The toolchain
Four tools. One connected evidence file.
Each tool answers one EU AI Act article and emits one named artefact. They hand those artefacts to each other, and to your Annex IV technical file. Free, Apache 2.0, runs locally, zero telemetry.
bashpip install riskforge litmus-screenerFour tools live on PyPI today · more building across 2026–2027. Not legal advice. Not a notified body.
The audit workflow
One tool per article. The artefact is the proof.
Each tool answers one obligation and hands the next tool a real file. Run them in order and the evidence pack assembles itself.
Art. 4 and Art. 13 tools join the chain as they ship. The full 14-tool catalogue lives on the tools page.
Live now · v1.0 on PyPI
The four tools, in detail.
Each maps to one EU AI Act obligation and produces a named artefact: an SBOM, a Risk Management File, a benchmark report, a prohibited-practice verdict. Install one, or the set.
License Compliance Checker
Article 53 requires model documentation. Scan the repo; the licence and training-data report comes out.
Regulatory relevance
GPAI Compliance · Generates audit evidence supporting EU AI Act Article 53 documentation obligations: evaluates model card completeness, license compliance, and training data risk for AI components in your stack.
bashpip install license-compliance-checkerRiskForge
Article 9 requires a documented risk management system. 37 guided questions produce the file, no consultants, ~30 minutes.
Regulatory relevance
Risk Management · Produces structured Article 9 Risk Management Files for high-risk AI systems suitable for inclusion in your Annex IV technical documentation pack. Organises the assessment across 8 risk dimensions derived across Articles 9, 10, 13, 14 and 15 (health & safety, fundamental rights, discrimination, privacy, transparency, human oversight, robustness, and data governance), with cross-maps to NIST AI RMF and ISO/IEC 42001. Not a substitute for notified-body conformity assessment.
bashpip install riskforgeRAG Benchmarking
Article 15 requires declared accuracy and robustness. Benchmark the system; the metrics report comes out.
Regulatory relevance
Accuracy Requirements · Provides systematic accuracy testing and documentation for high-risk AI systems under Article 15.
bashpip install rag-benchmarkingLitmusAI
Article 5 prohibits eight AI practices. Screen the system; a per-prohibition verdict comes out.
Regulatory relevance
Prohibited Practices · Screens AI systems against the eight prohibited-practice categories of EU AI Act Article 5(1)(a)–(h). Conservative-by-default verdicts; UNREVIEWED reference ruleset (no external lawyer review yet); BYO signed-ruleset path for customers who need lawyer-reviewed output today. Article 5 has been applicable since 2 February 2025 (Art. 113(a)); sanctionable since 2 August 2025 (Art. 113(b)).
bashpip install litmus-screenerBeyond the EU
One risk file, more than one framework.
The EU AI Act is the most mature regime, but its obligations overlap with others. RiskForge emits a per-question reference to two of them in every Article 9 export, so the work you do for Europe carries. The wider US-state landscape we map for context, not as tool output.
Per-question reference in every Art. 9 export
- RiskForge emits a reference to NIST AI RMF 1.0
NIST AI RMF 1.0
VoluntaryClause-level correspondenceArticle 9 · MAP / MEASURE / MANAGE functions
NIST hosts a crosswalk (Jan 2023, "OECD/EU/EO13960") mapping AI RMF trustworthiness characteristics to the PROPOSED EU AI Act. There is no NIST-authored crosswalk to the final Regulation (EU) 2024/1689; correspondence to the final Act is a clause-level reading, and RiskForge emits a per-question NIST RMF reference.
NIST AI RMF is voluntary, and the only NIST crosswalk touching the EU AI Act mapped the proposed Act, not the final text. Correspondence to 2024/1689 is analytical, not a NIST endorsement.
