EU AI Act and GDPR in one system

Your AI Act Compliance
Made Simple

SimpleAct connects the EU AI Act and GDPR in one platform: capture, assess, and document AI systems – with governance workflows, incident management, runtime monitoring, and integrations for Jira, Teams, or ServiceNow. AI governance and data protection in one system, audit-ready.

Full documentation
From €159/month (annual billing)
Made in Germany

✓ No credit card required · ✓ Cancel anytime

Copilot, ChatGPT & co. are already in use – mostly uncontrolled.
app.simpleact.de
AI System Name *
e.g. ChatGPT Integration
Provider *
OAIOpenAI
MSMicrosoft
GCGoogle
OTHOther
Decision Role
Supporting
Critical
Risk Level
MINIMAL
Assessment Details
No high-risk or limited-risk trigger detected. Standard documentation applies.
How SimpleAct works

From first system to finished audit report

Three steps. No legal knowledge required. No chaos.

Inventory

4 AI systems

Add
Search system…
AllHigh RiskLimitedMinimal
OAI
MINIMAL

GPT-4 Assistant

OpenAI

INT
HIGH

Candidate Matching

Internal

MS
MINIMAL

Document Analysis

Microsoft

GC
LIMITED

Support-Chatbot

Google

01

Capture all AI systems in one place

No more spreadsheets. Every AI system, every provider, every risk level — central, current and auditable.

< 5 min per system EU AI Act Art. 3 GPAI compliant
  • Add an AI system in < 5 minutes
  • Automatic risk classification (MINIMAL / LIMITED / HIGH)
  • Filter by department, provider and compliance status
System
2
Questions
3
Result
Progress2 / 3

Does the system make HR decisions?

YesNo

Are people automatically assessed?

YesNo

Is there human oversight?

YesNo

Risk Result

Risk Level

HIGH

Assessment Details

System falls under Annex III, Art. 6 EU AI Act.

Action required

02

Classify automatically under EU AI Act

No legal expertise needed. The guided questionnaire translates the AI Act into clear risk decisions.

< 15 min per assessment Art. 6–7 EU AI Act No lawyers needed
  • Questionnaire based on official EU AI Act criteria (Art. 6–7)
  • Automatic risk class with legal rationale
  • Concrete action recommendation per risk level

Dashboard

AI Act 2026

4

Systems

1

High Risk

3/4

Assessed

78%

Compliance

Risk distribution

4 systems
High1
Limited1
Minimal2

Compliance checklist

6 / 6

100% completed ✓

03

Prove compliance at any time

No stress before audits. Your dashboard shows in real time where you stand — and what to do next.

PDF export Audit-ready 1-click report
  • Live status of all AI systems at a glance
  • Progress indicator for your compliance obligations
  • Export as audit report with one click

Documenting AI use is becoming mandatory

The AI Act requires companies to demonstrate where and how AI is used, whether use is permitted, and whether sensitive data is processed – or face significant penalties.

max. fine
€0M

Fines up to €35M avoidable

With proper documentation you stay on the safe side. Without proof, fines of up to 7% of global annual turnover (max. €35M) can be imposed. With SimpleAct you avoid these risks.

days until Annex III deadline
0 days

High-risk deadline: 2 Dec 2027

The Digital Omnibus (May 2026) shifts Annex III high-risk obligations to 2 December 2027. Start now — building governance structures takes months, not days.

shadow AI without IT approval*
0%

50% use shadow AI without IT knowledge

According to the Software AG Shadow AI Study (2024), 50% of knowledge workers use AI tools without IT approval. What is not captured cannot be documented – and without documentation there is no compliance.

time spent
High

Unstructured capture costs a lot of time

Capturing AI use without a system means: unstructured Excel lists, no systematic risk assessment, no version control. With SimpleAct you avoid these risks.

* Software AG Shadow AI Study 2024, n=6.000 Wissensarbeiter (USA, UK, DE)

AI Check

Am I affected by the EU AI Act?

