The short answer
- •Last verified 4 August 2026. Every claim below is drawn from vendor-published documentation, pricing pages, trust centres and company registries as they stood on that date. Where a vendor does not publicly document a capability, this guide says "not publicly documented" rather than asserting the capability is absent.
- •Disclosure: Veritome publishes this comparison and sells one of the products in it. Veritome is assessed against the same criteria as every other vendor, including corporate disclosure, certifications and weaknesses. Where a competitor is a better fit, this guide says so and names it.
There is no single best EU AI Act compliance tool, because the category splits into four groups that solve genuinely different problems.
Enterprise GRC and compliance-automation suites — OneTrust, TrustArc, IBM watsonx.governance, Vanta — treat the AI Act as one framework inside a large privacy, security or model-risk product. Right if you already own the suite. Expensive and oversized if you do not.
AI governance platforms — Credo AI, Holistic AI, Saidot, Modulos, trail — govern the AI lifecycle itself: registries, risk libraries, control mapping, model monitoring. Right if you have a portfolio of models and an ML function to run them.
Runtime control planes — Kosmoy — enforce policy at the moment of inference. A different job entirely, and complementary rather than competing.
AI-Act-native SME tools — Veritome, Legalithm — start from the regulation's text and produce the documents it names, at prices a company without a compliance department can pay.
If you are an EU SME that has to classify a handful of AI systems and produce a technical file, the last group is where to look, and you should evaluate both products in it. If you are a bank governing 400 models, look at the second group. The groups are not substitutes.
What the Act actually requires you to produce
Most comparison guides rank tools on features. Documents are the better axis, because the Act does not ask you for features — it asks you for artefacts, and this is where the market's real gap sits. A provider or deployer of a high-risk AI system must be able to hand a market surveillance authority:
- Annex IV technical documentation (Art. 11) — the technical file, nine prescribed sections. SMEs including start-ups, and now medium-sized companies and small mid-caps, may supply this in a simplified form under Art. 11(1) as extended by Regulation (EU) 2026/1744, with the Commission required to establish a template that notified bodies must accept.
- A fundamental rights impact assessment (Art. 27, FRIA) — for public-law deployers, private entities providing public services, and deployers of certain Annex III systems.
- An EU Declaration of Conformity (Art. 47, Annex V).
- An Annex VIII registration record for the EU database (Art. 49).
- Article 50 transparency disclosures — for AI interacting with people, generating synthetic content, deepfakes, and biometric or emotion recognition.
A caveat on this framing, since we are not a neutral party: this axis favours document-generation tools, which includes ours. If your live obligation is Article 50 transparency rather than a high-risk technical file, or if your real problem is drift and bias across a model portfolio, weight the monitoring capabilities accordingly — and read the "what nobody does well yet" section before you decide.
The timeline, as of 4 August 2026
The Digital Omnibus on AI is now law: Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026 (EUR-Lex, Hunton).
| Obligation | Applies from |
|---|---|
| Prohibited practices (Art. 5) | In force since 2 February 2025 |
| AI literacy (Art. 4) | In force since 2 February 2025; recalibrated by Reg. 2026/1744 from 27 July 2026 |
| GPAI model obligations | In force since 2 August 2025 |
| Article 50 transparency | 2 August 2026 — not deferred, now live. Art. 50(2) machine-readable marking of synthetic content has a transitional window to 2 December 2026 for generative systems placed on the market before 2 August 2026 |
| New Art. 5 prohibitions — non-consensual intimate imagery, CSAM generation | 2 December 2026 |
| Annex III high-risk (standalone) | Deferred to 2 December 2027 |
| Annex I high-risk (embedded in products) | Deferred to 2 August 2028 |
The deferral is the single most important planning fact in this guide. It does not apply to Article 50, which became applicable on 2 August 2026 — two days before this guide was published. If you deploy a chatbot, a synthetic-media generator, a deepfake tool or an emotion-recognition system, your transparency obligations are live now, not in 2027. Penalties under Art. 99(4) reach €15 million or 3% of worldwide annual turnover.
