Complipath helps you do what the EU AI Act asks of you. The name for that kind of product is EU AI Act compliance software. It builds an inventory of the AI systems a company runs and classifies each one under Regulation (EU) 2024/1689.
Written 2026-08-17 by Yobel Tzegai · last changed 2026-10-09. Every figure below is read from the pricing source at build time, not written here.
The easiest way for a European company to know exactly what the AI Act requires, and prove it. Every compliance decision has a source.
Companies that build or deploy AI, from small teams to large organisations — often software companies with AI in the product — established in Europe, or established outside it and covered because the system is placed on the Union market or its output is used in the Union. Many already have compliance or legal people, and Complipath does the part that takes the time so they have something to work from.
What it does not do
Complipath never decides your risk level for you: it shows what the law says, where it says it and what follows, and the decision stays with you.
What it does
An inventory of every AI system, one row per system
Deterministic risk classification — a short set of questions, more if your answers open follow-ups; no language model in the decision path, the same answers always produce the same classification
The article behind every classification, quoted
The version of the Regulation each one was derived from, recorded and hashed
A shareable read-only link for a customer’s security review
Complipath decides with rules, not a language model. Every classification is made by a rule engine and cites the article, the engine version and the law version. AI only drafts text from your own documents. Every sentence links to its source, and a person confirms it.
Complipath provides legal information, not legal advice; it certifies nothing, runs no formal conformity assessment, and hands the questions that need a lawyer to a lawyer. The whole boundary: what the check can and cannot decide.
How it works, step by step
1 · Discover
Live. Reads your website and suggests the AI systems it shows; paste a list, read a package.json, or let colleagues report a tool through a link.
2 · Classify
Live. A rule engine decides the level and names the article it rests on, including the Article 5 practices.
3 · Understand
Live. Every factor cites its provision, and the plan gives each system its next steps by role.
4 · Assign
Live. Each obligation has an owner, a status and a date it applies from.
5 · Fix
Live. The Annex IV documentation is drafted from your register, and says what it could not answer.
6 · Evidence
Live. A file is linked to the requirements it proves, with the passage and its page.
7 · Monitor
Live. When an amending act touches a provision your records cite, you get an email per affected system.
8 · Prove
Live. Export the register with the law texts it was assessed against. Share a read-only link and read the audit log.
In progress. Not available yet: the audit pack, one file for an auditor.
What is live today, and what is not
Every capability buyers ask about, with its status in the product. 16 live, 2 in progress, 9 not supported. Status on 8 October 2026. Rules decide. AI only drafts. A person confirms.
AI inventoryLiveEvery AI system you build or use, with its owner and risk class.
Risk classificationLiveAnswers go through rules in code, never a language model, so the same answers always give the same result.
Article mappingLiveEach reason behind a verdict names the provision it rests on, so a reader can check it herself.
Obligations per systemLiveConfirming a classification creates the obligations that follow from it, each with an owner, a status and a place for evidence.
DeadlinesLiveEach obligation carries the date it applies from, derived from where the provision sits rather than written onto the row.
Annex IV documentationLiveA workspace for the technical documentation, section by section, saying which Annex IV points each one answers.
Documentation draftingLiveDrafts a documentation section from the facts in your register, and says which limbs it could not answer.
Regulatory change monitoringLiveChecks the provisions your confirmed records cite against amending acts, and emails you per affected system.
Named ownersLiveA person behind every system and every duty.
Export (PDF, JSON, spreadsheet)LiveThe whole register as a spreadsheet, as JSON or as a PDF, with the exact law texts it was assessed against.
Evidence managementLiveA file linked to the requirements it proves, with the passage and its page.
DashboardLiveWhere every system stands.
AI literacy (Article 4)LiveRecords who was trained on what and when, against the Article 4 duty to support AI literacy, which applies whatever your risk level.
Two-factor sign-inLiveA code from your phone after the email link, which the owner can require for everyone.
Audit logLiveWho did what, and when. No one can edit or delete a line, an owner included; only deleting the whole workspace removes it.
Audit packComing soonOne file for an auditor: every system, its classification, evidence, the audit log and a fingerprint. Not available yet.
Customer questionnaires (audit room)Coming soonComing soon: answering a customer's AI questionnaire from your own register.
Domain-specific guidanceNot supportedGuidance written for one sector.
Full risk-management lifecycleNot supportedArticle 9 is listed as a duty with its date. There is no risk register to run the cycle in.
Conformity assessment (Article 43)Not supportedWe found no support for this in what we have built. The same search found the number in one file — a comment using it as an example of the Official Journal's citation form — and the words in six, every one of them quoting Article 6(1), point (b)'s third-party condition, an Article 5 sentence or a section name. No template, no column, no limb.
