Quick answer

OptiTech runs the EU AI Act as a native framework: register every AI system in the inventory, run the guided classification to determine its risk category with documented reasoning, and receive the matching obligation set: full high-risk controls, transparency tasks for limited-risk, or just inventory presence for minimal. The heavy high-risk artifacts (risk management, technical documentation, logging, human oversight) run as maintained controls in the same workspace as your security program.

Classification you can defend

The guided assessment walks the Act's actual criteria (use context, affected persons, sector triggers) and stores the answers, the resulting category, and the reasoning with timestamps. That documented basis matters both directions: it justifies high-risk investment to your management, and it defends a minimal-risk call to a market surveillance authority or an enterprise customer's AI governance reviewer. Reclassification reviews recur, because systems change purpose faster than anyone updates wikis.

The high-risk obligation set, operationalized

  • Risk management system: AI-specific risks live in the risk register with assessment history across the lifecycle.
  • Technical documentation: generated from templates tied to the actual system record, versioned, and kept current through change previews.
  • Logging and traceability: verified as technical controls against your pipelines through integrations.
  • Human oversight: documented checkpoints, verified where technical (approval gates in deployment), assigned where procedural.
  • Accuracy and robustness: testing regimes as recurring tasks with attached results.

Deployer obligations (using high-risk AI, not building it) load as their lighter counterpart, and procured AI tracks through the supplier register with classification requests to vendors.

One AI governance layer, several frameworks

The same inventory and controls feed ISO 42001 certification and a NIST AI RMF profile, and OptiTech's own AI features are governed by the same standards they help you meet: EU-hosted, cited, human-reviewed. When customers' questionnaires add AI sections, answers come from live governance data, not improvisation.

See OptiTech in action

Get a personalized walkthrough of automated compliance for your team. No commitment required.