# AiExponent > The EU AI Act's required artefacts, generated where engineers work. ## About Open source tools that generate the EU AI Act's article-mapped compliance artefacts, with cross-mapping to NIST AI RMF and ISO/IEC 42001. Built by a practitioner, for practitioners. - [Website](https://aiexponent.com): Product site and documentation. - [GitHub](https://github.com/aiexponenthq): Source for every tool, Apache 2.0 licensed. - [LinkedIn](https://linkedin.com/company/aiexponent): Company updates. - [Contact](mailto:hello@aiexponent.com): General enquiries. ## Open Source Tools - [License Compliance Checker](https://aiexponent.com/docs/license-compliance-checker): Framework-agnostic license compliance harness for AI systems and software dependencies. Install: `pip install license-compliance-checker`. Source: [github.com/aiexponenthq/license-compliance-checker](https://github.com/aiexponenthq/license-compliance-checker). EU AI Act Article 53 · GPAI Compliance. Flagship, developer, python. - [RiskForge](https://aiexponent.com/docs/riskforge): EU AI Act Article 9 Risk Management System builder: 30 minutes to a signed, audit-trailed Risk Management File. Install: `pip install riskforge`. Source: [github.com/aiexponenthq/riskforge](https://github.com/aiexponenthq/riskforge). EU AI Act Article 9 · Risk Management. Flagship, developer, python. - [Agentic Document Analyser](https://aiexponent.com/docs/agentic-document-analyser): VLM-powered document-to-structured-JSON pipeline for compliance evidence processing. Install: `docker compose up`. Source: [github.com/aiexponenthq/agentic-document-analyser](https://github.com/aiexponenthq/agentic-document-analyser). EU AI Act Articles 11 + 19 · Evidence Processing. Infrastructure, developer, docker. - [RAG Benchmarking](https://aiexponent.com/docs/rag-benchmarking): Framework-agnostic evaluation harness for RAG and agentic AI systems. Install: `pip install rag-benchmarking`. Source: [github.com/aiexponenthq/rag-benchmarking](https://github.com/aiexponenthq/rag-benchmarking). EU AI Act Article 15 · Accuracy Requirements. Flagship, developer, python. - [LitmusAI](https://aiexponent.com/docs/litmusai): Free, deterministic CLI screener for the eight prohibited AI practices in EU AI Act Article 5. Install: `pip install litmus-screener`. Source: [github.com/aiexponenthq/litmusai](https://github.com/aiexponenthq/litmusai). EU AI Act Article 5 · Prohibited Practices. Flagship, developer, python. - [TraceForge](https://aiexponent.com/tools): Article 10 training-data governance: dataset lineage and risk registry. Gated 2027 build. Install: `# Conditional 2027 build, gated on adoption evidence`. Source: [github.com/aiexponenthq/traceforge](https://github.com/aiexponenthq/traceforge). EU AI Act Article 10 · Training Data Governance. In development, developer, python. - [TransparencyDeck](https://aiexponent.com/tools): Article 13 transparency document generator for deployers. Building Oct 2026. Install: `# Building Oct 2026`. Source: [github.com/aiexponenthq/transparencydeck](https://github.com/aiexponenthq/transparencydeck). EU AI Act Article 13 · Transparency. In development, developer, python. - [RMFMapper](https://aiexponent.com/tools): NIST AI RMF ↔ EU AI Act cross-mapping matrix. Demand-gated. Install: `# Demand-gated. Ask for it: /contact`. Source: [github.com/aiexponenthq/rmfmapper](https://github.com/aiexponenthq/rmfmapper). EU AI Act NIST AI RMF ↔ EU AI Act · Cross-Framework. In development, developer, python. - [ISOEvidence](https://aiexponent.com/tools): ISO/IEC 42001 management-system gap analysis. Demand-gated. Install: `# Demand-gated. Ask for it: /contact`. Source: [github.com/aiexponenthq/isoevidence](https://github.com/aiexponenthq/isoevidence). EU AI Act ISO 42001 · AI Management System. In development, assessment, python. - [VigilanceDash](https://aiexponent.com/tools): Article 72 post-market monitoring dashboard. Revisit 2027. Install: `# Timeline-gated. Revisit 2027`. Source: [github.com/aiexponenthq/vigilancedash](https://github.com/aiexponenthq/vigilancedash). EU AI Act Article 72 · Post-Market Monitoring. In development, assessment, python. - [OrgLiterate](https://aiexponent.com/tools): Article 4 AI-literacy evidence CLI. Building now. Install: `# Building now. Target: Sep 2026`. Source: [github.com/aiexponenthq/orgliterate](https://github.com/aiexponenthq/orgliterate). EU AI Act Article 4 · AI Literacy. In development, assessment, python. - [ConformityBot](https://aiexponent.com/tools): Article 43 conformity-assessment aggregation. Not on the current roadmap. Install: `# Not on the current roadmap. Revisit Jul 2027`. Source: [github.com/aiexponenthq/conformitybot](https://github.com/aiexponenthq/conformitybot). EU AI Act Article 43 · Conformity Assessment. In development, assessment, python. - [Sigil](https://aiexponent.com/tools#sigil): Articles 14 + 17 runtime governance evidence. Design-partner pilots. Install: `# Design-partner pilots. Enquire via /contact`. Source: [github.com/aiexponenthq/sigil](https://github.com/aiexponenthq/sigil). EU AI Act Articles 14 + 17 · Runtime Governance + QMS. In development, assessment, python. - [HealthAI-Comply](https://aiexponent.com/tools): MDR + EU AI Act + FDA clinical-AI evidence bundle. 