A rules engine for the law — not a chatbot guessing at it.
Most tools either hand you a static PDF checklist or ask a language model to improvise your obligations. Veritome does neither. The legal core is a proprietary obligation engine: a structured, article-by-article model of the EU AI Act that reads each system's role, risk tier and characteristics, and returns the precise set of obligations, deadlines and evidence it owes — and nothing it doesn't.
It is the single source of truth across the whole product. Every tab, score, document and reminder you see is derived from it — which is why a classification you defend to a regulator today reads identically a year from now.
Deterministic, not a guess
The legal core is a rules engine, not a language model. The same inputs always produce the same obligation set — so a decision you defend to an auditor today reads identically tomorrow.
Anchored to the Article
Every obligation, deadline and control cites the exact provision it comes from. Nothing is asserted without a reference you can look up in the Regulation itself.
Kept current, centrally
When guidance or the law changes, the engine is the single place we update — and every affected system re-derives its obligations. You inherit the change without re-reading 113 articles.
The engine's internal logic is Veritome intellectual property. What we share openly is the outcome — the exact article references behind every obligation — so your compliance is fully auditable without exposing how the mapping is built.
From first classification to live monitoring, in six phases.
Every system moves through the same journey. Phases are gate-locked — you can't register a system you haven't assessed — and empty phases are skipped automatically when they don't apply to your role. The bar at the top of each system shows exactly where it stands.
Classify
Know exactly what you're holding.
Answer a short set of questions per system. The engine returns a risk tier — prohibited, high, limited or minimal — anchored to the specific articles that decide it, plus the Art. 6(3) high-risk exception where it applies.
Scope
See only the obligations that are actually yours.
Your role (provider, deployer, importer, distributor) and risk tier resolve to the exact obligation set — nothing generic, nothing missing. A deployer of a limited-risk chatbot and a provider of a high-risk system get two different, correct lists.
Implement
Put the controls in place, with the proof attached.
Work each obligation as a guided checklist — human oversight, logging, data governance, technical documentation — attaching evidence as you go. Evidence carries expiry dates, so coverage stays honest over time.
Assess
Run the assessments the Act requires, on the record.
Guided fundamental-rights (FRIA) and conformity assessments, with a sealed report at the end. Where a DPIA already exists under the GDPR, the overlap is mapped so you don't do the same work twice.
Register
Hand the regulator a dossier that holds up.
Annex VIII registration fields pre-filled from your system record, a Declaration of Conformity, and a hash-sealed dossier with a public verify URL your auditor can check independently.
Monitor
Stay compliant after go-live, not just at launch.
Post-market monitoring, serious-incident reporting inside the Art. 73 window, scheduled reviews, and a live regulatory-change watch that flags when the law — or your obligation set — moves under you.