Getting started
Getting started
EuroCompliant turns two large regulations into tracked, evidenced work. This guide covers the shape of the platform and the order operations have to happen in, because several later steps are impossible until earlier ones are done.
Transcript
This is the EuroCompliant dashboard: the single place your organisation can see how much of its regulatory obligation is actually met.
That matters because of accountability. GDPR Article 5, paragraph 2 does not simply require you to comply. It requires you to be able to demonstrate that you comply.
The compliance roadmap tracks the four stages every organisation moves through: describing your organisation, registering your systems (AI and regular), classifying their risk, and producing the documentation the law expects.
Urgent alerts sit above everything else, because two obligations here are hard legal deadlines. A personal data breach must reach your supervisory authority within seventy-two hours. A data subject request must be answered within one month.
Each framework you enable (the AI Act, GDPR, DORA and the rest) generates its own obligations. Enable only the regimes you are actually subject to.
The Executive Summary and the posture trend beneath it are built for reporting upward: overall compliance, readiness by framework, and how that trend is moving, without opening a single obligation.
Priority Actions and Gap Analysis rank what actually needs attention next, so the question is never just what is missing, but what to do about it first.
Start by registering your systems, AI and otherwise. The inventory covers both regular and AI systems, and nothing else can be assessed, documented or evidenced until it exists.
Why this is required
Both regimes this platform covers are built on the same principle: it is not enough to comply, you must be able to demonstrate that you comply. GDPR Article 5(2) states that duty explicitly and calls it accountability. The EU AI Act expresses the same idea through its documentation, logging and record-keeping obligations.
The practical consequence is that compliance is an evidence-production problem. A regulator's question is rarely 'did you think about bias'; it is 'show me what you did, when you did it, and who signed it off'. An organisation that did the right thing but cannot prove it is, in enforcement terms, in much the same position as one that did not.
This is also why the order matters. You cannot classify a system's risk before the system is registered; you cannot generate Annex IV technical documentation before the classification exists; and you cannot evidence a control before there is a checklist item to attach it to.
What EuroCompliant does
The dashboard is the accountability view. The compliance roadmap tracks the four stages every organisation moves through (organisation profile, system registration, risk classification, documentation) and shows which one you are actually blocked on.
Urgent alerts are separated from everything else because two obligations in the platform are hard legal deadlines rather than good practice: the seventy-two hour breach clock and the one-month data subject request clock. Both count down in real time.
Pending tasks are drawn from the checklists generated for each registered system, so the dashboard reflects your actual obligation set rather than a generic list.
Deadlines
Walking through it
Complete your organisation profile
Your sector, size, jurisdictions and role (provider, deployer, or both) determine which obligations apply. The AI Act imposes materially different duties on providers and deployers, so this answer shapes everything downstream.
Open /settings/profile →Enable the frameworks that apply to you
Turn on the regimes you are actually subject to. Enabling a framework generates its checklist items and unlocks its document types; enabling everything produces noise rather than compliance.
Open /settings/profile?tab=frameworks →Register your systems
Add every AI system, and every conventional IT system that processes personal data. This is the inventory everything else attaches to.
Open /systems →Classify each system's risk
Run the assessment. The classification determines which obligations the system carries under the AI Act.
Open /compliance-docs →Work the generated checklists
Each classified system produces its obligation set. Complete items and attach evidence as you go.
Open /compliance-docs →Generate your documentation
With systems registered and assessed, the document generator has the data it needs to produce Annex IV technical documentation, records of processing and the rest.
Open /compliance-docs →The law
Accountability
The controller is responsible for, and must be able to demonstrate compliance with, the data protection principles.
Definition of an AI system
A machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions.
Obligations of providers
Providers must ensure compliance, operate a quality management system, keep documentation, undergo conformity assessment and register the system.
Obligations of deployers
Deployers must use systems per their instructions, assign competent human oversight, monitor operation and retain logs.
Frequently asked
Are we a provider or a deployer?
You are a provider if you develop an AI system, or have one developed, and place it on the market or into service under your own name or trademark. You are a deployer if you use an AI system under your own authority in a professional capacity. Many organisations are both: a deployer of purchased tools and a provider of anything they build. Note that substantially modifying a high-risk system, or putting your own branding on it, can make you a provider of it.
Does the AI Act apply to us if we are not in the EU?
Possibly. Article 2 extends the Act to providers placing systems on the EU market regardless of where they are established, and to providers and deployers outside the EU where the system's output is used within the EU.
Do we need to do all of this at once?
No, but the order is not negotiable. Register systems first, because the inventory is what every other obligation attaches to. Prohibited practices and AI literacy are already in force, so those are worth checking immediately.
Related guides
Registering your systems
Building the system inventory that every other obligation attaches to, covering both AI and conventional systems, and deciding correctly what counts as an AI system.
Risk classification
The Article 6 assessment that decides which obligations a system carries, and why the reasoning matters as much as the result.
AI literacy
Article 4 applies to nearly everyone deploying AI, it has been in force since February 2025, and it is the obligation most organisations discover last.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial