The toolchain

Four tools. One connected evidence file.

Each tool answers one EU AI Act article and emits one named artefact. They hand those artefacts to each other, and to your Annex IV technical file. Free, Apache 2.0, runs locally, zero telemetry.

bashpip install riskforge litmus-screener

Four tools live on PyPI today · more building across 2026–2027. Not legal advice. Not a notified body.

The audit workflow

One tool per article. The artefact is the proof.

Each tool answers one obligation and hands the next tool a real file. Run them in order and the evidence pack assembles itself.

Art. 5LitmusAI$ litmus screen
verdict: PASS
Art. 53License Compliance Checker$ lcc scan .
cyclonedx.json
Art. 9RiskForge$ riskforge assess
rmf.json + PDF
Art. 15RAG Benchmarking$ rag-benchmark run
accuracy_report.json
Your evidence packthe files a regulator asks for

Art. 4 and Art. 13 tools join the chain as they ship. The full 14-tool catalogue lives on the tools page.

Live now · v1.0 on PyPI

The four tools, in detail.

Each maps to one EU AI Act obligation and produces a named artefact: an SBOM, a Risk Management File, a benchmark report, a prohibited-practice verdict. Install one, or the set.

Art. 53 · in forceLive · v2.0.0

License Compliance Checker

Article 53 requires model documentation. Scan the repo; the licence and training-data report comes out.

Regulatory relevance

GPAI Compliance · Generates audit evidence supporting EU AI Act Article 53 documentation obligations: evaluates model card completeness, license compliance, and training data risk for AI components in your stack.

licence + model reportJSONSBOM
bashpip install license-compliance-checker
Art. 9 · applies Dec 2027 · pending OJEULive · v1.1.2

RiskForge

Article 9 requires a documented risk management system. 37 guided questions produce the file, no consultants, ~30 minutes.

Regulatory relevance

Risk Management · Produces structured Article 9 Risk Management Files for high-risk AI systems suitable for inclusion in your Annex IV technical documentation pack. Organises the assessment across 8 risk dimensions derived across Articles 9, 10, 13, 14 and 15 (health & safety, fundamental rights, discrimination, privacy, transparency, human oversight, robustness, and data governance), with cross-maps to NIST AI RMF and ISO/IEC 42001. Not a substitute for notified-body conformity assessment.

Risk Management FileJSONPDF
bashpip install riskforge
Art. 15 · applies Dec 2027 · pending OJEULive · v1.0.0

RAG Benchmarking

Article 15 requires declared accuracy and robustness. Benchmark the system; the metrics report comes out.

Regulatory relevance

Accuracy Requirements · Provides systematic accuracy testing and documentation for high-risk AI systems under Article 15.

accuracy + robustness reportJSON
bashpip install rag-benchmarking
Art. 5 · in forceLive · v1.0.0

LitmusAI

Article 5 prohibits eight AI practices. Screen the system; a per-prohibition verdict comes out.

Regulatory relevance

Prohibited Practices · Screens AI systems against the eight prohibited-practice categories of EU AI Act Article 5(1)(a)–(h). Conservative-by-default verdicts; UNREVIEWED reference ruleset (no external lawyer review yet); BYO signed-ruleset path for customers who need lawyer-reviewed output today. Article 5 has been applicable since 2 February 2025 (Art. 113(a)); sanctionable since 2 August 2025 (Art. 113(b)).

prohibited-practices verdictSARIF
bashpip install litmus-screener

Beyond the EU

One risk file, more than one framework.

The EU AI Act is the most mature regime, but its obligations overlap with others. RiskForge emits a per-question reference to two of them in every Article 9 export, so the work you do for Europe carries. The wider US-state landscape we map for context, not as tool output.

RiskForge emits this

Per-question reference in every Art. 9 export

  • RiskForge emits a reference to NIST AI RMF 1.0

    NIST AI RMF 1.0

    VoluntaryClause-level correspondence

    Article 9 · MAP / MEASURE / MANAGE functions

    NIST hosts a crosswalk (Jan 2023, "OECD/EU/EO13960") mapping AI RMF trustworthiness characteristics to the PROPOSED EU AI Act. There is no NIST-authored crosswalk to the final Regulation (EU) 2024/1689; correspondence to the final Act is a clause-level reading, and RiskForge emits a per-question NIST RMF reference.

    NIST AI RMF is voluntary, and the only NIST crosswalk touching the EU AI Act mapped the proposed Act, not the final text. Correspondence to 2024/1689 is analytical, not a NIST endorsement.

