Skip to main content

The EU AI Act, mapped to your codebase

Static analysis across 10+ programming languages, document checks in 8 EU languages, and a first-draft compliance dossier in minutes — every finding anchored to a specific article of Regulation (EU) 2024/1689. Review and finalize with your legal team.

  • 100 actionable EU AI Act obligations mapped
  • 66 automated checks, 34 guided assessments
  • Every finding cites article, paragraph, and point
Scanara scan report for an example AI system: compliance grade, findings by severity, and EU AI Act article checks

Example scan: open-source loan-default prediction model (limited risk, GPAI obligations)

Articles
113
Languages
10+
EU languages
8
First results
5 min

The EU AI Act is enforceable August 2, 2026. GPAI obligations are already live. Most teams aren't ready.

1

No AI inventory

Over half of organizations lack a systematic AI system inventory — they don't even know what needs to comply.

2

No documentation

40–80 hours per AI system for Annex IV documentation from scratch — and that's just one system.

3

97% non-compliant

97% of the open-source AI codebases we scanned in our benchmark show compliance gaps against EU AI Act requirements. The issue isn't capability — it's awareness.

Fines up to €35,000,000 or 7% of global turnover (Article 99) — but the real cost is lost EU market access.

EU AI Act enforcement beganAugust 2, 2026

Every day non-compliant is a day of liability.

One platform from repository to audit-ready dossier Three inputs, one compliance picture.

Static code scanning

Scanning rules detect EU AI Act-relevant patterns directly in your source repositories — across 10+ programming languages, mapped to specific articles.

Document policy checks

A policy engine evaluates your technical documentation in 8 EU languages against the obligations of your risk tier.

Structured assessments

Guided questionnaires cover what code can't show: Annex III high-risk screening (AIRA), FRIA, DPIA, GPAI provider, deployer, and prohibited-practice screening.

The result: a defensible compliance dossier

A risk classification across all four tiers — including GPAI and systemic-risk models — and a compliance dossier with Annex IV technical documentation, Annex XI, and Declaration of Conformity. Fields are auto-populated from scan and assessment data wherever possible, the remaining evidence is authored in-platform, and the finished dossier exports as PDF, DOCX, HTML, or Markdown.

Manual conformity cycles cost €50,000–€200,000 per AI system. Scanara reduces that by an order of magnitude.

From code to compliance dossier in four steps

Step 1

Risk classification

Automatic risk classification for your GitHub repository. You can view the detected indicators and change or confirm the classification.

Risk classification dialog for a GitHub repository suggesting a risk level, with GPAI detection
Step 2

Connect

Create an AI System and link all your repositories. The AI Systems will be risk classified automatically.

Scanara AI system overview with linked repository, risk classification, and required obligations
Step 3

Scan

Dual-engine scanning: static analysis for code across 10+ languages, policy engine for documents in 8 EU languages. Every finding maps to a specific EU AI Act article.

Code finding in the engineer view: flagged source line mapped to EU AI Act Article 50 with remediation guidance
Step 4

Report

Get your risk classification, compliance score, and first-draft compliance dossier. Annex IV, Annex XI, and Declaration of Conformity — generated, not hand-written. Review and finalize with qualified legal counsel.

Generated GPAI technical documentation dossier (Annex XI) with PDF, DOCX, and Markdown export

Turn Compliance Into Pipeline

Scanara generates compliance documentation drafts your EU prospects need to see — risk classification, Annex IV documentation, and compliance scan results — scan in minutes, finalize with your legal team.

The only compliance tool that reads your actual code

Find compliance gaps before an auditor does

Automated scanning rules for all 66 automatically detectable EU AI Act articles (44 code-detectable via Semgrep + 22 OPA policy rules). Guided assessments cover the remaining 34 articles with actionable obligations. 13 articles carry no actionable duties.

Classify risk without reading 459 pages

Automated risk classification across all Annex III categories and all 4 risk levels — prohibited, high, limited, and minimal.

Generate your compliance dossier automatically

Annex IV technical documentation, Annex XI, and Declaration of Conformity from your actual codebase. Four output formats: PDF, DOCX, HTML, Markdown.

