Vital signs
Why it's on the table
On the table, AI-Act Readiness (Ai) is seat 49 of 58, in the Trust & Compliance family. It is an emerging element — the job is real and here to stay, but the leaderboard still changes quarterly. Choose for this quarter, hold loosely, and watch the changelog. It is optional: plenty of companies run without it — until a specific trigger (scale, regulation, cost, or customers) makes it essential for them. It sits in the mid price band — a real line item that should earn its keep visibly.
AI-Act Readiness: the top 5 — v2026.Q3
Edition v2026.Q3 · ranking, pricing and status verified 2026-08-06.
1EU AI Act Compliance Checker + AI Act ExplorerFuture of Life Institute (artificialintelligenceact.eu)
FreeBest for The first hour of AI-Act work: classify your system (prohibited / high-risk / limited / minimal), learn your role (provider vs deployer), and read the actual articles in a searchable explorer.
The de-facto standard readiness scan: an interactive questionnaire that maps your product to risk tier and obligations, on the most-used AI Act resource on the internet (150k+ users/month, Aug 2026). Sits beside a full-text Explorer, implementation timeline, small-business guide, and a practical Article 50 transparency guide (May 14, 2026). The European Commission's own AI Act Service Desk now offers an official checker — but FLI's remains the fastest and most battle-tested entry point.
Watch Not legal advice and not affiliated with the EU; checker last updated Jul 3, 2025, and the site's timeline page had not yet fully absorbed the Jul 2026 Digital Omnibus date changes when we checked (Aug 2026) — cross-check deadlines against the Commission's page.
150k+ users/month on artificialintelligenceact.eu (site, Aug 2026) [src] · Checker updated Jul 3, 2025: GPAI systemic-risk questions, provider/deployer role logic [src] · Official alternative now live: Commission AI Act Service Desk with Explorer, Compliance Checker, and direct expert Q&A (2026) [src]2Vanta — EU AI Act frameworkVanta
Quote-based · 4 tiers (Essentials / Plus / Professional / Enterprise), AI-Act framework as add-onBest for Startups already running Vanta for SOC 2/ISO 27001 that now need the AI Act turned into tracked controls, policies, and evidence — without a second GRC vendor.
Converts the regulation into 150+ controls and 16 policies with guided risk classification (provider vs deployer), post-market monitoring, and incident tracking, wired into 400+ integrations you've likely already connected. Cross-framework mapping reuses ISO 42001 / NIST AI RMF evidence — Vanta pegs the ISO 42001 overlap at roughly 50% of AI-Act requirements — so the marginal cost of adding the AI Act to an existing compliance program is the lowest in the field.
Watch No public pricing — everything is a sales conversation. A GRC checklist is not a legal determination: high-risk classification edge cases still need counsel. Depth of AI-specific risk testing trails the dedicated governance platforms (Credo, Holistic).
150+ controls, 16 policies, adaptive risk-classification scoping (vendor page, Aug 2026) [src] · ISO 42001 covers ~50% of EU AI Act requirements — evidence reuse via framework mapping (vendor claim, Aug 2026) [src] · Vanta customers report ~50% faster audit completion; 400+ integrations (vendor claims, Aug 2026) [src]3Credo AICredo AI
Enterprise quote-basedBest for Scale-ups and enterprises that need a full AI governance platform — inventory, shadow-AI discovery, policy packs, audit-ready evidence — with the analyst validation procurement asks for.
The name-brand of AI governance: Leader in the Forrester Wave for AI Governance Solutions (Q3 2025), #6 in Applied AI on Fast Company's Most Innovative Companies 2026, with Mastercard, Autodesk, and Databricks as reference customers. Pre-built EU AI Act policy packs alongside NIST AI RMF and ISO 42001; one customer credits it with accelerating AI-Act compliance '10x'.
Watch Enterprise product at enterprise prices — overkill for a limited-risk seed-stage deployer. Its own framing stat (60% of enterprises scaling AI, 4% governing it) cuts both ways: the category's urgency is still ahead of its adoption.
4Holistic AIHolistic AI
Enterprise quote-basedBest for Teams that need verification, not just tracking — 40+ risk tests (bias, safety, security, performance) mapped to AI-Act requirements, plus AI discovery across cloud and repos.
The closest thing to the canon's eval.qa-class audit as a product: automated control mapping and gap analysis for the EU AI Act with quantitative risk testing behind it, a lineage in independent bias audits (NYC Local Law 144), and top marks where it counts — #1 for the AI Risk and Compliance use case in Gartner's evaluation and a place in the inaugural Gartner Magic Quadrant for AI Governance Platforms (Jul 2026).
Watch Quote-only pricing and an enterprise sales motion; startup fit is limited. Gartner positioning is cited from the vendor's own announcement — the full MQ is paywalled.
5Trailtrail (Munich)
Quote-based · SaaS (EU data centers) or on-premBest for EU-based startups and Mittelstand teams that want an EU-native platform: AI registry, risk libraries, automated technical documentation, and ISO 42001 certification support.
Purpose-built for exactly this element by a German team: EU AI Act self-assessment checker, risk libraries mapped to project characteristics, auto-generated compliance documentation, and GRC agents that work inside Confluence/Jira/GitHub rather than replacing them. Proven in regulated European organizations — Deutsche Bahn, PwC, Sparda-Bank, Atruvia — with a claimed 4x faster AI deployment for governed projects.
Watch Small vendor next to OneTrust/Credo — diligence the roadmap; funding undisclosed. The 4x deployment claim is vendor-reported and unaudited.
AI-Act Readiness: the top 8 compared
Edition v2026.Q3 · ranking, pricing and status verified 2026-08-06.
| Tool | What it is | Risk classification | Full framework + evidence | ISO 42001 crosswalk | Pricing | Best size | Analyst recognition |
|---|---|---|---|---|---|---|---|
| FLI Compliance Checker | Free questionnaire + full-text explorer | Yes (10 min) | No | No | Free | Anyone | 150k users/mo (de-facto standard) |
| Vanta (EU AI Act) | GRC module in compliance platform | Yes (adaptive scoping) | Yes — 150+ controls, 16 policies | Yes (~50% overlap reuse) | Quote | Startup → mid-market | — |
| Credo AI | AI governance platform | Yes | Yes — policy packs | Yes | Quote | Enterprise | Forrester Wave Leader Q3 2025 |
| Holistic AI | Governance + risk testing platform | Yes | Yes + 40+ risk tests | Yes | Quote | Enterprise | Gartner MQ 2026; #1 risk/compliance use case |
| Trail | EU-native governance platform | Yes (self-assessment) | Yes — auto documentation | Yes (cert support) | Quote | SME / startup | — |
| OneTrust AI Governance | Governance module of privacy suite | Yes (auto risk tiering) | Yes — templates + runtime guardrails | Yes | Quote | Enterprise | Gartner MQ 2026 Visionary |
| Saidot | Governance knowledge-graph platform | Yes (AI Act Classifier) | Yes — 620+ controls, API-first | Yes | Quote | Mid → enterprise | Gartner MQ 2026 |
| Modulos | ISO-42001-certified governance platform | Yes | Yes — 894 controls / 21 frameworks | Yes (certified itself) | Quote | Mid-market | Gartner MQ 2026 |
How to choose your ai-act readiness
- If you just need to know your tier (and whether the panic applies to you at all)
- Run the free FLI Compliance Checker, then confirm against the Commission's AI Act Service Desk. Most AI SaaS lands limited-risk: Art 50 disclosure + content marking + AI literacy, not a conformity assessment.
- If you already run Vanta (or any GRC tool) for SOC 2/ISO 27001
- Add the EU AI Act framework there — ISO 42001 evidence reuse (~50% overlap per Vanta) makes it the cheapest marginal path. Note Drata had no dedicated AI-Act framework as of Aug 2026, only ISO 42001.
- If you classify as high-risk (Annex III) or expect to
- The deadline moved to Dec 2, 2027 (Omnibus, in force Jul 27, 2026) — but conformity assessment plus ISO 42001 realistically takes 12–18 months. Start the registry and technical documentation now on Trail, Credo, or Holistic; don't bank on a second deferral.
