  • Not legal advice

    Risk class and obligation maps are assisted records you own. Counsel still signs the legal determination.

  • Not a public price list

    Work is scoped after a demo, for named systems, with a written quote. There is no self-serve checkout.

Ready to see your release gate?

Request a demo for one named AI system. We follow up with a written quote. This is not a legal certificate.