AI governance, as code

Governance for every jurisdiction. Starting with the EU.

AI regulation is arriving region by region. AiExponent generates the evidence each regime demands, and because the obligations overlap, you produce it once and map it everywhere. We begin with the most mature regime, the EU AI Act.

Not legal advice. Not a notified body. Tools produce evidence, not conformity assessment.

Coverage

European UnionTools live
United StatesCross-maps
Also tracking+4 regimes
Next enforcement · new Article 5 prohibitions · 2 Dec 2026

Live today · the EU toolchain

Four tools. One artefact per article.

Free · Apache 2.0 · zero telemetry

Art. 53 · in forceLive · v2.0.2

License Compliance Checker

Article 53 requires model documentation. Scan the repo; the licence and training-data report comes out.

OSS + model licence reportJSON
bashpip install license-compliance-checker
Art. 9 · applies Dec 2027Live · v1.1.3

RiskForge

Article 9 requires a documented risk management system. 37 guided questions produce the file, no consultants, ~30 minutes.

Risk Management FileJSONPDF
bashpip install riskforge
Art. 15 · applies Dec 2027Live · v1.0.2

RAG Benchmarking

Article 15 requires declared accuracy and robustness. Benchmark the system; the metrics report comes out.

Retrieval accuracy reportJSONMarkdown
bashpip install rag-benchmarking
Art. 5 · in forceLive · v1.0.1

LitmusAI

Article 5 prohibits eight AI practices. Screen the system; a per-prohibition verdict comes out.

Prohibited-practices verdictSARIF
bashpip install litmus-screener

Find your obligation

What are you deploying?

Pick one. We show the EU AI Act article that applies, when it bites, and the file it demands.

Art. 53In force

GPAI duties under Article 53 carry live enforcement today.

GPAI provider obligations

You must produce OSS + model licence report (JSON).

bashpip install license-compliance-checker
Generate now with License Compliance Checker →

Maximum fine

Up to €15M or 3% global turnover

Art. 101(1) · Commission-imposed

The file

OSS + model licence report (JSON)

Not legal advice. Not a notified body. Tools produce evidence, not conformity assessment. Dates and fine bands cite Regulation (EU) 2024/1689 (EUR-Lex CELEX:32024R1689).

EU AI Act · Article 113

What applies when

Three deadlines have passed. Three are ahead.

  1. 2 Feb 2025

    Bans and AI literacy apply

    Art. 4 and Art. 5 apply. Art. 113(a)
    In force
  2. 2 Aug 2025

    GPAI duties and governance apply

    Art. 53 duties and the penalty chapter apply. Art. 113(b)
    In force
  3. 2 Aug 2026

    GPAI fining powers attach

    Commission fines under Art. 101, up to €15M or 3%. Art. 113, second paragraph and point (b)
    In force
  4. 2 Dec 2026

    New prohibitions apply

    Art. 5(1)(ba) and (bb) apply. Generative systems already on the market meet Art. 50(2). Art. 113(a) and Art. 111(4), as amended
    Next
  5. 2 Dec 2027

    Annex III high-risk systems comply

    Annex III systems: Chapter III, Sections 1 to 3. Deferred by the Digital Omnibus. Art. 113(c)(i), as amended
    UpcomingMoved
  6. 2 Aug 2028

    Annex I high-risk systems comply

    Product-embedded systems under Annex I: Chapter III, Sections 1 to 3. Deferred by the Digital Omnibus. Art. 113(c)(ii), as amended
    UpcomingMoved

Dates as amended by Regulation (EU) 2026/1744, in force since 27 Jul 2026. See what changed.

Beyond the tools

Where the tools end, judgment begins.

AiExponent ships the evidence, the file a regulator will accept. Deciding your risk posture, reading overlapping regimes, and building AI literacy across your teams is human work. When you want the strategy before you deploy, that is our advisory arm.

Explore advisory at AskAjay.ai ↗Tools stay free and open source. Advisory is a separate engagement under AI Exponent LLC.
  • Not sure where to start?

    A governance readiness review: what applies to you, and in what order.

  • Want the trends and frameworks first?

    Thought leadership and workshops on AI strategy, risk and responsible deployment.

  • Need hands-on help?

    Advisory engagements that take the evidence our tools produce the rest of the way.