- If you train or heavily fine-tune general-purpose models
- GPAI obligations have applied since Aug 2, 2025 and the Commission's fining powers (Art 101, up to 3% of global turnover) went live Aug 2, 2026 — the GPAI Code of Practice plus specialist counsel, not a checklist tool, is your path.
- If enterprise buyers are sending AI-governance questionnaires before they'll sign
- That's a sales problem wearing a compliance hat: Credo AI or Holistic AI for the platform + analyst logos, or an ISO 42001 certification via your GRC tool as the exportable proof.
AI-Act Readiness: the whole field
17 more tools tracked in this category, including 3 dead, renamed, or sunsetting — a reference that hides the graveyard isn't one. Verified 2026-08-06.
| Tool | Maker | What it is | Entry | Status |
|---|---|---|---|---|
| AI Act Service Desk | European Commission | The official answer: AI Act Explorer, Compliance Checker, and direct multilingual Q&A with AI Office-backed staff — the authoritative readiness scan, free | free | active |
| OneTrust AI Governance | OneTrust | AI governance module on the privacy-suite installed base; EU AI Act templates + runtime guardrails; Visionary in the inaugural Gartner MQ (2026) | quote | active |
| Saidot | Saidot (Helsinki) | Governance knowledge graph (260+ risks, 620+ controls, 110+ policies), EU AI Act Classifier, MCP-based agentic workflows; Gartner MQ 2026 | quote | active |
| Naaia | Naaia (Paris) | Europe's first ISO 42001-built AI management system; €6M Series A (2026); Bouygues, Idemia, Île-de-France region | quote | active |
| Modulos | Modulos (Zurich) | ISO 42001-certified platform mapping 894 controls across 21 frameworks (48% serve 2+); EU AI Pact signatory; Gartner MQ 2026 | quote | active |
| Trustible | Trustible | AI governance for regulated enterprises — intake/triage, EU AI Act + NIST + ISO 42001 mapping; Leidos, Molson Coors, Kroll | quote | active |
| Lumenova AI | Lumenova | Governance + evals + guardrails hybrid with EU AI Act mapping — overlaps elements Ev and Gd | quote | active |
| Optro (ex-FairNow) | Optro | fairnow.ai now redirects to optro.ai (Aug 2026); 25+ frameworks incl. EU AI Act and ISO 42001, claims 50%+ of Fortune 500 | quote | renamed |
| Fairly AI | Fairly AI | AI readiness planner + expert-led validation engine; EU-AI-Act positioning thin on current site — verify fit before shortlisting | quote | active |
| anch.AI | anch.AI (Stockholm) | Ethical-AI screening pioneer (methodology since 2016, ~200 use cases assessed); site live but undated — momentum unclear in 2026 | quote | fading |
| Enzai | Enzai (Belfast) | Early AI-governance startup; enzai.co no longer resolves (Aug 2026) — presumed wound down or absorbed; re-verify before citing | — | dead |
| IBM watsonx.governance | IBM | Incumbent enterprise AI governance with EU AI Act accelerators; the default inside IBM-standard shops — not startup-shaped (not independently re-verified this cycle) | SaaS per-model/usage | active |
| Vanta ISO 42001 | Vanta | The certification route: ISO 42001 as exportable AI-governance proof, ~50% overlapping AI-Act requirements per Vanta's mapping | quote | active |
| Drata | Drata | Supports ISO 42001 and AI-agent governance, but no dedicated EU AI Act framework page found (Aug 2026) — general compliance automation belongs to element Cm | quote | active |
| AI Watch: Global Regulatory Tracker | White & Case | Free law-firm navigator covering 38+ jurisdictions — the multi-jurisdiction context layer around the AI Act | free | active |
| IAPP AI Governance Center / AIGP | IAPP | The people-side of readiness: AIGP certification for AI-governance professionals + conference/resource hub | exam + training fees | active |
| Covington Inside Privacy (AI) | Covington & Burling | Free, fast law-firm analysis — their May 18, 2026 Omnibus breakdown is the clearest public account of the final amendments | free | active |
AI-Act Readiness: the category in numbers
Edition v2026.Q3 · ranking, pricing and status verified 2026-08-06.
