The EU AI Act, mapped to your codebase
Static analysis across 10+ programming languages, document checks in 8 EU languages, and a first-draft compliance dossier in minutes — every finding anchored to a specific article of Regulation (EU) 2024/1689. Review and finalize with your legal team.
- 100 actionable EU AI Act obligations mapped
- 66 automated checks, 34 guided assessments
- Every finding cites article, paragraph, and point

Example scan: open-source loan-default prediction model (limited risk, GPAI obligations)
The EU AI Act is enforceable August 2, 2026. GPAI obligations are already live. Most teams aren't ready.
No AI inventory
Over half of organizations lack a systematic AI system inventory — they don't even know what needs to comply.
No documentation
40–80 hours per AI system for Annex IV documentation from scratch — and that's just one system.
97% non-compliant
97% of the open-source AI codebases we scanned in our benchmark show compliance gaps against EU AI Act requirements. The issue isn't capability — it's awareness.
Fines up to €35,000,000 or 7% of global turnover (Article 99) — but the real cost is lost EU market access.
EU AI Act enforcement began — August 2, 2026
Every day non-compliant is a day of liability.
One platform from repository to audit-ready dossier Three inputs, one compliance picture.
Static code scanning
Scanning rules detect EU AI Act-relevant patterns directly in your source repositories — across 10+ programming languages, mapped to specific articles.
Document policy checks
A policy engine evaluates your technical documentation in 8 EU languages against the obligations of your risk tier.
Structured assessments
Guided questionnaires cover what code can't show: Annex III high-risk screening (AIRA), FRIA, DPIA, GPAI provider, deployer, and prohibited-practice screening.
The result: a defensible compliance dossier
A risk classification across all four tiers — including GPAI and systemic-risk models — and a compliance dossier with Annex IV technical documentation, Annex XI, and Declaration of Conformity. Fields are auto-populated from scan and assessment data wherever possible, the remaining evidence is authored in-platform, and the finished dossier exports as PDF, DOCX, HTML, or Markdown.
Manual conformity cycles cost €50,000–€200,000 per AI system. Scanara reduces that by an order of magnitude.
From code to compliance dossier in four steps
Risk classification
Automatic risk classification for your GitHub repository. You can view the detected indicators and change or confirm the classification.

Connect
Create an AI System and link all your repositories. The AI Systems will be risk classified automatically.

Scan
Dual-engine scanning: static analysis for code across 10+ languages, policy engine for documents in 8 EU languages. Every finding maps to a specific EU AI Act article.

Report
Get your risk classification, compliance score, and first-draft compliance dossier. Annex IV, Annex XI, and Declaration of Conformity — generated, not hand-written. Review and finalize with qualified legal counsel.

Turn Compliance Into Pipeline
Scanara generates compliance documentation drafts your EU prospects need to see — risk classification, Annex IV documentation, and compliance scan results — scan in minutes, finalize with your legal team.
The only compliance tool that reads your actual code
Find compliance gaps before an auditor does
Automated scanning rules for all 66 automatically detectable EU AI Act articles (44 code-detectable via Semgrep + 22 OPA policy rules). Guided assessments cover the remaining 34 articles with actionable obligations. 13 articles carry no actionable duties.
Classify risk without reading 459 pages
Automated risk classification across all Annex III categories and all 4 risk levels — prohibited, high, limited, and minimal.
Generate your compliance dossier automatically
Annex IV technical documentation, Annex XI, and Declaration of Conformity from your actual codebase. Four output formats: PDF, DOCX, HTML, Markdown.
Evidence your compliance work continuously
Every scan creates an immutable audit trail. GitHub App integration triggers compliance checks on every pull request.
Built on the regulation itself — not a summary of it Every rule anchored to its exact legal source.
articles and annexes parsed and covered
actionable obligations mapped — 66 automated, 34 via assessments
programming languages with identical rule coverage in each
benchmark applications re-verified before every release
Every finding cites the exact article, paragraph, and point it relates to — never a vague category.
Each release is verified against fixture tests, golden outputs, and coverage KPIs before any rule ships.
How we measure this — full methodology and KPIs →Every release is re-verified against a 25-application benchmark
Scanara's scanning engine runs against a benchmark of purpose-built applications spanning all 12 supported languages, every risk tier, and all four actor roles before any rule ships.
- Covers prohibited, high-risk, limited-risk, and minimal-risk tiers, including Annex I and Annex III high-risk paths
- Benchmark results are reproduced on every release before rules ship
- Includes negative controls — a minimal-risk application and per-obligation negative fixtures that must produce zero findings
How Scanara compares
| Feature | Scanara | GRC Platforms |
|---|---|---|
| Scans actual source code | Code analysis + Policy engine | No |
| Programming languages | 10+ | N/A |
| Document scanning | 8 EU languages | No |
| Annex IV dossier generation | Automated (4 formats) | No |
| CI/CD integration | GitHub App (auto on PRs) | Limited |
| Immutable audit trail | Yes | Partial |
| Time to first result | 5 minutes | Days |
| Annual cost per AI system | From €0/mo | €10K+ |
Built for every role in the compliance chain
Ship to the EU without compliance blocking releases
Scanara runs in your CI/CD pipeline — your engineers build product, not compliance tooling. Get visibility into compliance status across all AI systems without pulling engineers off feature work.
Enterprise-grade security and compliance
EU Data Residency
All data stored and processed in AWS eu-west-1 (Dublin, Ireland).
Scanara UG, Dachau
German business, fully DSGVO/GDPR compliant.
Immutable Audit Trail
Tamper-proof evidence for regulatory inspection readiness.
EU-First Billing
SEPA & credit card support with EUR billing.
We don't keep a copy of your repository
Files are read from GitHub, scanned in an isolated function, and discarded. Findings keep only the flagged lines and their immediate context — nothing else. Your code is never sent to an AI model, never written to our logs, never used for training, and never leaves the EU.
How we handle your code — Privacy Policy §2.3Compliance costs less than non-compliance
EU AI Act fines reach €35,000,000. Manual compliance costs €50,000–200,000 per assessment. Scanara starts at €0.
Free
For individual developers exploring EU AI Act compliance.
- 5 scans (lifetime)
- 1 AI system (lifetime)
- 2 repositories (lifetime)
- 1 team member
- 3 assessments (lifetime)
- 2 dossiers (lifetime)
- 30-day scan history
Team
For small teams building compliant AI applications.
incl. VAT
- 100 scans/month
- 10 AI systems
- 15 repositories
- 7 team members
- 20 assessments/month
- 10 dossiers/month
- Merge gate (1 repo)
- 90-day audit trail
No credit card required for free tier and trials
Frequently Asked Questions
The EU AI Act is now enforced. Is your code ready?
Don't read 459 pages. Scan your code. Get your risk level.




