SimpleAct Logo
EU AI Act and GDPR in one system

Your AI Act Compliance
Made Simple

SimpleAct connects the EU AI Act and GDPR in one platform: capture, assess, and document AI systems – with governance workflows, incident management, runtime monitoring, and integrations for Jira, Teams, or ServiceNow. AI governance and data protection in one system, audit-ready.

Full documentation
From €159/month (annual billing)
Made in Germany

✓ No credit card required · ✓ Cancel anytime

Copilot, ChatGPT & co. are already in use – mostly uncontrolled.
app.simpleact.de
AI System Name *
e.g. ChatGPT Integration
Provider *
OAIOpenAI
MSMicrosoft
GCGoogle
OTHOther
Decision Role
Supporting
Critical
Risk Level
MINIMAL
Assessment Details
No high-risk or limited-risk trigger detected. Standard documentation applies.
How SimpleAct works

From first system to finished audit report

Three steps. No legal knowledge required. No chaos.

Inventory

4 AI systems

Add
Search system…
AllHigh RiskLimitedMinimal
OAI
MINIMAL

GPT-4 Assistant

OpenAI

INT
HIGH

Candidate Matching

Internal

MS
MINIMAL

Document Analysis

Microsoft

GC
LIMITED

Support-Chatbot

Google

01

Capture all AI systems in one place

No more spreadsheets. Every AI system, every provider, every risk level — central, current and auditable.

< 5 min per system EU AI Act Art. 3 GPAI compliant
  • Add an AI system in < 5 minutes
  • Automatic risk classification (MINIMAL / LIMITED / HIGH)
  • Filter by department, provider and compliance status
System
2
Questions
3
Result
Progress2 / 3

Does the system make HR decisions?

YesNo

Are people automatically assessed?

YesNo

Is there human oversight?

YesNo

Risk Result

Risk Level

HIGH

Assessment Details

System falls under Annex III, Art. 6 EU AI Act.

Action required

02

Classify automatically under EU AI Act

No legal expertise needed. The guided questionnaire translates the AI Act into clear risk decisions.

< 15 min per assessment Art. 6–7 EU AI Act No lawyers needed
  • Questionnaire based on official EU AI Act criteria (Art. 6–7)
  • Automatic risk class with legal rationale
  • Concrete action recommendation per risk level

Dashboard

AI Act 2026

4

Systems

1

High Risk

3/4

Assessed

0%

Compliance

Risk distribution

4 systems
High1
Limited1
Minimal2

Compliance checklist

6 / 6

100% completed ✓

03

Prove compliance at any time

No stress before audits. Your dashboard shows in real time where you stand — and what to do next.

PDF export Audit-ready 1-click report
  • Live status of all AI systems at a glance
  • Progress indicator for your compliance obligations
  • Export as audit report with one click

Documenting AI use is becoming mandatory

The AI Act requires companies to demonstrate where and how AI is used, whether use is permitted, and whether sensitive data is processed – or face significant penalties.

max. fine
€35M

Fines up to €35M – depending on the violation

The AI Act tiers fines by severity: up to 7% of global annual turnover or €35M applies to prohibited practices (Art. 5); most other violations cap at up to 3% or €15M. SMEs get the lower of the applicable thresholds. Proper documentation shows you meet your obligations.

days until Annex III deadline
460 days

High-risk deadline: 2 Dec 2027

The Digital Omnibus (May 2026) shifts Annex III high-risk obligations to 2 December 2027. Start now — building governance structures takes months, not days.

shadow AI without IT approval*
50%

50% use shadow AI without IT knowledge

According to the Software AG Shadow AI Study (2024), 50% of knowledge workers use AI tools without IT approval. What is not captured cannot be documented – and without documentation there is no compliance.

time spent
High

Unstructured capture costs a lot of time

Capturing AI use without a system means: unstructured Excel lists, no systematic risk assessment, no version control. With SimpleAct you avoid these risks.

* Software AG Shadow AI Study 2024, n=6.000 Wissensarbeiter (USA, UK, DE)

AI Check

Am I affected by the EU AI Act?

Answer 5 short questions in under 1 minute and find out whether your company needs AI documentation.

Step 0 of 5

What is your role in the company?

This lets us tailor the results to your situation.

What you’ll get

  • Instant risk classification
    Are you affected by the EU AI Act – and at which risk level?
  • Steps tailored to your role
    Concrete recommendations for Compliance, IT, Legal or Management.
  • In under a minute, no sign-up
    5 quick questions – that’s it.
Example result
High-risk AI

→ Create an AI inventory and document your high-risk systems.

Which systems count as high-risk (Annex III) →

⚖️ This check is not legal advice. If in doubt we recommend legal review.

Why SimpleAct

EU AI Act and GDPR are one system, not two projects

Most tools do either AI governance or data protection. With SimpleAct, one captured AI system triggers both sides automatically – all tied to a single audit trail.

One entry

Capture one AI system

Name, vendor, purpose, affected areas, responsible person – entered once.

EU AI Act
  • Rule-based risk class
  • Compliance checklist per class
  • Annex IV documentation
GDPR
  • DPIA relevance detected
  • Entry in the record of processing
  • TOMs & data subject rights linked
Audit-ready

Connected through governance

Owners, reviews, approvals, and a gap-free audit log span both sides – one body of evidence instead of two separate stacks.