- Digital Omnibus AI amendments in force Jul 27, 2026: Annex III high-risk deferred Aug 2026 → Dec 2, 2027; Annex I embedded high-risk Aug 2027 → Aug 2, 2028; Art 50(2) marking for existing systems → Dec 2, 2026 (new systems comply at market entry); sandboxes → Aug 2027 [src]
- Aug 2, 2026 still matters: general application date, national enforcement live, and Commission GPAI fining powers (Art 101, up to 3% global turnover) begin — GPAI obligations themselves applied Aug 2, 2025 (Art 113) [src]
- AI governance software market: $0.89B (2024) → $5.78B (2029), 45.3% CAGR (MarketsandMarkets) [src]
- Category institutionalized: first-ever Gartner Magic Quadrant for AI Governance Platforms published Jul 2026 (Holistic AI, OneTrust, Saidot, Modulos all announce placement) [src]
- New prohibition from Dec 2, 2026: AI systems for non-consensual intimate imagery / CSAM added to Art 5 by the Omnibus; Art 25 breaches now fined up to 3% / €15M [src]
- Governance gap persists: 60% of enterprises scaling AI, only ~4% actively governing it (Credo AI, 2026); OneTrust reports AI-risk workload up 37% YoY (2025) [src]
AI-Act Readiness: method & sources
Timeline conflict resolved: artificialintelligenceact.eu's timeline page had not fully absorbed the Digital Omnibus when checked (Aug 2026); we follow the European Commission's regulatory-framework page (Omnibus political agreement May 7, 2026; in force Jul 27, 2026) corroborated by Covington's May 18, 2026 analysis. Gartner MQ positions are cited from vendor announcements — the full MQ is paywalled; treat exact placements as vendor-reported. Drata: repeated 404s on any dedicated EU-AI-Act framework page (Aug 2026); it supports ISO 42001, so it stays a Cm-element tool here. Canon mapping: 'readiness scan' = FLI/Commission checkers (rank 1); 'eval.qa-class audit' = external verification, closest products Holistic AI (rank 4) and ISO 42001 certification via GRC platforms. Adjacent elements: general compliance automation (SOC 2, ISO 27001) → Cm; runtime safety filters → Gd · Guardrails; model testing/monitoring → Ev · Evals & Observability; bespoke legal advice → Lg · Legal. Most vendor stats in this thin category are single-source vendor claims (Vanta's 50% ISO-42001 overlap, Trail's 4x, Trustible's 10x intake) — flagged as such in entries. Pricing is quote-based across every commercial vendor; no public price list existed anywhere in this category as of Aug 2026. Ranking criteria: verified commercial traction, independent satisfaction surveys, agent benchmarks, and founder-fit (price floor, lock-in, surfaces). Editorial, never paid — the charter. Machine-readable twin: ai.json.
All sources (20)
- https://www.insideprivacy.com/artificial-intelligence/eu-ai-act-update-timeline-relief-targeted-simplification-and-new-prohibitions/
- https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- https://artificialintelligenceact.eu/article/113/
- https://artificialintelligenceact.eu/assessment/eu-ai-act-compliance-checker/
- https://artificialintelligenceact.eu/
- https://ai-act-service-desk.ec.europa.eu/en
- https://digital-strategy.ec.europa.eu/en/policies/ai-office
- https://www.vanta.com/products/eu-ai-act
- https://www.credo.ai/
- https://www.holisticai.com/
- https://www.trail-ml.com/
- https://www.saidot.ai/
- https://naaia.ai/
- https://www.modulos.ai/
- https://www.onetrust.com/products/ai-governance/
- https://www.trustible.ai/
- https://www.whitecase.com/insight-our-thinking/ai-watch-global-regulatory-tracker
- https://iapp.org/certify/aigp/
- https://www.marketsandmarkets.com/Market-Reports/ai-governance-market-176187291.html
- https://optro.ai/product/ai-governance
Our take
Deadlines moved (high-risk obligations pushed toward Dec 2027) but transparency duties keep landing. If you sell into the EU, know your tier.
Combines with
Appears in compounds
This is element 49 of 58. The table is versioned quarterly — when a tool loses its seat, the changelog records the succession.
Explore the full table →