At a glance
The first table is the one that matters: which tools produce the documents the Act names. The second covers where each vendor sits and what it costs.
| Tool | Annex IV | FRIA (Art. 27) | DoC (Art. 47) | Registration (Art. 49) | Art. 50 tooling |
|---|---|---|---|---|---|
| Veritome | Yes | Yes | Yes | Export | Yes — notice generator |
| Legalithm | Yes, free tool | No | No | No | Yes — via MCP/CLI |
| Modulos | Art. 11 claimed | Art. 27 claimed | Not documented | Art. 49 claimed | Not assessed |
| trail | Not named | Not documented | Not documented | Not documented | Not assessed |
| Saidot | ISO 42001-based | Not documented | Not documented | Not documented | Transparency reports |
| Holistic AI | Assesses, not generates | Not documented | Not documented | Not documented | Not assessed |
| Credo AI | Not documented | Not documented | Not documented | Not documented | Not assessed |
| Kosmoy | Dossier claimed | Explicitly none | Not documented | Not documented | Not assessed |
| IBM watsonx.governance | Not documented | Not documented | Not documented | Not documented | Not assessed |
| Vanta | Not documented | Not documented | Not documented | Not documented | Not assessed |
| OneTrust | Not documented | Not documented | Not documented | Not documented | Not assessed |
| TrustArc | Not documented | Not documented | Not documented | Not documented | Not assessed |
| Tool | HQ | AI-Act-native? | Published price |
|---|---|---|---|
| Veritome | EU | Yes | Yes, €0–699/mo |
| Legalithm | EU (sole operator) | Yes | Yes, €0–199/mo |
| Modulos | Switzerland | Partly | No |
| trail | Germany | Partly | No |
| Saidot | Finland | Partly | No |
| Holistic AI | United Kingdom | Partly | No |
| Credo AI | United States | Partly | No |
| Kosmoy | Italy | Runtime | No |
| IBM watsonx.governance | United States | No | Yes, USD 795+ |
| Vanta | United States | No | No |
| OneTrust | United States | No | No |
| TrustArc | United States | No | No |
Ask every vendor directly, and ask for a sample output rather than a demo.
The AI-Act-native tools
Legalithm
What it is. A self-serve EU AI Act compliance layer aimed explicitly at EU start-ups and SMEs who want to get correctly scoped and documented without a five-figure contract (source).
What it produces. A free, no-signup risk classification wizard returning a four-tier result with article citations (tool), and a free, live Annex IV generator that outputs all nine prescribed sections as a PDF (tool). Its own FAQ correctly caveats this as a starter document rather than a complete conformity assessment output, requiring validation with qualified counsel.
Genuinely differentiated. Legalithm is the only vendor in this guide shipping developer-native distribution: an npx legalithm CLI across eight language ecosystems, an MCP server that runs offline inside Cursor and Claude Code, and a GitHub Action that fails the build on risk drift (source). If compliance needs to live in your CI pipeline rather than in a compliance officer's browser, nothing else here does this. Its MCP tooling also generates Article 50 disclosures — relevant given that obligation is live now.
Pricing. Free tier at €0. List prices €29 / €79 / €199 per month, currently discounted to €17 / €47 / €119 as founding-member rates at 40% off for year one (pricing). Paid billing has not yet activated.
Weaknesses. It is roughly five months old and self-describes as an MVP launch, founder-led. No disclosed funding, no customer logos, no case studies, and no third-party press coverage found. Its imprint names an individual operator and a contact email but no company registration number, registered address or VAT number (imprint) — consistent with a sole-operator business rather than a registered company. If vendor continuity or a corporate counterparty matters to you, ask about the contracting entity. A meaningful share of paid-tier features are marked "roadmap" or "at paid rollout". No FRIA, no standalone Art. 47 Declaration of Conformity, no Annex VIII registration export. No SOC 2 or ISO certification claimed. Core storage is EU-hosted and its privacy policy openly discloses transfers to the United States for AI inference and email delivery under standard contractual clauses with zero-retention terms (sub-processors) — relevant if EU-only processing is a hard requirement for you.
Choose it if you are a developer-led team that wants compliance checks in CI, you want a free Annex IV starting point today, and you can accept vendor-continuity risk on a five-month-old sole-operator business.
Veritome
What it is. Our product. An EU AI Act compliance toolkit for European SMEs, structured around a six-phase journey — classify, scope, implement, assess, register, monitor — with an assistant (Aria) that maps obligations article by article.
What it produces. Annex IV technical files, FRIAs and Declarations of Conformity, hash-sealed with public verify URLs, plus Annex VIII registration exports and an Article 50 notice generator. A sample dossier shows the actual output before you sign up, which is the check you should apply to every vendor in this guide.
Pricing. Free tier (1 AI system). Starter €59, Core €149, Growth €349 and Business €699 per month, or €49 / €119 / €279 / €559 billed annually (pricing). All plans include EEA data residency, with customer-facing AI running on Mistral hosted in Paris.
Corporate disclosure, on the same terms we applied to everyone else.
- Operated by Relay Labs Limited, registered in Dublin, Ireland, company number 807438.
