01
A model never decides a risk tier
Classification is rule-based against the Act. The model explains; the rules decide. If those two ever disagreed, the rule stands and the rationale is the thing that is wrong.
About E-ARI
E-ARI turns EU AI Act obligations into evidence. Not a policy template, not a readiness score with nothing behind it — a record of the AI systems you operate, what the law asks of each, the evidence behind it, the work you reviewed, and exports a reviewer can verify.
Why it exists
Most organisations covered by the AI Act are not large enough to have an AI officer. Under 250 people, the Act lands on whoever already owns GDPR — usually one person, usually part-time, usually without a budget line.
That person does not need a 400-page explainer. They need to know which systems they are responsible for, which duties actually apply to them rather than to a frontier lab, and what they can hand over when someone asks. Most of the Act is addressed to providers of high-risk systems. Establishing that you are not one is itself work, and it is work worth recording.
How it works
Every AI system you operate goes into one register, including tools an SSO or expense export shows are already in use but were never declared. Registration does not require an assessment.
Each registered system is matched against the Act’s own criteria to produce a risk tier. The rules decide the tier. A language model writes the rationale in readable English and cites the provisions that fired — it never chooses the outcome, and it cannot move a system between tiers.
Obligations are scoped to each system’s tier and your role, and uploaded evidence is linked to the obligations it supports, clause by clause. Article 4 training runs as 12 modules with server-graded knowledge checks; completions are dated per person and carry a keyed attestation, so the roster exports as evidence rather than as a claim that training happened.
A 40-question readiness assessment across 8 pillars, weighted by sector, diagnoses organisational practice. The scoring engine is deterministic and versioned: the same answers produce the same score on any day, on any machine, and the version that produced a report is stamped on it. No model sits between your answers and your number, and the number is a diagnostic, not a compliance determination.
Assessment priorities become improvement actions with an owner, a due date, linked systems and evidence, and a recorded review of the outcome. Obligation gaps stay visible in controls until evidence closes them.
Exports are sealed: artifacts are bound to a signed manifest that a reviewer can check with the independent verifier, outside E-ARI.
Readiness engine v5.6 · 8 pillars · 40 questions · 12 Article 4 training modules
What it will not do
01
Classification is rule-based against the Act. The model explains; the rules decide. If those two ever disagreed, the rule stands and the rationale is the thing that is wrong.
02
If a figure appears on a screen or in a report, it was computed from something you entered or something we can cite. A plausible-looking chart built on a fabricated axis launders a guess into evidence, which is worse than showing nothing.
03
Training is graded on the server, not in your browser. Completions are dated and hashed. An attestation anyone could recompute would not be evidence of anything.
04
The readiness score and level describe self-reported practice, and evidence coverage shows what is linked. Neither certifies compliance. The methodology and the scoring version are published, and where the platform cannot know something it says so instead of estimating.
The text we track
E-ARI is a compliance tool, not a law firm. It tells you what the Act asks and helps you evidence it. It does not give legal advice, and no output should be filed as though a lawyer wrote it.
Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (the Digital Omnibus). The platform works from the consolidated text, and where an amendment changed a duty, the change is recorded rather than quietly absorbed — you can read what moved and when in the regulatory changelog.
Who builds it
E-ARI is built in Portugal. The methodology, the people behind it, and the verifiability claims we hold ourselves to are on the team page. How your system register, evidence, assessment answers and training records are actually held is on the security page, and the roles we are hiring for are open here.