Finds every place you run AI, and what each one now obliges you to do
The EU AI Act's duties fall on the companies deploying AI, not only on the labs building it, and they phase in through 2026. Most companies running AI in production cannot say where they run it, what it decides, or whether any of it falls into a prohibited category.
The usual answer is a consultancy engagement or a checklist. Neither can tell you what you actually operate. This works from your own descriptions of your own systems — what each one does, what it decides, whose data it touches, whether a person reviews the output — and produces the register that every obligation starts from.
For each system it reports what the description suggests: whether a use appears prohibited, whether it appears to touch a high-risk area such as employment, credit or essential services, what transparency the deployment would owe, and where human oversight is claimed but not evidenced. It reaches no legal conclusion. Classification is a determination a lawyer signs, and a tool that announced it would be selling you a liability.
Usually more systems than anyone expected.
Those are not deadlines. They are stop signs.
Counsel reads a register rather than interviewing everyone.
Every obligation starts from a list of what you run. Almost no company has one.
Not by which model it calls. What it decides about a person is the thing the rules turn on.
Some practices are not a compliance burden but a ban. Those are reported before anything else.
"A human reviews it" is the commonest control asserted and the least often documented — and an assertion is not a control.
Telling people they are dealing with a system, and labelling generated content.
Risk classification is a legal determination. It gathers what a lawyer needs and refuses to pre-empt them.
Why Compliance & Risk in particular. The duties fall on companies deploying AI, not only the labs, and they phase in through 2026. Most companies cannot say what they run — and some of what they built is not a compliance burden but a ban.
Runs unattended
Started by you or by an event, and it finishes on its own. Nothing waits for someone to be at a desk.
The same standard every time
The two-hundredth item is held to the bar the first one was. Consistency is the part people cannot sustain.
It cannot act on its own
AI Use Register & Readiness Agent has no path to sending, spending or committing. That limit is why its output is safe to act on.
This agent runs server-side through the PROMIVO runtime. Each run is logged step by step and every tool call is permission-checked before it executes.
Read-only by design. This agent has no path to sending, spending, publishing or committing anything. Where that limit is the product, removing it would remove the reason to trust the output.
Demo dataIllustrative sample output, abridged.
{
"markets": [
"EU"
],
"systems": [],
"organisation": "Northwind"
}{
"escalate": true,
"register": [
{
"system": "Applicant ranking assistant",
"decides": "Orders candidates for a recruiter to review.",
"forLawyer": [
"Whether ordering candidates constitutes a decision in employment for classification purposes.",
"Whether the recruiter's review meets oversight requirements — no record shows who reviews or whether they may overturn the order."
],
"oversightEvidenced": "asserted-only",
"transparencyDuties": [
"Candidates are not told a system is involved anywhere in the described process."
],
"needsClassification": true
}
],
"disclaimer": "A register and an obligations map from your own descriptions. Not legal advice, no classification has been made, and nothing here states the organisation is compliant.",
"frameworkFound": true,
"escalationReason": "A system decides in an employment context and its human oversight is asserted without evidence.",
"undescribedSystems": [
"Your support description mentions 'the bot' answering customers, which is not in the register."
],
"apparentlyProhibited": []
}No integrations required.
From scattered descriptions into one list.
What it would oblige you to do, before it exists.
Enterprise diligence now asks this, and blank is a bad answer.
$399/month
Billed monthly through your PROMIVO subscription. Cancel at any time.
Runs consume your plan allowance for agent executions and tokens. See plan limits.
No. That is a legal classification with substantial consequences and a lawyer signs it. It reports what your description suggests and gathers what counsel needs to decide, which is where most of the time goes anyway.
No. It works from your descriptions and the framework text you load, and routes every judgement. Obligations differ by role, jurisdiction and date, and it does not interpret them.
If you offer a system to people in the EU, or its output is used there, it can reach you. It reports what your description suggests and flags where your market needs checking — it does not decide jurisdiction.
No reviews yet. Reviews open once customers have run this agent.
Tell us what to change and our team will scope a customised version for your business.
Customize this agent