Aria · the assistant inside the register

Drafts, proposes, never files.

Aria reads your register and drafts the record, maps the requirement and flags the change — with the article beside every answer. Each write lands in the Inbox as a proposal until a named person applies it.

The oversight the Act asks forArt. 14Art. 26(2)Art. 50(1)
Aria's Settings tab — the copilot set-up: what it may read, what it knows and how far it may go
What Aria does — and does not

Proposes, cites, waits for a person.

Four things Aria does on every workspace, and four it will not do on any. Both lists are the product's rules, not a promise: the agent test suite fails a release on a single write applied without approval.

Aria does
Drafts the record

A first pass at the human-oversight section, a FRIA from the risk register, an incident notification — from what is already in your register, for a person to edit.

Art. 27
Maps the requirement

Which obligations a system owes, which frameworks an obligation also closes, which controls are still uncovered — read from the same engine the register runs on.

Cites the article

Every answer names the provision it relies on or says it cannot. The citation is checked against the regulatory registry; one that does not resolve is flagged, not passed on.

Proposes the change

Give it a goal — review the unclassified systems, propose tasks for what is due this month — and each write lands in the Inbox as a proposal with its reasoning.

Aria does not
File with a regulator

Incident notifications, EU database registration and dossier submissions are manual only. Aria drafts them; it will not even propose sending one.

Art. 73
Apply a change on its own

The default is Approve each: nothing applies without sign-off. Classification and anything touching a high-risk system need a named person's sign-off whatever you set.

Art. 14
Give legal advice

Aria is decision support. Every substantive answer carries the same posture — informational, confirm with counsel — and the product records who confirmed what.

Learn from your data

Conversations are not used to train the model. Aria reads your register through org-scoped tools and does not browse the web during a conversation.

One page, five tabs

Inbox · Run · Activity · Ask · Settings

Aria is one page in the product, with the tab in the URL. Copilot is what it produces — the Inbox of proposals, a Run you give a goal to, the Activity log with outcomes. Chat is Ask. Settings is the set-up. The top-bar button opens the same assistant as a drawer, with the page you are on as context.

Inbox

Every proposal, one place, the same anatomy.

Whatever produced it — a run, a conversation or a regulatory signal — a proposal waits here with what Aria read, what it proposes and what it will not do, until someone applies or dismisses it. The tab carries the count, so nothing waits unseen.

  • Apply writes the record and the audit line together; dismissing records the decision
  • Where the floor says sign-off, the button reads Review & sign
  • Filter by source — runs, chat, signals — and the oldest proposal is named
Art. 14Art. 26(2)
Aria's Inbox — the tab that lists every proposal waiting for a person; empty on the demo workspace
Ask

A question, an answer, the article beside it.

Ask in plain language, attach a document to answer against, and read the reply with its citations as clickable references. The top-bar drawer opens the same assistant with the page you are on as context, so on a system's obligations it offers what is due on that system.

  • Citations always on — the toggle that let Aria drop the article was removed
  • Attach PDF, DOCX, TXT, MD or CSV to ground an answer in your own material
  • Conversation history is off by default
Art. 50(1)
Aria's Ask tab — the conversation with prompt cards, before a first question
Settings

The set-up: what it reads, what it knows, how far it may go.

Behaviour, privacy and context, knowledge sources and autonomy, on one screen. Knowledge follows Frameworks — enable ISO/IEC 42001 and its corpus grounds Aria; there is no second list to keep in sync. Context is off by default unless it is needed to answer at all.

  • Obligation status and risk classifications on by default; team names and document titles off
  • Anonymise system names before anything reaches the model
  • Autonomy per capability, with the policy floor shown on each row
Art. 14GDPR Art. 25
Aria's Settings tab — behaviour, privacy and context, knowledge sources that follow Frameworks, and autonomy per capability
Run

Give Aria a goal.