Evidence your compliance work continuously

Every scan creates an immutable audit trail. GitHub App integration triggers compliance checks on every pull request.

Built on the regulation itself — not a summary of it Every rule anchored to its exact legal source.

113 + 13

articles and annexes parsed and covered

100

actionable obligations mapped — 66 automated, 34 via assessments

12

programming languages with identical rule coverage in each

25

benchmark applications re-verified before every release

Every finding cites the exact article, paragraph, and point it relates to — never a vague category.

Each release is verified against fixture tests, golden outputs, and coverage KPIs before any rule ships.

How we measure this — full methodology and KPIs →

Every release is re-verified against a 25-application benchmark

Scanara's scanning engine runs against a benchmark of purpose-built applications spanning all 12 supported languages, every risk tier, and all four actor roles before any rule ships.

  • Covers prohibited, high-risk, limited-risk, and minimal-risk tiers, including Annex I and Annex III high-risk paths
  • Benchmark results are reproduced on every release before rules ship
  • Includes negative controls — a minimal-risk application and per-obligation negative fixtures that must produce zero findings

How Scanara compares

FeatureScanaraGRC Platforms
Scans actual source codeCode analysis + Policy engineNo
Programming languages10+N/A
Document scanning8 EU languagesNo
Annex IV dossier generationAutomated (4 formats)No
CI/CD integrationGitHub App (auto on PRs)Limited
Immutable audit trailYesPartial
Time to first result5 minutesDays
Annual cost per AI systemFrom €0/mo€10K+

Built for every role in the compliance chain

Ship to the EU without compliance blocking releases

Scanara runs in your CI/CD pipeline — your engineers build product, not compliance tooling. Get visibility into compliance status across all AI systems without pulling engineers off feature work.

Enterprise-grade security and compliance

EU Data Residency

All data stored and processed in AWS eu-west-1 (Dublin, Ireland).

Scanara UG, Dachau

German business, fully DSGVO/GDPR compliant.

Immutable Audit Trail

Tamper-proof evidence for regulatory inspection readiness.

EU-First Billing

SEPA & credit card support with EUR billing.

We don't keep a copy of your repository

Files are read from GitHub, scanned in an isolated function, and discarded. Findings keep only the flagged lines and their immediate context — nothing else. Your code is never sent to an AI model, never written to our logs, never used for training, and never leaves the EU.

How we handle your code — Privacy Policy §2.3
Procurement team needs security docs before signing? Download the vendor evaluation pack
Scanara catches code-level and document-level compliance gaps. For complex legal interpretations, we recommend pairing with specialized legal counsel.

Compliance costs less than non-compliance

EU AI Act fines reach €35,000,000. Manual compliance costs €50,000–200,000 per assessment. Scanara starts at €0.

MonthlyAnnual
Save 10%

Free

For individual developers exploring EU AI Act compliance.

0
  • 5 scans (lifetime)
  • 1 AI system (lifetime)
  • 2 repositories (lifetime)
  • 1 team member
  • 3 assessments (lifetime)
  • 2 dossiers (lifetime)
  • 30-day scan history

Team

For small teams building compliant AI applications.

249/month

incl. VAT

  • 100 scans/month
  • 10 AI systems
  • 15 repositories
  • 7 team members
  • 20 assessments/month
  • 10 dossiers/month
  • Merge gate (1 repo)
  • 90-day audit trail
Most Popular

Business

For scaling organizations with comprehensive compliance needs.

799/month

incl. VAT

  • 500 scans/month
  • 50 AI systems
  • Unlimited repositories
  • 50 team members
  • 70 assessments/month
  • 50 dossiers/month
  • Merge gate (all repos)
  • 1-year audit trail

Enterprise

For large organizations requiring dedicated support and custom integrations.

Custom
  • Custom scans
  • Custom AI systems
  • Unlimited repositories
  • Custom team members
  • Custom assessments
  • Custom dossiers
  • SSO (OIDC/SAML)
  • Custom roles
  • Dedicated CSM
  • Unlimited audit trail + export
  • 99.95% SLA

No credit card required for free tier and trials

Frequently Asked Questions

The EU AI Act is now enforced. Is your code ready?

Don't read 459 pages. Scan your code. Get your risk level.