2028 window. Install: `# Out of the current window. Anchored to Annex I, Aug 2028`. Source: [github.com/aiexponenthq/healthai-comply](https://github.com/aiexponenthq/healthai-comply). EU AI Act MDR + EU AI Act + FDA · Clinical AI Compliance. In development, assessment, python. ## Sigil (Design-Partner Pilots) - [Early access](https://aiexponent.com/contact?topic=sigil-early-access): Runtime governance for AI agents, developed with design partners. - Status: Fixed-scope design-partner pilots. Not generally available. No launch date announced; the pilots will decide the delivery model. - Details: An exploration into runtime AI agent governance: policy enforcement, tamper-evident audit logs, and compliance evidence for EU AI Act Articles 14 and 17, cross-mapped to NIST AI RMF and ISO/IEC 42001. Runs as fixed-scope design-partner pilots; the pilots decide the delivery model. Early access by enquiry. - EU AI Act: Articles 14, 17 · Runtime Governance - Pricing: Not yet published. Design-partner / founding-customer terms available on request. ## EU AI Act Tool Mapping | Tool | Article | Label | Description | |------|---------|-------|-------------| | License Compliance Checker | Article 53 | GPAI Compliance | Generates audit evidence supporting EU AI Act Article 53 documentation obligations: evaluates model card completeness, license compliance, and training data risk for AI components in your stack. | | RiskForge | Article 9 | Risk Management | Produces structured Article 9 Risk Management Files for high-risk AI systems suitable for inclusion in your Annex IV technical documentation pack. Organises the assessment across 8 risk dimensions derived across Articles 9, 10, 13, 14 and 15 (health & safety, fundamental rights, discrimination, privacy, transparency, human oversight, robustness, and data governance), with cross-maps to NIST AI RMF and ISO/IEC 42001. Not a substitute for notified-body conformity assessment. | | Agentic Document Analyser | Articles 11 + 19 | Evidence Processing | Structures unstructured compliance documents into machine-readable JSON for Article 11 technical documentation packages and Article 19 automatically-generated-log preservation workflows. Does not implement Article 9 risk management; use RiskForge for that. | | RAG Benchmarking | Article 15 | Accuracy Requirements | Provides systematic accuracy testing and documentation for high-risk AI systems under Article 15. | | LitmusAI | Article 5 | Prohibited Practices | Screens AI systems against the eight prohibited-practice categories of EU AI Act Article 5(1)(a)–(h). Conservative-by-default verdicts; UNREVIEWED reference ruleset (no external lawyer review yet); BYO signed-ruleset path for customers who need lawyer-reviewed output today. Article 5 has been applicable since 2 February 2025 (Art. 113(a)); sanctionable since 2 August 2025 (Art. 113(b)). | | TraceForge | Article 10 | Training Data Governance | Will produce Article 10 training-data governance evidence: dataset lineage, risk registry, copyright opt-out signals, provenance tracking. Not yet released. | | TransparencyDeck | Article 13 | Transparency | Will produce Article 13 transparency documentation for deployers. Not yet released. | | RMFMapper | NIST AI RMF ↔ EU AI Act | Cross-Framework | Will produce a NIST AI RMF ↔ EU AI Act cross-mapping matrix. Not yet released. | | ISOEvidence | ISO 42001 | AI Management System | Will produce ISO/IEC 42001 management-system gap reports. Not yet released. | | VigilanceDash | Article 72 | Post-Market Monitoring | Will produce Article 72 post-market monitoring evidence. Not yet released. | | OrgLiterate | Article 4 | AI Literacy | Will produce the Article 4 AI-literacy evidence artifact (JSON plus PDF): a record of the literacy measures taken, not training content or certification. Building now. | | ConformityBot | Article 43 | Conformity Assessment | Will aggregate conformity-assessment evidence into Article 43 packages. Not yet released. | | Sigil | Articles 14 + 17 | Runtime Governance + QMS | Runtime governance and QMS evidence for Articles 14 and 17, developed through fixed-scope design-partner pilots. Delivery model decided with those partners. | | HealthAI-Comply | MDR + EU AI Act + FDA | Clinical AI Compliance | Will produce clinical-AI evidence bundles spanning EU MDR, EU AI Act, and FDA. Not yet released. | | Sigil | Articles 14, 17 | Runtime Governance | An exploration into runtime AI agent governance: policy enforcement, tamper-evident audit logs, and compliance evidence for EU AI Act Articles 14 and 17, cross-mapped to NIST AI RMF and ISO/IEC 42001. Runs as fixed-scope design-partner pilots; the pilots decide the delivery model. Early access by enquiry. | ## Contact - [General enquiries](mailto:hello@aiexponent.com): hello@aiexponent.com - [Security](mailto:security@aiexponent.com): security@aiexponent.com - [Website](https://aiexponent.com): https://aiexponent.com