The pain

AI vendors are the new third-party risk. Your enterprise customers need you compliant before they'll sign — and regulators are coming for the supply chain.

EU AI Act DORA NIS2 Foundation Model Obligations

Laws that likely apply to you

  • EU AI Act — Foundation Model Obligations — technical documentation, copyright compliance for GPT/Claude/etc. deployers
  • DORA — ICT risk management for AI vendors serving EU financial entities
  • NIS2 — cybersecurity measures for AI service providers classified as essential entities
  • EU AI Act Art. 50 — chatbot disclosure and synthetic-content labeling, in effect since Aug 2, 2026; machine-readable marking for existing systems from Dec 2, 2026
  • California SB 942 / AB 853 — detection tool and provenance disclosures for large generative AI providers, in effect since Aug 2, 2026
  • OMB M-25-22 — if you sell to federal agencies: no training on non-public agency data, portability terms, pre-award testing and continuous monitoring
  • NIST AI RMF — de facto standard even outside government; your customers will ask for it

What we do

The fastest version: we turn your answers into a trust profile — a live page you send to a buyer instead of completing their spreadsheet. Answer once, reuse in every deal, and let the tracker keep it true when the law moves. Start from the open standard.

We help AI vendors build the compliance infrastructure their enterprise customers require — documentation, risk assessments, and audit readiness — so a procurement questionnaire stops being the thing that stalls your deal.

Take the Assessment

Last verified:

Informational only — not legal advice. Consult qualified counsel for binding guidance.