    Verified 2026-07-13 · source ↗

  • RiskForge emits a reference to ISO/IEC 42001:2023

    ISO/IEC 42001:2023

    In forceClause-level correspondence

    Article 9 · Clause 6.1 + Clause 8 (AI risk assessment/treatment), Annex A A.6–A.9

    Clause-level correspondence between the Article 9 lifecycle risk-management duty and the ISO/IEC 42001 AI management-system risk clauses. No official ISO-published EU AI Act crosswalk exists; the correspondence is analytical, and RiskForge emits a per-question ISO/IEC 42001 reference.

    ISO/IEC 42001 is a voluntary management-system standard, not law. Clause numbers reflect the 2023 edition; no official ISO crosswalk to the AI Act exists.

    Verified 2026-07-13 · source ↗

Regulatory landscape

Context only · not RiskForge output

RiskForge does not emit these as structured output. They sit here so the US-state picture is honest: one instrument is repealed, the other carries no general risk-management duty.

Colorado AI Act (SB 24-205, repealed)

Repealed / supersededStale, target repealed

The correspondence was to SB 24-205's risk-management and impact-assessment duties. That statute was repealed before taking effect and replaced by SB 26-189 (signed 14 May 2026, effective 1 Jan 2027), which dropped the risk-management and impact-assessment obligations in favour of disclosure/transparency for automated decision-making. The Art. 9/10 risk-management crosswalk no longer holds.

DO NOT assert a live Colorado risk-management crosswalk. SB 24-205 is repealed; successor SB 26-189 has no equivalent risk-management or impact-assessment duty. RiskForge docs still cite the superseded SB 24-205 and a superseded 1 Feb 2026 date.

Verified 2026-07-13 · source ↗

Texas TRAIGA (HB 149)

In forceNominal overlap, no equivalent duty

TRAIGA was enacted as HB 149 (signed 22 Jun 2025, effective 1 Jan 2026). March 2025 amendments scaled it back to prohibitions (behavioural manipulation, discrimination, unlawful deepfakes/CSAM), a regulatory sandbox, and an AI advisory council. It imposes no general risk-management or bias-testing duty, so an Article 9 risk-management crosswalk is nominal, not substantive.

The enacted instrument is HB 149, not the older HB 1709 draft that RiskForge docs still cite. Enacted TRAIGA carries no general risk-management or bias-testing mandate; treat any Article 9 crosswalk as nominal.

Verified 2026-07-13 · source ↗

Cross-mapping ships in RiskForge today; the other tools are EU-article-specific for now. Not a legal-equivalence opinion. Not legal advice. Not a notified body.

The roadmap

What is shipping next, and what is not.

We ship against enforceable obligations, in order, and say so plainly. None of the tools below is available today. Their status is stated exactly as it stands.

Articles 11 + 19Alpha

Agentic Document Analyser

VLM-powered document-to-structured-JSON pipeline for compliance evidence processing.

Technical file + logging extract

Article 102027 · gated

TraceForge

Article 10 training-data governance: dataset lineage and risk registry. Gated 2027 build.

Dataset governance report

Article 13Oct 2026

TransparencyDeck

Article 13 transparency document generator for deployers. Building Oct 2026.

Deployer-facing transparency document

NIST AI RMF ↔ EU AI ActDemand-gated

RMFMapper

NIST AI RMF ↔ EU AI Act cross-mapping matrix. Demand-gated.

Cross-map matrix

ISO 42001Demand-gated

ISOEvidence

ISO/IEC 42001 management-system gap analysis. Demand-gated.

Management-system gap report

Article 72Revisit 2027

VigilanceDash

Article 72 post-market monitoring dashboard. Revisit 2027.

Post-market monitoring feed

Article 4Sep 2026

OrgLiterate

Article 4 AI-literacy evidence CLI. Building now.

Literacy evidence file (JSON / PDF)

Article 43Revisit 2027

ConformityBot

Article 43 conformity-assessment aggregation. Not on the current roadmap.

Conformity-assessment aggregation

Articles 14 + 17Pilots

Sigil

Articles 14 + 17 runtime governance evidence. Design-partner pilots.

Runtime oversight + QMS evidence

MDR + EU AI Act + FDA2028

HealthAI-Comply

MDR + EU AI Act + FDA clinical-AI evidence bundle. 2028 window.

Clinical-AI evidence bundle

Free tools stay Apache 2.0 and open source. Not legal advice. Not a notified body.

These tools answer specific obligations. For programme-level regulatory design across an AI portfolio, the sister practice is at askajay.ai →