AIAuditSense
Point AIAuditSense at a website, a repository or a product description. It classifies the system, scores it against the EU AI Act, India’s DPDP Act and NIST AI RMF, and returns a remediation list with the clause each action answers. The first check takes two minutes and asks for no sign-up.
AIAuditSense is an orientation tool, not legal advice. Classification and obligations under the EU AI Act turn on facts that are not fully observable from code or a product description. Engage qualified counsel before relying on any assessment, including this one. The operative legal text is Regulation (EU) 2024/1689.
Evidence in, assessment out
The quality of the answer tracks the quality of the evidence. Give it more and the classification sharpens, which holds for the automated check and for the human one.
A website
We browse the product the way a regulator's assistant would: pages, claims, disclosures and whatever the interface tells a user about the AI behind it.
A repository
Metadata, structure and high-signal files read through the GitHub API, so the assessment sees what the system is rather than what the marketing says it is.
Documents and notes
Model cards, DPIAs, architecture notes, policies, anything you already have. Context you supply sharpens the classification.
What comes back
01
Risk classification
Prohibited, high-risk under Annex III, limited-risk under Article 50, or minimal. Then your likely role under the Act, and whether general-purpose model duties have attached to you.
02
Graded scorecard
An A to F grade and a weighted score, broken down by governance dimension, each finding tied back to the evidence it came from.
03
NIST AI RMF posture
Maturity across Govern, Map, Measure and Manage, for organisations whose US counterparts expect a framework they recognise.
04
Remediation roadmap
A ranked list of actions, each with the clause it answers and a rough effort estimate. Something your team can work through.
A report, with the company taken out of it
This is what the EU AI Act half of a real assessment looked like. We have removed the name of the system it graded, because publishing somebody else's compliance posture as an advertisement is not a thing we would want done to us.
Every dimension, scored
Candidate screening and job-fit platform. Classified high risk under Art. 6 / Annex III(4), employment and worker management. Twelve dimensions, weighted, with the obligation each one answers beside it.
| Dimension | References | Status | Score |
|---|---|---|---|
| Prohibited practices screeningArt. 5 | Art. 5 | Partial | 40 |
| Risk classification and scopingArt. 6 · Annex III | Art. 6 · Annex III | Non-compliant | 15 |
| Risk management systemArt. 9 | Art. 9 | Non-compliant | 8 |
| Data and data governanceArt. 10 | Art. 10 | Non-compliant | 15 |
| Technical documentation and record-keepingArt. 11 · Annex IV | Art. 11 · Annex IV | Non-compliant | 5 |
| Transparency and instructions for useArt. 13 · Art. 50 | Art. 13 · Art. 50 | Partial | 28 |
| Human oversightArt. 14 | Art. 14 | Non-compliant | 12 |
| Accuracy, robustness and cybersecurityArt. 15 | Art. 15 | Non-compliant | 10 |
| Quality management and conformityArt. 16 · Art. 43 | Art. 16 · Art. 43 | Non-compliant | 5 |
| Registration and post-market monitoringArt. 49 · Art. 72 | Art. 49 · Art. 72 | Non-compliant | 5 |
| Deployer duties and fundamental rightsArt. 4 · Art. 26 | Art. 4 · Art. 26 | Partial | 20 |
| General-purpose model obligationsArt. 51 · Art. 53 | Art. 51 · Art. 53 | Not applicable | n/a |
Penalty exposure
Up to €15,000,000 or 3% of worldwide annual turnover
Art. 99(4), the band for the high-risk obligations
Live on the findings above as they stand.
Up to €35,000,000 or 7% of worldwide annual turnover
Art. 99(3), the band for the prohibited practices
Reached only if the Art. 5(1)(f) question resolves against the product. The roadmap opens with that legal opinion for this reason.
In practice the commercial risk arrives before either band. European customers ask for conformity evidence as a condition of signing.
In priority order
Each item names the artefact to produce or the process to stand up, the provisions it answers, and a rough effort estimate.
Critical priority
Document the Annex III classification
Write down why the product falls under employment and worker management, why the narrow-task derogation does not apply, and hand the memo to every enterprise customer during onboarding.
Art. 6 · Annex III(4) · effort: medium
Critical priority
Get a legal opinion on emotion inference
Establish whether the interview analysis infers a candidate's emotional state. If it does, remove that output from employment contexts, because workplace emotion recognition is a prohibited practice.
Art. 5(1)(f) · effort: medium
High priority
Stand up a risk management system
A continuous process covering foreseeable misuse, with defined metrics, mitigations, and specific consideration of the younger applicants the product is sold on reaching.
Art. 9 · effort: high
High priority
Run and publish bias audits
Commission independent bias testing across protected characteristics and document dataset provenance. Until that evidence exists, drop the bias-free claim from the marketing.
Art. 10 · effort: high
About the tool
Is it free?
The first check is free and takes about two minutes, with no sign-up. It tells you in plain language which of the three rulebooks apply to you. Full audits, the graded scorecard and the PDF report are paid. We built AIAuditSense for our own consulting work, and opening the front of it up is how people find out whether they need us. Some of them find out they do not.
Can it replace a compliance audit?
No, and we would not let you rely on it as one. Classification under the AI Act depends on facts that are not visible from code or copy: how the system is marketed, whose name is on it, what a deployer does with the output, and the contractual chain behind it. AIAuditSense gets you oriented fast. A defensible assessment involves people, documents and interviews.
What happens to what I submit?
Crawled site content and uploaded document text are retained only as long as needed to produce and revisit your report, and prompt bodies are redacted on a 90-day schedule. Full detail is in the privacy notice and in the AIAuditSense application itself.
Which model does it use?
A frontier language model accessed through OpenRouter, working against codified framework logic rather than being asked to recall the law from memory. The frameworks are encoded; the model reasons over your evidence against them.
Can it audit a private repository?
Yes, with a GitHub token scoped to read contents. If you would rather not grant that, run it against a product description and upload the documents you are comfortable sharing.
The report found work to do
Bring us the AIAuditSense output and we will turn it into a scoped plan. If the list is short enough for your own team to handle, we will say that instead.