- Founded 30.01.2026. Bootstrapped, solo founder, team of one.
- Certifications held: none.
- Sub-processors published at veritome.eu/sub-processors.
- No paying customers. Currently in pre-public beta, scoping design partners.
- Third-party press coverage: none to date.
Weaknesses, stated plainly. Veritome is a young company and a small team; if you need a vendor with a decade of audit history and a Big Four implementation channel, buy Modulos or an enterprise suite instead. It holds no ISO/IEC 42001 certification, which trail holds and Modulos holds at product level. It does not do model monitoring, bias testing or runtime enforcement — if your problem is drift detection across a live model portfolio, Holistic AI, Modulos or Kosmoy solve a problem Veritome does not attempt. Document generation is only as good as the inputs you give it; nothing here removes the need for legal review before you sign a Declaration of Conformity. System-count limits on lower tiers mean an organisation with more than 25 AI systems will land on the Business plan or need a conversation. And we have no independent analyst coverage — Veritome does not appear in the June 2026 Gartner Magic Quadrant, unlike IBM, Credo AI, OneTrust, Holistic AI and Saidot.
Choose it if you are an EU SME or mid-market company that needs the Act's named documents produced and kept current, you want EU-only data processing, and you want to see the output before committing.
The AI governance platforms
trail (Germany)
Munich-based, founded 2023, "Made in Germany. Built for Enterprises" (source). Strong on GRC depth: AI asset registry, a 170+ risk library drawn from MIT, NIST, OWASP and BSI, control effectiveness tracking, agent runtime enforcement. Holds both ISO/IEC 27001 and ISO/IEC 42001 certification — the strongest certification posture of any small vendor here. Hosted on Google Cloud in Europe, with BYOC and on-premise options.
Its FAQ is candid that large, regulated enterprises developing their own AI systems typically gain the most value from it. Real logos: Deutsche Bahn, PwC, BearingPoint, Sparda-Bank. No published pricing. Claims documentation generation but does not name Annex IV anywhere in its public material. Announced a €1.45M pre-seed in July 2024 (tech.eu); no subsequent round was publicly announced as of 4 August 2026. Private companies are not obliged to announce funding — ask directly about runway if vendor continuity matters.
Choose it if you are a DACH enterprise wanting a certified German vendor and ISO 42001 alignment matters as much as the AI Act.
Saidot (Finland)
Helsinki-based, EU-headquartered, ISO/IEC 27001 certified, with personal data processed within the EU/EEA. Built around a knowledge graph — connect your AI systems, models and agents, and let risks and controls inherit automatically (source) — with a library of 110+ policies, 260+ risks and 620+ controls, an EU AI Act classifier, transparency report generation, and roughly 95% of the platform exposed through a REST API. Gartner placed it as a Niche Player in the June 2026 AI Governance Platforms Magic Quadrant, characterised as EU-hosted and EU-focused.
The important caveat: its documentation standard is explicitly "adapted based on ISO/IEC 42001:2023" (help centre), not Annex IV-structured. A high-risk provider needing a technical file may not get it out of the box. Its pricing page publishes no tiers or numbers.
Choose it if you want a genuinely EU-headquartered platform, you have an inventory worth graphing, and ISO 42001 is your primary framework with the AI Act layered on.
Modulos (Switzerland)
ETH Zürich spin-off, Zurich-based. The most article-level-specific EU AI Act coverage in this guide: Art. 9 risk management with Monte Carlo simulation, Art. 10 data governance, Art. 11 technical documentation auto-generated with agents that find evidence in your repositories, Art. 13 transparency, Art. 14 human oversight, Art. 17 QMS, Art. 27 fundamental rights impact assessment, and Art. 49 EU database registration (source). It states 140+ controls mapped to the EU AI Act, ISO 42001 and the NIST AI RMF. On the artefact axis this is the broadest claimed coverage of any non-SME-native platform here — as with all of these, ask for sample output.
Modulos holds a CertX product conformity certificate (213-001/24) against ISO/IEC 42001:2023 — a product conformity attestation rather than an organisational management-system certification. Its live pricing page still describes a legacy AutoML product, which is a maintenance signal. Third-party directories list CHF 15,000 as a starting price but contradict each other on the unit; treat that as unverified. Delivery runs through SGS, CertX, PwC and KPMG partners, implying consulting-attached cost. Switzerland is outside the EU/EEA, though it holds an adequacy decision. The Art. 11 automation presupposes you have an engineering repository with harvestable artefacts, and its EU AI Act page does not name Annex IV directly.
Choose it if you are a regulated mid-to-large enterprise with an engineering estate, you want article-level mapping, and a certification-body channel is a feature rather than a cost.
