New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

Getting started

Getting started

EuroCompliant turns two large regulations into tracked, evidenced work. This guide covers the shape of the platform and the order operations have to happen in, because several later steps are impossible until earlier ones are done.

Transcript

This is the EuroCompliant dashboard: the single place your organisation can see how much of its regulatory obligation is actually met.

That matters because of accountability. GDPR Article 5, paragraph 2 does not simply require you to comply. It requires you to be able to demonstrate that you comply.

The compliance roadmap tracks the four stages every organisation moves through: describing your organisation, registering your systems (AI and regular), classifying their risk, and producing the documentation the law expects.

Urgent alerts sit above everything else, because two obligations here are hard legal deadlines. A personal data breach must reach your supervisory authority within seventy-two hours. A data subject request must be answered within one month.

Each framework you enable (the AI Act, GDPR, DORA and the rest) generates its own obligations. Enable only the regimes you are actually subject to.

The Executive Summary and the posture trend beneath it are built for reporting upward: overall compliance, readiness by framework, and how that trend is moving, without opening a single obligation.

Priority Actions and Gap Analysis rank what actually needs attention next, so the question is never just what is missing, but what to do about it first.

Start by registering your systems, AI and otherwise. The inventory covers both regular and AI systems, and nothing else can be assessed, documented or evidenced until it exists.

Why this is required

Both regimes this platform covers are built on the same principle: it is not enough to comply, you must be able to demonstrate that you comply. GDPR Article 5(2) states that duty explicitly and calls it accountability. The EU AI Act expresses the same idea through its documentation, logging and record-keeping obligations.

The practical consequence is that compliance is an evidence-production problem. A regulator's question is rarely 'did you think about bias'; it is 'show me what you did, when you did it, and who signed it off'. An organisation that did the right thing but cannot prove it is, in enforcement terms, in much the same position as one that did not.

This is also why the order matters. You cannot classify a system's risk before the system is registered; you cannot generate Annex IV technical documentation before the classification exists; and you cannot evidence a control before there is a checklist item to attach it to.

What EuroCompliant does

The dashboard is the accountability view. The compliance roadmap tracks the four stages every organisation moves through (organisation profile, system registration, risk classification, documentation) and shows which one you are actually blocked on.

Urgent alerts are separated from everything else because two obligations in the platform are hard legal deadlines rather than good practice: the seventy-two hour breach clock and the one-month data subject request clock. Both count down in real time.

Pending tasks are drawn from the checklists generated for each registered system, so the dashboard reflects your actual obligation set rather than a generic list.

Deadlines

2 February 2025Prohibited practices (Article 5) and the AI literacy duty (Article 4) already apply.
2 August 2025General-purpose AI model obligations apply.
2 December 2027The main high-risk obligations apply, including Annex III systems. (Postponed from 2 August 2026 by the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026.)
2 August 2028High-risk obligations apply to AI as a safety component of products regulated under Annex I. (Postponed from 2 August 2027 by the same Digital Omnibus.)

Walking through it

1

Complete your organisation profile

Your sector, size, jurisdictions and role (provider, deployer, or both) determine which obligations apply. The AI Act imposes materially different duties on providers and deployers, so this answer shapes everything downstream.

Open /settings/profile →
2

Enable the frameworks that apply to you

Turn on the regimes you are actually subject to. Enabling a framework generates its checklist items and unlocks its document types; enabling everything produces noise rather than compliance.

Open /settings/profile?tab=frameworks →
3

Register your systems

Add every AI system, and every conventional IT system that processes personal data. This is the inventory everything else attaches to.

Open /systems →
4

Classify each system's risk

Run the assessment. The classification determines which obligations the system carries under the AI Act.

Open /compliance-docs →
5

Work the generated checklists

Each classified system produces its obligation set. Complete items and attach evidence as you go.

Open /compliance-docs →
6

Generate your documentation

With systems registered and assessed, the document generator has the data it needs to produce Annex IV technical documentation, records of processing and the rest.

Open /compliance-docs →

The law

Frequently asked

Are we a provider or a deployer?

You are a provider if you develop an AI system, or have one developed, and place it on the market or into service under your own name or trademark. You are a deployer if you use an AI system under your own authority in a professional capacity. Many organisations are both: a deployer of purchased tools and a provider of anything they build. Note that substantially modifying a high-risk system, or putting your own branding on it, can make you a provider of it.

Does the AI Act apply to us if we are not in the EU?

Possibly. Article 2 extends the Act to providers placing systems on the EU market regardless of where they are established, and to providers and deployers outside the EU where the system's output is used within the EU.

Do we need to do all of this at once?

No, but the order is not negotiable. Register systems first, because the inventory is what every other obligation attaches to. Prohibited practices and AI literacy are already in force, so those are worth checking immediately.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial