# Ai · AI-Act Readiness — element 49 of 58

> Europe has rules now. Turns regulatory confusion into a checklist.

- **Group:** 11 · Trust & Compliance
- **Necessity:** Optional
- **Price band:** $$ · $30–150/mo
- **Maturity:** Emerging
- **Edition:** v2026.Q3 · verified 2026-09-13

## Leading tools (v2026.Q3)

- **EU AI Act Checker** — the free readiness scan
- **Vanta — EU AI Act framework** — ai act in your grc
- **Credo AI** — enterprise governance leader
- **Holistic AI** — audits and risk testing
- **Trail** — eu-native, sme-friendly

## Our take

Deadlines moved (high-risk obligations pushed toward Dec 2027) but transparency duties keep landing. If you sell into the EU, know your tier.

## Combines with

Cm, Ev


## The top 5 — deep dossier (verified 2026-09-13)

Classify before you buy: the free EU AI Act Compliance Checker (Future of Life Institute) is the winner for the element's actual job — a 10-minute readiness scan that tells you whether you're a provider or deployer and which tier you land in, on the site 150k people a month already use. Most AI startups come out limited-risk, owing chatbot disclosure and content marking (Art 50) plus AI literacy — not a conformity assessment. Vanta wins once you want the checklist automated inside the compliance stack you already run for SOC 2/ISO 27001; Credo AI when enterprise procurement demands a governance platform with a Forrester-Leader logo; Holistic AI when you need risk testing and audit-grade verification (the canon's eval.qa-class audit); Trail when you want an EU-native, SME-priced platform with ISO 42001 built in. The Digital Omnibus (in force Jul 27, 2026) moved high-risk deadlines to Dec 2027/Aug 2028 — which makes classification cheap and panic-buying premature.

1. **EU AI Act Compliance Checker + AI Act Explorer** (Future of Life Institute (artificialintelligenceact.eu)) — Free. Best for: The first hour of AI-Act work: classify your system (prohibited / high-risk / limited / minimal), learn your role (provider vs deployer), and read the actual articles in a searchable explorer. Why: The de-facto standard readiness scan: an interactive questionnaire that maps your product to risk tier and obligations, on the most-used AI Act resource on the internet (150k+ users/month, Aug 2026). Sits beside a full-text Explorer, implementation timeline, small-business guide, and a practical Article 50 transparency guide (May 14, 2026). The European Commission's own AI Act Service Desk now offers an official checker — but FLI's remains the fastest and most battle-tested entry point. Watch: Not legal advice and not affiliated with the EU; checker last updated Jul 3, 2025, and the site's timeline page had not yet fully absorbed the Jul 2026 Digital Omnibus date changes when we checked (Aug 2026) — cross-check deadlines against the Commission's page. [https://artificialintelligenceact.eu/assessment/eu-ai-act-compliance-checker/](https://artificialintelligenceact.eu/assessment/eu-ai-act-compliance-checker/)
2. **Vanta — EU AI Act framework** (Vanta) — Quote-based · 4 tiers (Essentials / Plus / Professional / Enterprise), AI-Act framework as add-on. Best for: Startups already running Vanta for SOC 2/ISO 27001 that now need the AI Act turned into tracked controls, policies, and evidence — without a second GRC vendor. Why: Converts the regulation into 150+ controls and 16 policies with guided risk classification (provider vs deployer), post-market monitoring, and incident tracking, wired into 400+ integrations you've likely already connected. Cross-framework mapping reuses ISO 42001 / NIST AI RMF evidence — Vanta pegs the ISO 42001 overlap at roughly 50% of AI-Act requirements — so the marginal cost of adding the AI Act to an existing compliance program is the lowest in the field. Watch: No public pricing — everything is a sales conversation. A GRC checklist is not a legal determination: high-risk classification edge cases still need counsel. Depth of AI-specific risk testing trails the dedicated governance platforms (Credo, Holistic). [https://www.vanta.com/products/eu-ai-act](https://www.vanta.com/products/eu-ai-act)
3. **Credo AI** (Credo AI) — Enterprise quote-based. Best for: Scale-ups and enterprises that need a full AI governance platform — inventory, shadow-AI discovery, policy packs, audit-ready evidence — with the analyst validation procurement asks for. Why: The name-brand of AI governance: Leader in the Forrester Wave for AI Governance Solutions (Q3 2025), #6 in Applied AI on Fast Company's Most Innovative Companies 2026, with Mastercard, Autodesk, and Databricks as reference customers. Pre-built EU AI Act policy packs alongside NIST AI RMF and ISO 42001; one customer credits it with accelerating AI-Act compliance '10x'. Watch: Enterprise product at enterprise prices — overkill for a limited-risk seed-stage deployer. Its own framing stat (60% of enterprises scaling AI, 4% governing it) cuts both ways: the category's urgency is still ahead of its adoption. [https://www.credo.ai/](https://www.credo.ai/)
4. **Holistic AI** (Holistic AI) — Enterprise quote-based. Best for: Teams that need verification, not just tracking — 40+ risk tests (bias, safety, security, performance) mapped to AI-Act requirements, plus AI discovery across cloud and repos. Why: The closest thing to the canon's eval.qa-class audit as a product: automated control mapping and gap analysis for the EU AI Act with quantitative risk testing behind it, a lineage in independent bias audits (NYC Local Law 144), and top marks where it counts — #1 for the AI Risk and Compliance use case in Gartner's evaluation and a place in the inaugural Gartner Magic Quadrant for AI Governance Platforms (Jul 2026). Watch: Quote-only pricing and an enterprise sales motion; startup fit is limited. Gartner positioning is cited from the vendor's own announcement — the full MQ is paywalled. [https://www.holisticai.com/](https://www.holisticai.com/)
5. **Trail** (trail (Munich)) — Quote-based · SaaS (EU data centers) or on-prem. Best for: EU-based startups and Mittelstand teams that want an EU-native platform: AI registry, risk libraries, automated technical documentation, and ISO 42001 certification support. Why: Purpose-built for exactly this element by a German team: EU AI Act self-assessment checker, risk libraries mapped to project characteristics, auto-generated compliance documentation, and GRC agents that work inside Confluence/Jira/GitHub rather than replacing them. Proven in regulated European organizations — Deutsche Bahn, PwC, Sparda-Bank, Atruvia — with a claimed 4x faster AI deployment for governed projects. Watch: Small vendor next to OneTrust/Credo — diligence the roadmap; funding undisclosed. The 4x deployment claim is vendor-reported and unaudited. [https://www.trail-ml.com/](https://www.trail-ml.com/)

