Compliance you can put in front of an auditor.
E-ARI turns EU AI Act obligations into evidence. Not a policy template, not a readiness score with nothing behind it — a record of what you operate, what the law asks of it, and what your people were actually trained on.
Why it exists
Most organisations covered by the AI Act are not large enough to have an AI officer. Under 250 people, the Act lands on whoever already owns GDPR — usually one person, usually part-time, usually without a budget line.
That person does not need a 400-page explainer. They need to know which systems they are responsible for, which duties actually apply to them rather than to a frontier lab, and what they can hand over when someone asks. Most of the Act is addressed to providers of high-risk systems. Establishing that you are not one is itself work, and it is work worth recording.
E-ARI is built for the person who has to sign the file.
How it works
Measure
A 40-question assessment across 8 pillars, weighted by sector. The scoring engine is deterministic and versioned: the same answers produce the same score on any day, on any machine, and the version that produced a report is stamped on it. No model sits between your answers and your number.
Classify
Each AI system you register is matched against the Act’s own criteria to produce a risk tier. The rules decide the tier. A language model writes the rationale in readable English and cites the provisions that fired — it never chooses the outcome, and it cannot move a system between tiers.
Evidence
Obligations are mapped to what you actually operate, and Article 4 training runs as 12 modules with server-graded knowledge checks. Completions are dated per person and carry a keyed attestation, so the roster exports as evidence rather than as a claim that training happened.
Scoring engine v5.4 · 8 pillars · 40 questions · 12 training modules
What it will not do
A compliance tool that guesses is worse than no tool, because its output looks like evidence.
A model never decides a risk tier
Classification is rule-based against the Act. The model explains; the rules decide. If those two ever disagreed, the rule stands and the rationale is the thing that is wrong.
Numbers come from inputs, not from vibes
If a figure appears on a screen or in a report, it was computed from something you entered or something we can cite. A plausible-looking chart built on a fabricated axis launders a guess into evidence, which is worse than showing nothing.
Nothing important is self-declared
Training is graded on the server, not in your browser. Completions are dated and hashed. An attestation anyone could recompute would not be evidence of anything.
The limits are written down
The methodology is published, the scoring version is stamped on every report, and where the platform cannot know something it says so instead of estimating.
The text we track
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (the Digital Omnibus). The platform works from the consolidated text, and where an amendment changed a duty, the change is recorded rather than quietly absorbed — you can read what moved and when in the regulatory changelog.
E-ARI is a compliance tool, not a law firm. It tells you what the Act asks and helps you evidence it. It does not give legal advice, and no output should be filed as though a lawyer wrote it.
Who builds it
E-ARI is built in Portugal. The methodology, the people behind it, and the verifiability claims we hold ourselves to are on the team page.