Post-market monitoring (Article 72)Not supportedWe found no support for this in what we have built. MVP searched 245 shipped source files, 44 migrations, 14 obligation templates, 15 export columns and 12 Annex IV limbs, on the article number and on the provision's own words: nothing on any of the five.
Serious incident reporting (Article 73)Not supportedWe found no support for this in what we have built. Same search, same five places: nothing.
Fundamental rights impact assessment (Article 27)Not supportedThe step-by-step plan lists Article 27 as a step only for systems classified under points 5(b) and 5(c) of Annex III. Article 27(1) also binds deployers that are bodies governed by public law or private entities providing public services, and the product does not ask whether you are one. Nothing carries the assessment itself.
Declaration of conformity (Article 47)Not supportedThe Annex IV documentation asks for a copy of the declaration and you upload it; the plan says to issue it when the system is ready. The declaration itself is not drafted.
EU database registration (Article 49)Not supportedListed as a duty with its date. The registration itself is yours.
ISO/IEC 42001 mappingNot supportedThe assistant answers questions about ISO/IEC 42001 next to the AI Act. There is no mapping of its controls to the Act, and Complipath certifies nothing.
Vendor managementLiveAn AI tool you buy is registered and classified like one you build, with the obligations of a deployer and the AI literacy record. There is no vendor questionnaire and no contract review.
Is Complipath an EU AI Act compliance platform or an AI governance platform?
An EU AI Act compliance platform. Complipath is not an AI governance platform. It is EU AI Act compliance, and nothing else. If you searched for an AI governance platform or an AI compliance operating system, the boundary is in the table above: no mapping of ISO/IEC 42001 controls to the Act, no risk register to run the Article 9 cycle in and no post-market monitoring under Article 72.
Which Complipath this is
Complipath (complipath.io), EU AI Act compliance software from Gothenburg, Sweden. Complipath is the company at complipath.io. It has no connection to complipath.systems or complipath.com, which are other services with a similar name (both read on 8 October 2026).
AI literacy
For the people who work with your AI systems, Complipath keeps a record of who has read what, and when.
Add the people who work with AI, whether staff, contractors or agency people, with their role and the systems they use, and you get one list of who should read what.
Paste a list of names or upload a CSV file, up to 500 at a time, and they are added in one step.
Send everyone “AI Act basics (everyone)”, built from the law, and send each system’s own briefing, built from your register, your documentation, your company’s notes and your plan, to the people who work with that system; every version is kept.
Write three fields for each system in your own words, and the briefing shows them as written by your company.
Press “Send to everyone who hasn’t read it”, or choose people one by one, and the briefing goes to them.
Each person gets an email link that works for 30 days and that you can revoke, and you get a link to copy for anyone without an email address.
The person reads it and presses “I have read this”, without an account, and the reading is recorded with its date.
Record a reading yourself or add training done elsewhere, and it goes into the same record.
See each person’s status for each briefing: “Read”, “Earlier version”, “Sent, not read yet”, “Link expired” or “Not sent”.
Download the record as a PDF or a CSV file, and you have something to show a customer.
AI literacy is part of Starter and the 30-day trial. It is not part of Free.
Article 4 of the AI Act: providers and deployers “shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf”. It has applied since 2 February 2025 (Article 113, third paragraph, point (a)); this wording is from Regulation (EU) 2026/1744. The same paragraph adds that the obligation “does not require providers or deployers to guarantee any specific level of AI literacy of any individual”. What the duty asks, and of whom: who the AI literacy duty applies to.
The 72-second tour
See how it works in 72 seconds.
The app, shown with an example company. Turn the sound on, or read the captions.
The EU AI Act is here. Your AI systems now have rules, and deadlines.
Many teams answer with spreadsheets and consultants. One company we spoke with pays about twenty-five thousand kronor a month for outside help.
Complipath starts with your company name. It reads your website and suggests the AI systems it shows. No account needed.
Each system gets its risk class from a rule engine, with the exact article behind it. No guesswork. The source.
You see what each system owes, who owns it and the documentation the law asks for, drafted from your answers.
Ask the assistant anything about the law or your register. Every answer shows its source.
When the law changes, Complipath tells you which of your systems it touches.
Your first system is free, always. Try Starter free for thirty days, no card. Check your AI systems at complipath.io.
What it costs
Starter — €499/month · 20 AI systems · 5 users
Archived systems don’t count toward your limit.
Growth — €1,499/month · 50 AI systems · 25 users
Archived systems don’t count toward your limit.
Scale — €4,999/month · unlimited AI systems
Prices exclude VAT.
Growth and Scale are announced but not yet available. Your first system is free, with no application and nothing asked in exchange. Before you decide anything, the twelve questions an outside reviewer would put to us are answered at what to ask us — four of the answers are no.
How to try it
The classifier is open at complipath.io with no account.