Answer 5 short questions in under 1 minute and find out whether your company needs AI documentation.

Step 0 of 5

What is your role in the company?

This lets us tailor the results to your situation.

What you’ll get

  • Instant risk classification
    Are you affected by the EU AI Act – and at which risk level?
  • Steps tailored to your role
    Concrete recommendations for Compliance, IT, Legal or Management.
  • In under a minute, no sign-up
    5 quick questions – that’s it.
Example result
High-risk AI

→ Create an AI inventory and document your high-risk systems.

⚖️ This check is not legal advice. If in doubt we recommend legal review.

Why SimpleAct

EU AI Act and GDPR are one system, not two projects

Most tools do either AI governance or data protection. With SimpleAct, one captured AI system triggers both sides automatically – all tied to a single audit trail.

One entry

Capture one AI system

Name, vendor, purpose, affected areas, responsible person – entered once.

EU AI Act
  • Rule-based risk class
  • Compliance checklist per class
  • Annex IV documentation
GDPR
  • DPIA relevance detected
  • Entry in the record of processing
  • TOMs & data subject rights linked

Connected through governance

Owners, reviews, approvals, and a gap-free audit log span both sides – one body of evidence instead of two separate stacks.

That is the difference: competitors document AI or data protection. SimpleAct shows the link between the two – exactly where authorities and audits look.

See how the platform works
Pricing

EU AI Act and GDPR in one system

One platform instead of two tools: Starter covers the EU AI Act, and from Professional onwards GDPR is included. Enterprise adds security, integrations, and organisational rollouts.

Starter

For smaller companies and first AI governance processes

EU AI Act
159/month

billed annually

Start with EU AI Act

GDPR can be added later

  • AI inventory
  • Risk classification
  • Compliance checklists
  • Annex IV documentation
  • Reporting
Recommended

Professional

For multiple teams and real governance requirements

EU AI ActGDPRGovernanceAudit Readiness
279/month

billed annually

Start Professional

GDPR included from here

  • Everything in Starter
  • Vendor register, model registry, and APIs
  • Governance workflows and audit readiness score
  • DSR, DPA, TOMs, and privacy notices
  • Register export and more operational depth

Enterprise

For complex compliance, governance, and security requirements

Everything in ProfessionalSSO / SAMLEnterprise SecurityCustom Requirements
On request

Contact us
  • SSO / SAML and LDAP
  • DPO management and third-country transfers
  • Authority packages and escalation workflows
  • Custom integrations and priority support
  • Onboarding workshops and custom SLAs

Starter can later be expanded to Professional or Enterprise. GDPR is included from Professional onwards.

30 days free

Trial

For a fast product check

  • Full Starter onboarding
  • Real data & real workflows
  • 30 days access
  • No setup fee
  • No credit card required
Start 30-day trial
Pilot project

Guided Pilot Project

Pilot projects are enabled individually and after the period either transition into a regular subscription or end cleanly.

See pilot project
Trust & security

Your data is safe with us

As a German company we take data protection and security seriously. Made in Germany means the highest standards with no compromise.

Security & Infrastructure

GDPR-oriented

European data protection

Made in Germany

German quality

Data in Germany

All your data is stored exclusively on German servers in Nuremberg. Backups are held in Falkenstein (Hetzner). No cloud providers outside the EU.

Enterprise-grade security

Encryption at rest and in transit, plus regular security reviews for the highest data security.

Data protection expertise

Our team has experience in data protection (GDPR) and AI governance.

German quality

Developed and hosted in Germany with a focus on data protection and reliability.

New on the blog

Latest developments around the EU AI Act

Fresh updates on the EU AI Act, AI compliance, and practical implementation guidance.

Get the full picture of your AI

In a short demo we show how to build your AI inventory, classify risk and document it audit-ready – tailored to your situation.

Made in Germany · EU hosting · no credit card

Yannick Heisler

Yannick Heisler

Sales · Personal consultation

SimpleAct - EU AI Act & GDPR Compliance in One System