### How to choose
- If You just need to know your tier (and whether the panic applies to you at all) → Run the free FLI Compliance Checker, then confirm against the Commission's AI Act Service Desk. Most AI SaaS lands limited-risk: Art 50 disclosure + content marking + AI literacy, not a conformity assessment.
- If You already run Vanta (or any GRC tool) for SOC 2/ISO 27001 → Add the EU AI Act framework there — ISO 42001 evidence reuse (~50% overlap per Vanta) makes it the cheapest marginal path. Note Drata had no dedicated AI-Act framework as of Aug 2026, only ISO 42001.
- If You classify as high-risk (Annex III) or expect to → The deadline moved to Dec 2, 2027 (Omnibus, in force Jul 27, 2026) — but conformity assessment plus ISO 42001 realistically takes 12–18 months. Start the registry and technical documentation now on Trail, Credo, or Holistic; don't bank on a second deferral.
- If You train or heavily fine-tune general-purpose models → GPAI obligations have applied since Aug 2, 2025 and the Commission's fining powers (Art 101, up to 3% of global turnover) went live Aug 2, 2026 — the GPAI Code of Practice plus specialist counsel, not a checklist tool, is your path.
- If Enterprise buyers are sending AI-governance questionnaires before they'll sign → That's a sales problem wearing a compliance hat: Credo AI or Holistic AI for the platform + analyst logos, or an ISO 42001 certification via your GRC tool as the exportable proof.

### The field (17 more)

AI Act Service Desk, OneTrust AI Governance, Saidot, Naaia, Modulos, Trustible, Lumenova AI, Optro (ex-FairNow) (renamed), Fairly AI, anch.AI (renamed), Enzai (dead), IBM watsonx.governance, Vanta ISO 42001, Drata, AI Watch: Global Regulatory Tracker, IAPP AI Governance Center / AIGP, Covington Inside Privacy (AI)

Full dossier data: https://elems.ai/e/ai.json

---
Source: [elems.ai](https://elems.ai/e/ai.html) — the periodic table of the AI-led startup. Data: https://elems.ai/elements.json (CC BY 4.0, cite elems.ai).
