EU AI Act · Transparency & disclosure obligations

Go from “we need to deal with the EU AI Act” to an audit-ready evidence pack.

A guided assessment that turns what you already know about your AI product into a professional Transparency Evidence Pack — the document your enterprise buyers, security reviewers and auditors keep asking for.

  • 30–60 minutes, start to export
  • Nothing to install, no account to start
  • Your answers stay in your browser

Sound familiar?

“A prospect sent us a 40-question AI due-diligence form. We had nothing to send back.”Founder, Series A SaaS
“Our AI disclosure lives in three different documents and none of them agree with each other.”Head of Product
“We're probably fine. The problem is we can't prove it in writing to anyone who asks.”Compliance Lead

Most teams don't have a transparency problem. They have a documentation problem. You already disclose, oversee and limit your AI — it's just never been written down in one place that a buyer or regulator would recognise.

What you get

Ten sections. One document. Written to be handed over.

Your answers are turned into clear, professional statements — not a dump of form fields. Every claim is tagged with where the evidence lives, and anything missing becomes a tracked action.

01

AI system & product overview

What the system is, what it does, which AI capabilities it uses, and where it's deployed.

02

Intended purpose and users

Who it's for, who is affected by its outputs, and — just as important — what it is explicitly not for.

03

AI disclosure & transparency statements

Plain-language statements of how and where people are told they're interacting with AI, and how generated content is marked.

04

Human oversight & escalation

Your oversight model, who reviews what, how outputs get overridden, and the route for someone to contest a result.

05

Known limitations and risks

Documented failure modes, where performance drops off, the controls you run, and the risks you knowingly accept.

06

Data and input disclosures

What goes in, whether it's personal data, whether it trains anything, where it's processed, and how long it's kept.

07

User-facing notices

The actual notice wording, where it appears, in which languages — plus drafted templates you can lift straight into your product.

08

Record of transparency controls

A control register: what's in place, who owns it, how often it's reviewed, and what triggers a re-review.

09

Evidence checklist

A line-by-line table of what information was provided and where it can be verified. This is the page reviewers read first.

10

Gaps & recommended actions

Everything you couldn't answer, ranked by severity, each with a concrete next step and an owner field.

And three things you can use the same afternoon

Drafted user-facing notices

Up to six notices written from your own answers — in-product labels, a first-contact disclosure, an AI-generated content line, your primary AI notice, a privacy-notice section and a responsible-use note for business customers. Copy and publish.

A one-page customer summary

Oversight, disclosure, data handling and limitations on a single page. Send it to the prospect who asked one question, and keep the full pack for the people who want all of it.

A change log between versions

Duplicate last release's pack and the new one records exactly what changed, answer by answer — so re-issuing is a review, not a rewrite.

How it works

Four steps. One sitting.

  1. 1

    Answer a guided questionnaire

    Nine short sections, in plain English. Every question tells you why it's being asked and what a good answer looks like. Don't know something? Skip it — it becomes a tracked gap, not a blocker.

    ~45 min
  2. 2

    Review your gaps

    See an evidence readiness score, plus every gap ranked Critical, Important or Recommended — each with a specific action, not vague advice. Fix what you can in the moment, assign the rest.

    ~10 min
  3. 3

    Generate your evidence pack

    Your answers become a formatted document with a cover page, statements, control register, evidence checklist and gap register. You also get your user-facing notices drafted from your own answers, ready to paste into the product.

    Instant
  4. 4

    Export and share

    Save as PDF, download as Markdown or self-contained HTML, or export your structured answers so you can update the pack next release instead of starting over.

    ~2 min

Who this is for

Built for whoever got handed this.

The founder

“This is blocking a deal and I have two hours.”

You need something credible in front of a buyer this week. You'll answer most of it from memory, flag the rest, and export.

The product lead

“I know the product. I don't know what they want written down.”

You have all the answers already. The value here is the structure, the wording, and knowing when you're done.

The compliance lead

“I need a defensible record, not a marketing page.”

You get a control register, an evidence checklist with source references, versioning fields and a gap log you can actually work through.

Straight answer

What this is — and what it isn't.