Holistic AI (United Kingdom)
"The end-to-end AI governance platform trusted by global enterprises running AI at scale." Registered in London (Companies House). Gartner Challenger in the June 2026 Magic Quadrant, strongest on discovery and registry: 40+ specialised tests, agentic red teaming, shadow-AI discovery, and EU AI Act classification into prohibited / high-risk / low-minimal with a readiness score.
Note the verb on its conformity assessment page: it will "assess and assure" the technical documentation of your high-risk AI systems (source) — reviewing documentation you already have, not generating it. Its pricing page and security page both returned HTTP 404 when checked on 4 August 2026, and no trust centre was locatable at that date, so hosting and data residency are undisclosed. Substantial non-EU regulatory surface as well (NYC Local Law 144 bias audits).
Choose it if testing and red-teaming your models matters more than producing legal artefacts, and you are large enough to run an enterprise sales cycle.
Credo AI (United States)
Palo Alto, founded 2020, around 51 employees. Gartner Visionary in the June 2026 Magic Quadrant. Pre-built EU AI Act policy packs, AI registry, shadow-AI discovery, agent governance. Its policy packs are credible enough that IBM licenses them into watsonx.governance as a paid Compliance Accelerators add-on — a meaningful third-party validation.
Its EU AI Act page lists drafting the Declaration of Conformity, affixing CE marking and registering in the EU database as obligations you have, not as things Credo AI does — read that page carefully. Its pricing page returned HTTP 404 when checked on 4 August 2026; there is no published price and no self-serve. Its trust centre confirms only SOC 2 Type II, with no ISO 27001, no ISO 42001 and no stated EU data residency (trust centre) — a material gap if you are running a GDPR transfer assessment alongside AI Act work.
Choose it if you are a US-headquartered enterprise governing AI globally with the EU as one jurisdiction among several.
The runtime control plane
Kosmoy (Italy)
Milan-registered, with Banca d'Italia and Leonardo as named reference customers. A genuinely different product: an AI gateway acting as a policy enforcement point for LLM, MCP and agent-to-agent calls, plus guardrails, RBAC, routing, logging and a Kubernetes sandbox with just-in-time credentials and a kill switch. Automated EU AI Act risk classification sits in its registry, and it exports evidence bundles from the gateway event stream.
Refreshingly explicit about what it is not: "It is not a legal-workflow suite: no FRIA templates, no questionnaire engine, no regulator-report designer" (source). Pricing states "no tiers, no self-serve". Requires Kubernetes. Its DPA permits processing in any country in which Kosmoy, its subsidiaries and sub-processors maintain facilities, so there is no EU-residency guarantee from the vendor — the mitigation is self-hosting.
Choose it if you must prove controls operate at runtime, you have a platform engineering team, and you will pair it with a documentation tool rather than replace one.
The enterprise suites
IBM watsonx.governance
The only vendor here publishing real numbers. The GRC console — where the EU AI Act Applicability Assessment questionnaire lives — starts at USD 795 per instance plus USD 2,650 per solution plus USD 53 per concurrent user; the packaged AWS Marketplace bundle is USD 38,160 per year (pricing). Model evaluation is metered separately at USD 0.64 per evaluation. EU AI Act regulatory content requires a third purchase: the Compliance Accelerators add-on, which ships Credo AI's policy packs. Gartner Leader, June 2026. Provisionable in Frankfurt and London.
Three separate meters to get regulatory coverage, and no Annex IV, FRIA, DoC or Annex VIII output documented anywhere in IBM's material.
Vanta
Vanta's own homepage defines the company as SOC 2, HIPAA, ISO 27001, PCI and GDPR automation. EU AI Act is a framework added to that platform (product page), launched October 2024, delivering "all AI-specific controls, policies, tests and documents mandated by the act". Output is controls and evidence, not regulatory artefacts. EU data centre in Frankfurt on AWS, European HQ in Dublin.
Pricing is quote-only, but third-party transaction data puts the observed median at USD 20,000 per year, with the lowest band for a 1–50-employee company on a single framework at USD 12,000–28,000 (Vendr). Pricing scales per framework, so adding the AI Act to an existing SOC 2 subscription is an incremental cost.
Choose it if you already run Vanta for SOC 2 or ISO 27001 and want AI Act controls in the same place. Do not buy Vanta for the AI Act alone.
