SimpleAct Logo
Why SimpleAct

Your compliance problems — concretely solved

Many companies don't know which AI systems they use, how risky they are, or how to prove it to regulators. SimpleAct solves exactly that.

No overview of your AI systems?

SimpleAct centrally captures all AI systems in use: name, provider, description, category (internal/external), role, purposes, affected areas, responsible person. One place for everything — no more spreadsheet chaos.

Unsure which risk class a system falls into?

A structured questionnaire guides you through the assessment and automatically classifies each AI system under the EU AI Act — no legal knowledge needed. Re-assess at any time when things change.

Regulators want evidence — you have none?

Compliance checklists per risk class with EU AI Act article references, a complete audit log with timestamps, and an exportable compliance report with versioning. Audit-ready at the click of a button.

Documentation takes too long?

Structured templates for organisation profile, systems, risk assessment and checklists — SimpleAct walks you through step by step. What used to take days now takes hours.

Free

One-off self-assessment

  • One-time risk assessment
  • No data storage
  • No versioning
  • No team access
  • No export
  • No updates on changes
  • No regulatory evidence
  • No incident management
  • No integrations

SimpleAct Platform

A one-off assessment is a good start. SimpleAct turns it into a permanent, auditable system – for EU AI Act and GDPR.

How it works

EU AI Act compliance in 5 steps

From capture to auditable evidence – and beyond: governance workflows, runtime monitoring, and incident management as your permanent operating system for your AI stack.

01

Login and setup

Sign up and enter basic company data and the person responsible for your AI compliance management.

  • Quick registration and setup
  • Enter company data
  • Designate responsible person
02

Capture AI systems

Enter all AI tools in use: ChatGPT, VS Code AI, Canva AI, internal applications. Capture takes only 1–2 minutes per system.

  • Simple capture of name, provider, and purpose
  • Document scope of use (internal/external)
  • Capture takes only 1–2 minutes per system
03

Assess risk

Answer guided questions about your AI system. Based on your answers, the system automatically determines the appropriate risk class – no legal expertise required.

  • Guided questions on risk factors and context
  • Automatic classification under EU AI Act
  • Versioning for repeat assessments
  • No legal interpretation required
04

Complete compliance checklist

Depending on risk class, a specific compliance checklist is shown: Minimal Risk (basic documentation), Limited Risk, High Risk. Each checklist includes EU AI Act article references.

  • Minimal Risk: Basic documentation and privacy alignment
  • Limited Risk: Transparency obligations and content labelling
  • High Risk: Full checklist with Art. 9–14 references
  • Additional documentation for high-risk systems possible
05

Operational governance

After setup, the real governance begins: dashboard, audit playbook, incident management with CAPA, runtime monitoring with signals and change register, assurance workflows with bias findings and validation suites – all connected, all audit-ready.

  • Dashboard overview of all AI systems and status
  • Incident management: CAPA, re-assessment triggers, authority responses
  • Runtime monitoring: signals, change register, observability profiles
  • Assurance: bias findings, validation suites, human oversight
  • Integrations: Jira, Teams, ServiceNow, API keys, webhooks
First full documentation in
2–3 hours

Quick onboarding – then governance, monitoring, and incident management run permanently as your AI operating system

Get started
Frequently asked questions

Everything you need to know about AI documentation

The most important questions on the documentation obligation, AI capture, and SimpleAct answered.

Most companies have no overview of which AI systems are in use, no defensible evidence for audits, and no time for manual documentation in spreadsheets. SimpleAct solves exactly these three problems with structured capture, rule-based assessment, and exportable reports.
No. The legal logic is built into the tool and guides you through a structured questionnaire to a risk classification. SimpleAct does not replace individual legal advice for specific cases.
That is exactly what SimpleAct is for. Start with the inventory – even an incomplete inventory is better than none and demonstrates regulatory intent. A step-by-step approach works fine.
Both. SimpleAct connects the EU AI Act and GDPR in one system, since the two frameworks already overlap for AI systems involving personal data – for example DPIAs for high-risk AI.

More questions? We're happy to help.

The Solution for EU AI Act & GDPR Compliance | SimpleAct