“Review my unclassified systems and propose classifications.” “Propose tasks for the obligations due in the next 30 days.” Aria reads what it needs with org-scoped tools, works inside the run’s scope, and proposes. The run reports what it did and where the outputs went — the Inbox.

Activity

What Aria did, with outcomes.

Every run and every proposal, with an outcome an auditor can read. A run that produced nothing is not a success — it reads as what it is.

AppliedDismissedIn inboxIn inbox · 3No proposalsFailed · timed out
The autonomy model

Two settings. One floor that cannot be lowered.

Each capability is set to Approve each or Auto-apply. The first queues every change for a person; the second applies low-stakes changes and logs them for review. Under both sits a policy floor derived from the system’s risk tier and the kind of change — you can dial a capability down, never past the floor.

Stakes
When
The floor
Low stakes
A routine change on a minimal-risk system — a task, a review date, a draft.
Low stakes · candidate for auto-apply
Medium stakes
A change on a limited-risk system, or one whose tier is not yet known.
Floor: needs approval
High stakes
Any classification, and any change to a high-risk or prohibited-tier system.
Floor: sign-off required · always
Regulator-facing
An incident notification, an EU database registration, a dossier submission.
Manual only

The floor is the Act’s: a natural person exercises oversight over a high-risk system (Art. 14), a deployer assigns that oversight to people with the competence and authority to act (Art. 26(2)), and a serious incident is reported by the provider, not by software (Art. 73). The agent test suite pins each row above, and fails a release on a single forbidden outcome.

Built in the open

An AI system, documented the way yours will be.

Aria is an AI system, so Veritome documents it the way it asks you to document yours: the model, the data that reaches it and the tests every change must pass — published, dated, on a public card.

The model
Mistral Small, served from Paris

A general-purpose model by Mistral AI, configured with instructions and retrieval over a controlled corpus — configuration, not training. Mistral holds the model-provider duties; Veritome holds the system-provider ones.

The data
Your question and the context you allow

What reaches the model is your prompt, any document you attach, the context toggles you leave on and the retrieved passages. It is processed under a data-processing agreement and not used for training.

The tests
20/20 answers · 0 forbidden outcomes

Two evaluation suites gate every change to Aria's prompt, sources or model. The latest run (02.09.2026) is published in full, questions included.

How Aria is built and tested →Aria’s public AI System ID →
Questions

Straight answers about Aria.

What does Aria actually do inside Veritome?

Aria reads your register through org-scoped tools and drafts, maps and cites: a first pass at a record, the obligations a system owes, the article behind an answer. Anything that would change the register lands in its Inbox as a proposal for a person to apply or dismiss.

Can Aria change something without me?

Not by default. Approve each queues every change for a person. If you switch a capability to Auto-apply, only low-stakes changes apply, and each is logged for review. Classification and anything on a high-risk system always need sign-off, and regulator-facing actions are never automated.

Which model does Aria run on, and where?

Mistral Small, served by Mistral AI from Paris under a data-processing agreement. The application and its database run on Hetzner in Nuremberg. Prompts are not used to train the model. The full picture, including the sub-processors under standard contractual clauses, is on the transparency page and the public sub-processor register.

What does Aria know?

The EU AI Act and its recitals, Veritome's regulatory registry of articles, dates and obligations, official guidance and the record templates — plus the corpus of every framework you have enabled. Knowledge sources follow Frameworks; the EU AI Act is always on.

Is Aria legal advice?

No. Aria is informational decision support. Every substantive answer says so and asks you to confirm compliance decisions with qualified counsel; the product records the person who confirmed, and that decision, not Aria's suggestion, is what your audit trail carries.

Is Aria itself governed under the EU AI Act?

Yes. Aria is an AI system, so it carries the Art. 50 disclosure on every screen and publishes its own AI System ID card — model, hosting, role, risk classification and oversight — the same card the product asks you to publish for yours.

More in the help centre: Ask Aria — what the assistant can and can’t do. Aria’s legal notice is the AI Transparency Notice.