What it is

  • A structured way to document the transparency practices you already have.
  • A professional artefact you can attach to security reviews, RFPs and vendor questionnaires.
  • A prioritised gap list with concrete next actions and owners.
  • A repeatable record you update each release instead of rebuilding from scratch.
  • A readiness score that always states how much of the questionnaire it covers.
  • A far better starting point for your lawyer than a blank page and an hourly rate.

What it isn't

  • Legal advice, or a legal opinion on your obligations.
  • A certification, audit, conformity assessment or regulatory filing.
  • A determination of whether your system is high-risk — that's a call for qualified counsel.
  • A guarantee of compliance with the EU AI Act or any other law.
  • A replacement for your privacy notice, DPA or security documentation.

We help you prepare the evidence. Your legal counsel decides what it means.

Pricing

Pay once per pack. No seats, no subscription trap.

Start the assessment free. You only pay when you're ready to export a finished pack.

Single Pack

$99one-off

One product. Everything you need to answer a buyer this week.

  • Full guided questionnaire
  • Gap review with recommended actions
  • PDF, Markdown & HTML export
  • Structured answer export for reuse
  • 30 days of revisions and re-exports

or buy now →

Portfolio

$499one-off

For a portfolio, an agency, or a compliance function.

  • Everything in Standard
  • Up to 10 products or systems
  • Versioned packs with change history
  • Reviewer sign-off and approval fields
  • Customer-facing summary one-pager

or buy now →

Every plan includes the full questionnaire, the gap review and the pack on screen — those are free and always will be. You pay to export. Your own answers export as JSON free, whatever you choose. Checkout runs on Stripe; prices exclude VAT.

Questions

Before you start

Is this legal advice?

No. This is an evidence preparation tool. It helps you assemble and articulate what your product already does in a format that reviewers recognise. It does not interpret the law for your situation, determine your risk classification, or tell you whether you are compliant. If you need that, take your finished pack to qualified counsel — you'll get a much faster, cheaper answer than starting from nothing.

How long does it actually take?

Most people finish in 30–60 minutes. If you know your product, the questionnaire moves quickly — roughly half the questions are yes/no or multiple choice. The longest sections are limitations and human oversight, because those are the ones worth thinking about. You can leave and come back; progress saves automatically.

What if I don't know an answer?

Skip it. Unanswered questions become tracked gaps in your pack, ranked by severity, each with a recommended action. A pack that honestly says “we haven't defined this yet, here's the plan” is far more credible than one with confident answers nobody can back up.

We use a third-party model. Does any of this still apply to us?

Yes, and it's one of the most common situations. If you build a product on someone else's model, you're still the one talking to your users — so disclosure, oversight, limitations and notices are still yours to document. The questionnaire branches based on whether you build the model, use someone else's, or both.

Some of your questions won't apply to us. Does that count against us?

No. Mark anything that genuinely doesn't apply as not applicable and say why. Declared questions are excluded from your readiness score rather than counted as failures — and they're listed in the pack with your reason, so a reviewer can see the decision. They're also excluded from the score rather than counted as satisfied, so waving things away can't inflate the number: if you declare a large share of the questionnaire, the headline says so.

Where does my data go?

In this version, nowhere. Your answers are stored in your own browser and the pack is generated locally on your machine. You can export a structured copy at any time, and clearing your browser data clears your answers — so export before you do.

We have more than one AI feature. Do we need a pack for each?

Generally yes — one pack per AI system, because intended purpose, oversight and limitations differ between them. Your workspace holds as many packs as you need, side by side, each with its own readiness score and gap list. If two features genuinely share a purpose, an oversight model and a set of limitations, one pack covering both is fine — just say so in the scope statement.

Our product changes constantly. Will this go stale?

That's what the version field and pack duplication are for. Copy last release's pack, clear the version, update what changed, and export — the old pack stays intact as a record of what was true then. Most teams re-run it at a major release, when they change model provider, or when they enter a new market.

Who should sign this off?

The pack includes an accountable owner field and space for a reviewer. In practice that's usually the product lead who knows the system, countersigned by whoever owns compliance or legal. The point isn't the signature — it's that one named person can answer questions about it.

You already do most of this. Let's get it written down.

Start the assessment now — you'll know within five minutes whether this is worth your afternoon.