OneTrust
"The AI-Ready Governance Platform." Atlanta-headquartered, trusted by over half the Fortune 500. Gartner Visionary in the June 2026 Magic Quadrant. The AI Act is delivered as templates within the AI Governance product: a system registry covering models, agents, datasets and third-party AI, continuously evaluated risk records, incident routing, and automatic documentation of decisions and corrective actions. Metered on admin users and AI inventory, quote-only; Vendr's observed median across all OneTrust products is USD 11,970 per year, though that dataset is dominated by privacy and consent purchases and is a poor proxy for the AI module. Hosting regions are not disclosed on its trust centre.
TrustArc
Walnut Creek, California. No dedicated AI Act module — the capability is assembled from existing privacy components: Nymity Research, Assessment Manager, Data Inventory Hub, PrivacyCentral. Its flagship AI deliverable is a Responsible AI Certification, a TRUSTe seal and Letter of Attestation whose criteria incorporate the Act's core obligations on transparency, human oversight and data governance. Read that carefully: it confers no presumption of conformity under Articles 40–42 and is not a conformity assessment under Article 43, and TrustArc does not position it as one. Its trust centre describes hosting only as a world-class enterprise-grade cloud data hosting provider, with no region or provider named — the weakest hosting transparency in this guide. Vendr observed median USD 15,120 per year across 47 purchases.
What nobody does well yet
Being straight about the state of the category, including where our own product has room.
FRIA is thinly served — and the regulator is about to help. Article 27 assessments are a documented feature at few vendors; Modulos claims Art. 27 coverage, Kosmoy explicitly disclaims it, and most others discuss FRIA in content marketing without shipping functionality. Reg. 2026/1744 amended Art. 27(4) to let a FRIA cross-reference or incorporate parts of an existing DPIA, and Art. 27(5) now requires the AI Office to develop a questionnaire template "including through an automated tool". A free regulator-supplied tool may narrow the gap this section describes — including for our own product. Factor that into what you pay for.
Annex VIII registration is thinly served, and just got simpler. Reg. 2026/1744 deleted points 7 and 9 from Annex VIII Section B, reducing the information required for systems assessed as non-high-risk under Art. 6(3). Registration remains mandatory; the burden is lower than it was.
"Technical documentation" is doing a lot of work in vendor copy. Several platforms claim documentation generation; only a handful name Annex IV; almost none show you the output. Ask every vendor on your shortlist for a sample technical file before you buy. If they cannot produce one, they generate evidence, not documents.
Certification is thin. trail holds ISO/IEC 42001 and ISO/IEC 27001; Modulos holds a CertX product conformity certificate against ISO/IEC 42001:2023; Saidot holds ISO/IEC 27001; Credo AI holds SOC 2 Type II. Most vendors in the SME tier, ours included, hold nothing.
Article 50 is the live obligation and the least-covered axis in this market. It applied from 2 August 2026 while the high-risk machinery everyone markets against is deferred to December 2027. We have not yet systematically assessed Art. 50 tooling across all twelve vendors — that is a gap in this guide, and we will close it in the next edition.
Nobody's classification is legal advice. Every risk classifier here, ours included, is an indicative tool. The Act's Annex III categories involve judgement calls that a decision tree approximates rather than resolves.
How to choose, in four questions
Are you a provider or a deployer? Providers of high-risk systems need Annex IV, a Declaration of Conformity and registration. Deployers need a FRIA, human oversight records and Art. 26 duties. Most tools serve one better than the other. Ask which.
Does Article 50 apply to you right now? If you run a chatbot, generate synthetic content or deploy emotion recognition, your obligations became applicable on 2 August 2026 regardless of the high-risk deferral — with a marking transition to 2 December 2026 for generative systems already on the market. Solve this first.
Do you need documents or do you need monitoring? These are different products. Buying a model-monitoring platform to produce a technical file, or a documentation tool to catch drift, is the most common and most expensive mistake in this category.
Can you see the output before you buy? The single best filter. Ask for a sample Annex IV file, a sample FRIA, a sample Declaration of Conformity. Vendors who generate them will show you. Vendors who do not will show you a dashboard.
Method and corrections
Twelve vendors were assessed on publicly available material — product pages, documentation, pricing pages, trust centres and company registries — verified on 4 August 2026. Contract-value figures come from third-party transaction aggregators and are labelled as observed medians, not vendor-published prices. Affiliate and AI-generated comparison sites were excluded as sources. Article 50 tooling was not systematically assessed across all vendors in this edition and is marked "not assessed" where we did not verify it.
If you are a vendor named here and something is wrong or out of date, tell us and we will correct it and note the correction publicly.
- •This guide is information, not legal advice. Risk classification under the EU AI Act involves judgement that no software tool resolves definitively. Have a qualified lawyer review your classification and conformity documentation before you place a high-risk system on the market.