Documentation · FAQ · Transparency
The project, explained honestly
ComplyAI is a free suite of compliance tools for European SMEs, in beta, built in public on a zero budget. This page explains how it really works, what it cannot do, and where to find more mature tools. If a compliance tool is not transparent about itself, why would you trust what it says about your obligations?
How it works
Six integrated modules, one underlying rule: never fake it. Every result says where it comes from (article of law, library pattern, or declared AI), and when something is not ready, we say so.
Design principles
Deterministic first, AI second
The AI Act classification is a rules engine with precise citations (no hallucinations on the law). AI (Mistral, EU) steps in only where needed — policy and contract analysis — always declared, always with a local fallback that sends nothing to third parties.
Your data stays yours
Database in the EU (Frankfurt) with per-user isolation (RLS). Contract text extraction happens in your browser; we store the review memo, not the contract. The AI provider is configured with training opt-out. No ads, no data resale.
Everything tracked, nothing erasable
Every action on your data lands in an append-only audit log that neither we (nor you) can alter: the same integrity guarantee you would demand from a supplier in a real audit.
Up to date, and dated
Regulatory content is versioned and reflects the 2026 Digital Omnibus, with explicit warnings where new dates await the Official Journal. The regulatory radar checks official EU sources daily.
The six modules
- AI Act Compliance Checker →
Guided questionnaire → risk classification with citations, obligations checklist, gaps and action plan. No sign-up needed.
- Regulation Watcher →
Daily radar on the EU Official Journal, Commission/AI Office and EDPB, with deterministic tags. No generated summaries: original titles and links.
- Policy-to-Controls Mapper →
From a policy to a matrix of operational controls (owner, cadence, evidence), with optional AI analysis and a full editor.
- Contract Review Agent →
Upload a contract (text is extracted in your browser), get risky clauses, missing protections and key dates to send to the tracker.
- Legal Deadline Tracker →
Deadline tracker with automatic states and .ics export to your calendar.
- Audit Trail Builder →
Browse, filter and export the immutable log of all actions, ready for an external auditor.
Frequently asked questions
Is ComplyAI free? What's the catch?
It is free and there is no catch, there is a constraint: the project is built entirely on free-tier services (hosting, database, AI) and says so. We do not sell data or show ads. If a paid plan ever existed, this version would remain honestly labelled for what it is.
Are the Checker's results legal advice?
No. The Checker applies deterministic rules derived from the AI Act text and always cites the reference article, but the outcome depends on your answers and the law evolves. Decisions with legal effects require a qualified professional: the report is designed to be brought to an advisor, not to replace one.
What happens to my data and contracts?
Saved data (account and content you choose to save) lives in an EU database, isolated per user. Uploaded contracts are read in your browser: text reaches the server only if you choose AI analysis, and we store the review memo, not the contract. The configured AI (Mistral, EU) has training opt-out enabled. Every change is tracked in an immutable log.
Do I need to sign up?
No: the Checker, the radar and local analyses work without an account. Registration (just email and password) is for saving assessments, deadlines and memos, and for AI analysis, whose free quota is shared among users.
How reliable are the analyses?
It differs by engine. The Checker's rules are tested and cited, but they simplify complex articles. The clause library recognises explicit patterns and can miss atypical wording (which is why 'not found' does not mean 'absent'). AI analysis can be wrong, and we say so under every result. In beta, the right reliability to assume is: an excellent starting point, never the last word.
Are you updated to the 2026 Digital Omnibus?
Yes: deadlines reflect the deferral of high-risk obligations (Annex III → 2 December 2027, Annex I → 2 August 2028) and flag with an asterisk what awaits publication in the Official Journal. The transparency obligation (Art. 50) was not postponed and remains 2 August 2026. The regulatory radar alerts us when something changes.
Who is behind the project?
Giacomo Fedeli, a data analyst, building it in public as a real product and a learning journey, assisted by AI development tools. The code is open on GitHub: you can verify every claim on this page by reading it.
Can I use the reports with my accountant, DPO or lawyer?
Yes, that is what they are for: every module exports (PDF, CSV, JSON, .ics) and the audit log is exportable for external auditors. Bringing your advisor a structured analysis saves time for both of you.
Why should I trust a beta tool?
You should not trust — you should be able to verify. That is why the code is public, legal sources are cited line by line, limits are written on this page, and more mature tools are listed below. Blind trust is exactly what a compliance tool should never ask of you.
I found a bug or have an idea: how do I contribute?
Message me on LinkedIn (link below) or open an issue on GitHub. Reports of legal/regulatory errors are the most valuable of all: they will be checked against the sources and fixed, with a mention in the decision log.
More complete alternatives (seriously)
ComplyAI is a zero-budget beta: more mature, complete and supported tools exist. Here are some, with no affiliation whatsoever. If your case is critical, start here — especially with the official sources, which are free:
Official and free sources (start here)
- AI Act Service Desk — European Commission ↗
The official EU Compliance Checker, the AI Act Explorer and the helpdesk: free and authoritative by definition.
- EU AI Act Compliance Checker — Future of Life Institute ↗
A widely cited free checker, on the same site publishing the AI Act text and analyses.
- EUR-Lex ↗
The official text of the law, with free email alerts and RSS: the primary source every tool (including ours) should cite.
AI governance platforms (enterprise)
- Credo AI ↗
End-to-end AI governance, policy packs for the AI Act and standards (e.g. ISO/IEC 42001).
- Holistic AI ↗
Large-scale AI risk assessment, audits and continuous monitoring.
- OneTrust ↗
Broad GRC suite (privacy, AI governance, third parties) widely used by large companies.
- trail ↗
European AI governance with a free AI Act checker and automated technical documentation.
Certifications and automated GRC
Professional contract review
- Luminance ↗
Legal AI for contract review and negotiation, used by firms and companies.
- Juro ↗
Full contract lifecycle management with built-in AI.
- Spellbook ↗
AI contract drafting assistant, inside Word.
And the best alternative of all remains human: a lawyer, a DPO or an advisor who knows your business. No software — least of all this one — replaces that.
Contribute or get in touch
Suggestions, bug reports (especially legal/regulatory ones), ideas, honest criticism: everything is welcome. The project is open and under development — and the best way to build it is a conversation.
ComplyAI provides informational compliance support and does not constitute legal advice. Trademarks belong to their respective owners; links to alternatives are provided for information, with no affiliation or compensation.