0 entries in the shared audit trail

That is the difference: competitors document AI or data protection. SimpleAct shows the link between the two – exactly where authorities and audits look.

See how the platform works
Pricing

EU AI Act and GDPR in one system

One platform instead of two tools: Starter covers the EU AI Act, and from Professional onwards GDPR is included. Enterprise adds security, integrations, and organisational rollouts.

Starter

For smaller companies and first AI governance processes

EU AI Act
159/month

billed annually

Start with EU AI Act

GDPR can be added later

  • Up to 5 AI systems & 3 users
  • AI inventory
  • Risk classification
  • Compliance checklists
  • Annex IV documentation
  • Reporting
Recommended

Professional

For multiple teams and real governance requirements

EU AI ActGDPRGovernanceAudit Readiness
279/month

billed annually

Start Professional

GDPR included from here

  • Everything in Starter
  • Vendor register, model registry, and APIs
  • Governance workflows and audit readiness score
  • DSR, DPA, TOMs, and privacy notices
  • Register export and more operational depth

Enterprise

For complex compliance, governance, and security requirements

Everything in ProfessionalSSO / SAMLEnterprise SecurityCustom Requirements
On request

Contact us
  • SSO / SAML and LDAP
  • DPO management and third-country transfers
  • Authority packages and escalation workflows
  • Custom integrations and priority support
  • Onboarding workshops and custom SLAs

Starter can later be expanded to Professional or Enterprise. GDPR is included from Professional onwards.

30 days free

Trial

For a fast product check

  • Full Starter onboarding
  • Real data & real workflows
  • 30 days access
  • No setup fee
  • No credit card required
Start 30-day trial
Pilot project

Guided Pilot Project

Pilot projects are enabled individually and after the period either transition into a regular subscription or end cleanly.

See pilot project
Trust & security

Your data is safe with us

As a German company we take data protection and security seriously. Made in Germany means the highest standards with no compromise.

Security & Infrastructure

Data in Germany

All your data is stored exclusively on German servers in Nuremberg. Backups are held in Falkenstein (Hetzner). No cloud providers outside the EU.

Enterprise-grade security

Encryption at rest and in transit, plus regular security reviews for the highest data security.

Data protection expertise

Our team has experience in data protection (GDPR) and AI governance.

German quality

Developed and hosted in Germany with a focus on data protection and reliability.

New on the blog

Latest developments around the EU AI Act

Fresh updates on the EU AI Act, AI compliance, and practical implementation guidance.

Ein KI-System, zwei Register: Warum KI-Inventar und Verarbeitungsverzeichnis zusammengehören
Dokumentation

Ein KI-System, zwei Register: Warum KI-Inventar und Verarbeitungsverzeichnis zusammengehören

Jedes KI-System, das personenbezogene Daten verarbeitet, muss in zwei Verzeichnissen auftauchen: im KI-Inventar nach EU AI Act und im Verarbeitungsverzeichnis nach Art. 30 DSGVO. In der Praxis pflegen Unternehmen beide getrennt, oft in unterschiedlichen Abteilungen und in unterschiedlichen Tabellen. Das Ergebnis sind doppelte Erfassung, widersprüchliche Angaben und ein Datenschutzbeauftragter, der von der Hälfte der eingesetzten Systeme nichts weiß.

August 13, 20266 min
Read post
Frequently asked questions

Everything you need to know about AI documentation

The most important questions on the documentation obligation, AI capture, and SimpleAct answered.

The AI Act requires companies to demonstrate which AI systems they use, whether sensitive data is processed, and whether AI makes or supports decisions. Transparency obligations (Art. 50) apply from 2 August 2026; Annex III high-risk documentation is mandatory by 2 December 2027 (Digital Omnibus, May 2026).
Fines are tiered by severity: up to 7% of global annual turnover or €35M for prohibited practices (Art. 5), up to 3% or €15M for most other violations — SMEs get the lower of the applicable thresholds. Audits and reputational risk are also possible. With SimpleAct you create the required evidence in a structured way.
With SimpleAct: 2–3 hours for the first capture of all AI systems, then continuous maintenance. Without a tool: weeks or months with unstructured Excel lists. Time savings come from structured capture and rule-based assessment.
Under the EU AI Act, AI systems are classified into three risk classes: Minimal Risk (basic documentation, privacy alignment), Limited Risk (transparency obligations, content labelling), and High Risk (full checklist with risk management, data governance, technical documentation, human oversight). SimpleAct classifies each system rule-based via a structured questionnaire in 3 sections: Section A (high-risk triggers), Section B (limited-risk triggers), Section C (context).
Exclusively in Germany: servers in Nuremberg, backups in Falkenstein (Hetzner). We do not use US or non-European cloud providers. GDPR-oriented hosting from day one, encryption at rest and in transit for all data.

More questions? We're happy to help.

Book your personal demo

Pick a slot right here – we’ll confirm by email with a calendar invite.

Week 35

Mon, 08/24/2026Fri, 08/28/2026

Mon

24.08.

Tue

25.08.

Wed

26.08.

Thu

27.08.

Fri

28.08.

Please pick a slot above.

Struck-through times are already booked. Times in your local timezone – we’ll confirm by email.

SimpleAct - EU AI Act & GDPR Compliance in One System