For DPOs & Compliance

Your AI register, ready for the regulator. Not in six months — now.

Map the Shadow AI you cannot see, classify your high-risk systems (Annex III) and produce verifiable evidence. One leak is enough to put the organisation on the hook.

No account · No card · Instant result

What keeps you up at night, handled

Real visibility on Shadow AI — the tools in use without approval, mapped.
Guided AI Act classification: Annex III triage, documentation, official register.
Verifiable Evidence Pack, signed and timestamped — the file a regulator can read as-is.
  • Official AI Act register
  • Verifiable exports
  • EU hosting
  • Per-organisation isolation

What you must be able to show

An inspection never opens with “are you compliant?” — it opens with “show me”. These are the pieces the platform keeps current on your behalf.

  • The AI system register: purpose, provider, data processed, owner.
  • The AI Act classification of each system, with the reasoning documented.
  • The link between each AI system and its GDPR processing, its DPIA and its evidence.
  • Proof the review actually happened: timestamped, versioned history.
  • Undeclared usage detected, and the decision taken on each one.
  • An exportable Evidence Pack — handed over as-is rather than reconstructed.

Ce qu’on nous oppose

« We already keep a GDPR register. We will just add an “AI” column. »

It is the most common reflex, and it breaks at the first substantive question. An Article 30 register describes processing activities; the AI Act asks about systems — their purpose, their risk classification, human oversight, and disclosure to people (Art. 50). The two frameworks do not overlap: a single HR process can carry three AI systems with three different classifications. We import your existing register as a starting point, then complete it on the fields the AI Act adds.

« Detecting what staff use is one more processing activity to justify. »

Detection reads no prompts, no responses and no files: it sees domain names and timestamps. It remains a processing activity and it belongs in your register — we provide the record sheet to do so, along with the exhaustive list of data read, written to be annexed to your documentation.

« Nothing formally requires me to keep a register of AI systems. »

Correct: no single article mandates one under that name. But the documentation duties (Art. 12), deployer obligations (Art. 26) and transparency requirements (Art. 50) all assume you know which systems you operate. In practice it is the first item requested in an inspection — and the one that takes longest to reconstruct after the fact.

À emporter

AI usage register checklist

The fields to fill, system by system, for a register that holds up in front of an auditor. Usable in your current tooling, including without us.

Ouvrir la checklist

Conçu pour les organisations qui veulent garder la maîtrise de leur IA

Sécurité

  • Données hébergées en UE, chiffrées, isolées par organisation.
  • MFA, RBAC par rôle, journal d’audit complet.

Conformité

  • Conçu pour le cadre RGPD et l’EU AI Act.
  • Evidence Pack, briefs signés, exports vérifiables.

Contrôle

  • Vous gardez la maîtrise de vos données et de vos accès.
  • Aucune installation pour la démo, sans engagement.
Ne stocke pas vos contenus sensiblesExtension : noms de domaine uniquement, jamais vos promptsAucun transfert de données métier hors UE

On inspection day, you print the file. You do not rebuild it.

The demo is open, no account required: you will see a real register, its AI Act classification and a complete Evidence Pack.