Next EU AI Act date: — Article 50(2) marking of AI-generated content, for systems already on the market on 2 August 2026

AI Governance That Keeps You Compliant

Automate EU AI Act, BaFin MaRisk, and GDPR compliance for your AI systems. From risk classification to incident reporting — one platform built for enterprises, SMEs, and startups.

Built for regulatory compliance

Select any of them to see what it is and who it applies to.

EU AI ActRegulation (EU) 2024/1689The EU's regulation on artificial intelligence. It sorts AI systems into risk tiers — prohibited, high-risk, limited-risk and minimal-risk — and attaches different duties to the provider that builds a system and the deployer that uses it. It entered into force on 1 August 2024 and applies in stages; the Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk stages later without changing the penalties. Article 99 leaves those at up to €35 million or 7% of worldwide annual turnover for prohibited practices, and up to €15 million or 3% for most other breaches, including the high-risk and transparency duties.Applies toProviders and deployers of AI systems placed on or used in the EU market.Next dateDecember 2, 2026 — Article 50(2) marking of AI-generated content, for systems already on the market on 2 August 2026Read the source text (opens in a new tab)General information about the instrument named, not legal advice.
BaFin MaRiskMindestanforderungen an das Risikomanagement — BaFin Circular 06/2024 (BA)BaFin's minimum requirements for risk management, issued as a circular under § 25a KWG rather than as a statute. It is administrative guidance that BaFin supervises against, which is why institutions treat it as binding in practice. Its IT expectations, formerly the separate BAIT, are where model and AI risk lands.Applies toCredit institutions and financial services institutions supervised by BaFin.Read the source text (opens in a new tab)General information about the instrument named, not legal advice.
GDPRRegulation (EU) 2016/679 — in German, the DSGVOThe EU's general data protection regulation. Alongside lawful basis, purpose limitation and data-subject rights, Article 35 attaches a data protection impact assessment to processing likely to result in a high risk — which is the provision an AI project meets most often, and the one that overlaps an AI Act risk assessment without being the same document.Applies toAny controller or processor handling personal data of people in the EU.Read the source text (opens in a new tab)General information about the instrument named, not legal advice.
DORADigital Operational Resilience Act — Regulation (EU) 2022/2554The EU regulation on digital operational resilience in the financial sector. It covers ICT risk management, incident classification and reporting, resilience testing, and oversight of third-party ICT providers — bringing those providers into a supervisory perimeter that previously stopped at the financial entity. BaFin's guidance of 18 December 2025 addresses entities subject to Articles 5 to 15 of DORA and places AI systems inside that existing ICT framework rather than a separate regime, examining ICT risk across the whole AI lifecycle — data acquisition, model development and provision, ongoing operation and retirement — with particular weight on third-party ICT risk.Applies toFinancial entities in the EU, and the ICT providers designated as critical to them.Read the source text (opens in a new tab)General information about the instrument named, not legal advice.
ISO 42001ISO/IEC 42001:2023The international management-system standard for artificial intelligence, structured like ISO 27001: a management system, a risk process, and a set of Annex A controls. It is certifiable and voluntary, so it evidences governance rather than discharging a legal duty. In Germany, certification bodies are accredited by the DAkkS.Applies toNobody by law — it is a voluntary standard an organisation chooses to certify against.Read the source text (opens in a new tab)General information about the instrument named, not legal advice.
NIS2 / BSIGDirective (EU) 2022/2555, transposed in Germany by the NIS2 implementation act amending the BSI-GesetzThe EU's second network and information security directive, and the German act that carries it into national law. It sets cybersecurity risk-management measures, a staged incident-reporting timetable, and registration with the BSI. Under § 38 Abs. 2 BSIG a company's management is personally liable to the entity for breaches of those duties, which is what distinguishes it from earlier German IT-security law.Applies to"Important" and "particularly important" entities across 18 sectors, sized by headcount and turnover.Read the source text (opens in a new tab)General information about the instrument named, not legal advice.

Govern AI models from leading providers

OpenAI
Anthropic
Google
Azure
Meta
Mistral

One Platform, Full AI Governance

Purpose-built tools to classify, monitor, and document your AI systems across every regulatory framework.

gavel

EU AI Act Readiness

Risk classification wizard, conformity assessments, model cards, and compliance calendars aligned to Articles 9–15.

Learn more →
monitoring

Bias Detection & Explainability

Fairness dashboards, SHAP/LIME explanations, and automated alerts to catch disparate impact before it reaches production.

Learn more →
search_insights

Shadow AI Discovery

Scan repositories, SaaS tools, and procurement records to find every AI system in your organisation and bring it under governance.

Learn more →

Evidence Collection That Leaves Your Data Where It Is

Compliance forms are mostly evidence gathering — proving a control exists, is owned, and was reviewed. Alleina’s compliance agent runs inside your own environment and does that work where the data already lives. What comes back is the answer, not the records.

lock_person

Read-only by construction

The agent connects to your cloud accounts, repositories, identity provider and document stores to read posture — and only to read it. The connector interface has no write method at all, so there is nothing for a misconfiguration to expose.

fingerprint

Findings travel, evidence doesn’t

For each control the agent sends a signed finding: pass or fail, how it was determined, a confidence score, a timestamp, and a SHA-256 reference to the evidence. The evidence artifact itself stays on your infrastructure. The wire format rejects any field outside that list.

description

Posture facts, not documents

To answer “is there an approved retention policy, and when was it last reviewed?” the agent reads whether the document exists and its review date — never the body. Identifiers such as file paths, URLs and resource IDs are hashed before they leave your network.

dns

Your models, or none at all

Where a judgement call is needed, the agent can run entirely against your own Ollama, vLLM, llama.cpp or LM Studio instance. A fail-closed policy engine refuses to send anything you have classified as confidential or restricted to a hosted model — and treats a backend it cannot identify as hosted rather than assuming the safe case.

