Know which AI Act
deadline is yours.
Build a clear, defensible classification for every AI system so you know exactly which obligations apply.
The enforcement clock,
after the Omnibus.
The EU AI Act applies in waves. Know what each tier means and what your team must have ready.
Four risk tiers.
Different rules for each.
Everything follows from classification. Get the tier wrong and you either over-document, or miss obligations priced in global revenue.
Banned outright
Systems posing severe threats to fundamental rights. There is no compliance route, only withdrawal.
Strict obligations
Systems affecting people in sensitive domains. Conformity assessment, risk management and human oversight all apply, now from December 2027.
Transparency rules
Systems that interact with people or generate content. The duty is disclosure, not assessment.
Voluntary codes
Most AI in most businesses. No mandatory obligations, but you still need to have shown the system sits here.
Start free, before
you start buying.
Two tools that answer the first two questions any AI governance programme faces: what do we run, and what does the Act require of it.
EU AI Act Compliance Checker
Answer a short set of questions about one AI system and get its likely risk tier with the obligations that follow. Useful before a budget conversation, because it turns "we should look at the AI Act" into a specific list of what is owed and by when.
AI Inventory Template
Every obligation under the Act starts with knowing which AI systems you run, and most organisations cannot say. This template gives you the columns that matter, so a first inventory is an afternoon rather than a project.
Your role decides
your obligations.
The same AI system carries different duties depending on where you sit in the chain. Most organisations occupy more than one of these positions at once.
Providers
You build, train or place an AI system on the market under your own name.
Deployers
You use someone else's AI in your operations, which is most companies. Human oversight, logging and impact assessment apply to you.
Importers and distributors
You bring non-EU AI systems to the European market and must verify conformity assessment and CE marking.
Non-EU organisations
Your company sits outside the EU but your AI output reaches EU users. The Act reaches you, exactly as the GDPR does.
Four stages. One
continuous programme.
Whisperly runs the Act as a lifecycle rather than a document exercise, and links it to your GDPR programme so a system processing personal data is governed once.
Discover and register
Nothing can be governed until it is known. Intake catches new initiatives before they reach production, and discovery finds the AI already running in your stack.
Classify
Each system scored against Annex I and Annex III criteria, with the reasoning recorded. A defensible minimal-risk conclusion is worth as much as a high-risk one.
Document
The Annex IV technical file, human oversight procedures and AI policies generated from what the platform already holds, rather than drafted from scratch per system.
Monitor and prove
Models change, and a classification made last year may not hold. Drift triggers re-assessment, and every change is timestamped for the file.
Frequently asked questions
Ready for what
actually lands.
Start with the free checker and the inventory template, or see the whole programme running alongside your GDPR work.