Verified 2026-07-13 · source ↗
- RiskForge emits a reference to ISO/IEC 42001:2023
ISO/IEC 42001:2023
In forceClause-level correspondenceArticle 9 · Clause 6.1 + Clause 8 (AI risk assessment/treatment), Annex A A.6–A.9
Clause-level correspondence between the Article 9 lifecycle risk-management duty and the ISO/IEC 42001 AI management-system risk clauses. No official ISO-published EU AI Act crosswalk exists; the correspondence is analytical, and RiskForge emits a per-question ISO/IEC 42001 reference.
ISO/IEC 42001 is a voluntary management-system standard, not law. Clause numbers reflect the 2023 edition; no official ISO crosswalk to the AI Act exists.
Verified 2026-07-13 · source ↗
Context only · not RiskForge output
RiskForge does not emit these as structured output. They sit here so the US-state picture is honest: one instrument is repealed, the other carries no general risk-management duty.
Colorado AI Act (SB 24-205, repealed)
The correspondence was to SB 24-205's risk-management and impact-assessment duties. That statute was repealed before taking effect and replaced by SB 26-189 (signed 14 May 2026, effective 1 Jan 2027), which dropped the risk-management and impact-assessment obligations in favour of disclosure/transparency for automated decision-making. The Art. 9/10 risk-management crosswalk no longer holds.
DO NOT assert a live Colorado risk-management crosswalk. SB 24-205 is repealed; successor SB 26-189 has no equivalent risk-management or impact-assessment duty. RiskForge docs still cite the superseded SB 24-205 and a superseded 1 Feb 2026 date.
Verified 2026-07-13 · source ↗
Texas TRAIGA (HB 149)
TRAIGA was enacted as HB 149 (signed 22 Jun 2025, effective 1 Jan 2026). March 2025 amendments scaled it back to prohibitions (behavioural manipulation, discrimination, unlawful deepfakes/CSAM), a regulatory sandbox, and an AI advisory council. It imposes no general risk-management or bias-testing duty, so an Article 9 risk-management crosswalk is nominal, not substantive.
The enacted instrument is HB 149, not the older HB 1709 draft that RiskForge docs still cite. Enacted TRAIGA carries no general risk-management or bias-testing mandate; treat any Article 9 crosswalk as nominal.
Verified 2026-07-13 · source ↗
Cross-mapping ships in RiskForge today; the other tools are EU-article-specific for now. Not a legal-equivalence opinion. Not legal advice. Not a notified body.
The roadmap
What is shipping next, and what is not.
We ship against enforceable obligations, in order, and say so plainly. None of the tools below is available today. Their status is stated exactly as it stands.
Agentic Document Analyser
VLM-powered document-to-structured-JSON pipeline for compliance evidence processing.
Technical file + logging extract
TraceForge
Article 10 training-data governance: dataset lineage and risk registry. Gated 2027 build.
Dataset governance report
TransparencyDeck
Article 13 transparency document generator for deployers. Building Oct 2026.
Deployer-facing transparency document
RMFMapper
NIST AI RMF ↔ EU AI Act cross-mapping matrix. Demand-gated.
Cross-map matrix
ISOEvidence
ISO/IEC 42001 management-system gap analysis. Demand-gated.
Management-system gap report
VigilanceDash
Article 72 post-market monitoring dashboard. Revisit 2027.
Post-market monitoring feed
OrgLiterate
Article 4 AI-literacy evidence CLI. Building now.
Literacy evidence file (JSON / PDF)
ConformityBot
Article 43 conformity-assessment aggregation. Not on the current roadmap.
Conformity-assessment aggregation
Sigil
Articles 14 + 17 runtime governance evidence. Design-partner pilots.
Runtime oversight + QMS evidence
HealthAI-Comply
MDR + EU AI Act + FDA clinical-AI evidence bundle. 2028 window.
Clinical-AI evidence bundle
Free tools stay Apache 2.0 and open source. Not legal advice. Not a notified body.
These tools answer specific obligations. For programme-level regulatory design across an AI portfolio, the sister practice is at askajay.ai →