The same split applies to fairness and explainability: metrics are computed on your side and only the resulting numbers are transmitted. Our backend does not ship Fairlearn, SHAP or LIME — it could not reconstruct your data from what it receives, because it never had the tools or the inputs.

Regulatory Coverage at a Glance

Everything you need to stay ahead of AI regulation across the EU and beyond.

6+

Regulatory Frameworks

15+

Compliance Checks

72h

Incident SLA Tracking

100%

Audit Trail Coverage

Zwei Kolleginnen im Gespräch an einem Besprechungstisch vor einer Fensterfront.

Backed by German and European Research Funding

We are an early-stage venture building in the open — here is exactly where we stand.

account_balance

Federally funded

Awarded the EXIST-GrĂĽndungsstipendium by the Federal Ministry for Economic Affairs and Energy, co-financed by the European Social Fund Plus.

school

University spin-off

Incubated at the University of Koblenz, where our research into applied AI governance began.

balance

Law and engineering, together

Founded by qualified lawyers and systems engineers — the two disciplines this problem actually needs.

Universität Koblenz EXIST – Existenzgründungen aus der Wissenschaft StArfrica – Startup Germany-Africa Bundesministerium für Wirtschaft und Energie Kofinanziert von der Europäischen Union

Latest from the Blog

Article 5-min Read

EU AI Act Compliance: What German Businesses Need to Know Now

EU AI Act compliance for GPAI is now enforced. See who is in scope, the three most common gaps, and…

Daniella Esi Darlington · Aug 6, 2026 Read →
Article 5-min Read

The Ethical Lens: Unpacking the Dancing AI Baby Trend Beyond the Cuteness

The viral AI baby trend raises critical questions about data sovereignty, consent, and digital identity. As AI governance experts, we…

Karyn Ewurakua Sawyerr · Mar 17, 2026 Read →
Article 5-min Read

Shadow AI: The Hidden Risk in Your Organization

Staff-adopted AI tools create an ungoverned AI estate that no inventory captures. Why shadow AI forms, what it exposes under…

Dominic Fui Dodzi-Nusenu · Mar 16, 2026 Read →
Article 5-min Read

AI Bias in Financial Services: How to Detect It and What the Law Requires

Bias in credit and lending models is both a fairness problem and an Article 10 obligation. How bias enters, which…

Dominic Fui Dodzi-Nusenu · Mar 16, 2026 Read →
Case Studies 5-min Read

How German Banks Are Adopting AI: Market Landscape 2026

German financial institutions are deploying AI faster than they are governing it. Where adoption is concentrated, why the governance gap…

Dominic Fui Dodzi-Nusenu · Mar 16, 2026 Read →
Toolkit 5-min Read

EU AI Act Compliance Checklist for High-Risk AI Systems

A working checklist for Articles 9 to 15, 17, 72 and 73 — what each one demands, what counts as…

Dominic Fui Dodzi-Nusenu · Mar 16, 2026 Read →
Article 5-min Read

German AI Regulation: Navigating BaFin, DORA, NIS2 and the KI-MIG

German AI governance is four overlapping regimes, not one. How the KI-MIG, BaFin's MaRisk and BAIT, DORA and NIS2 interact…

Dominic Fui Dodzi-Nusenu · Mar 16, 2026 Read →
Article 5-min Read

EU AI Act for Financial Institutions: The 2027 Deadline and What to Do Now

The EU AI Act's high-risk deadline moved to 2 December 2027, but credit scoring is still Annex III and the…

Dominic Fui Dodzi-Nusenu · Mar 16, 2026 Read →

Parts of the EU AI Act Are Already Applying

The Act arrives in stages, and several are already live — the remaining ones are less runway than they sound once every system has to be mapped, classified and documented. This is the register the platform works from:

  1. applyingEU AI Act — Prohibited practices and AI literacy duties began applying
  2. applyingEU AI Act — Obligations for general-purpose AI models began applying
  3. applyingEU AI Act — General application, including Article 50 transparency duties
  4. EU AI Act — Article 50(2) marking of AI-generated content, for systems already on the market on 2 August 2026
  5. EU AI Act — High-risk duties for stand-alone Annex III systems
  6. EU AI Act — High-risk duties for Annex I systems embedded in regulated products

Dates from the sources linked on each instrument, tracked on a best-effort basis. General information, not legal advice, and not a substitute for your own legal watch.

Not ready yet? Get compliance updates instead.

Alleina AI

Responsible AI governance platform for European enterprises, SMEs, and startups. EU AI Act compliance, bias detection, and model explainability.

Stay Updated

Get the latest on AI governance, regulatory updates, and platform news.

Gefördert durch

Universität Koblenz EXIST – Existenzgründungen aus der Wissenschaft StArfrica – Startup Germany-Africa Bundesministerium für Wirtschaft und Energie Kofinanziert von der Europäischen Union

Die Europäische Union fördert zusammen mit dem Bundesministerium für Wirtschaft und Energie über den Europäischen Sozialfonds Plus (ESF Plus) das Programm „Existenzgründungen aus der Wissenschaft (EXIST)“ in Deutschland.

Alleina AI ist ein an der Universität Koblenz inkubiertes Startup. Die Gründung wurde durch StArfrica („Startup Germany-Africa“) begleitet, ein Projekt des ZIFET an der Universität Koblenz.

© 2026 Alleina AI. Alle Rechte vorbehalten.