EU AI Act Compliance Scanner
EU AI Act — Main Obligations Apply Since
Scan your AI-related websites and documents for PII exposure. Find personal data in training datasets, model outputs, and user-facing interfaces — enforcement is already under way.
What is the EU AI Act?
The EU Artificial Intelligence Act is the world's first comprehensive legal framework for AI. It sets out a risk-based approach with stricter requirements for high-risk uses, transparency obligations, and heavy penalties for non-compliance.
Article 10 (Data Governance) requires providers of high-risk AI systems to document training, validation, and testing datasets—including measures taken to detect and address bias and ensure data quality. This means you must know what personal data your AI systems process.
Key Compliance Requirements
- Data Governance (Art. 10): Document training data sources, identify PII in datasets
- Technical Documentation (Art. 11): Maintain records of data processing operations
- Transparency (Art. 13): Inform users when AI processes personal data
- Human Oversight (Art. 14): Enable human review of AI decisions affecting individuals
- Record Keeping (Art. 12): Log AI system activities for audit purposes
- Accuracy & Security (Art. 15): Ensure AI systems are accurate and cybersecure
AI System Risk Categories
Strictest Requirements
Compliance required since August 2, 2026
- Biometric identification systems
- Critical infrastructure management
- Education and vocational training
- Employment and worker management
- Credit scoring and insurance
- Law enforcement and border control
- Migration and asylum processing
- Justice and democratic processes
Transparency Obligations
Must disclose AI use to users
- Chatbots and virtual assistants
- Emotion recognition systems
- Deepfake generators
- AI-generated content
- Recommendation systems
No Special Requirements
Voluntary codes of conduct
- Spam filters
- AI-enabled video games
- Inventory management
- General-purpose AI tools
Non-Compliance Penalties
The EU AI Act sets heavy penalties for violations, calculated as the higher of a fixed amount or percentage of global annual turnover.
| Violation Type | Fixed Amount | % of Turnover |
|---|---|---|
| Prohibited AI practices | Up to €35 million | 7% |
| High-risk AI non-compliance | Up to €15 million | 3% |
| Incorrect information to authorities | Up to €7.5 million | 1% |
Example: A company with €1 billion annual turnover could face fines up to €70 million (7%) for prohibited AI practices, or €30 million (3%) for high-risk AI non-compliance.
How piisafe.eu Helps with EU AI Act Compliance
1. Identify PII in Training Data
Scan documents and data catalogs to detect personal data in AI training datasets. Article 10 requires documentation of all PII used in high-risk AI systems.
2. Audit User-Facing Interfaces
Scan AI-powered websites and apps for exposed personal data. Find SSNs, credit cards, and other PII that may appear in AI outputs.
3. Document Compliance
Export scan results as HTML, JSON, or CSV for compliance records. Audit-ready reports show due diligence under Article 11.
4. No-Storage Architecture
piisafe.eu runs scans in memory only, with no storage — finished sessions are automatically deleted within 35 minutes. This aligns with data minimization principles (GDPR Article 5).
Start Your EU AI Act Compliance Audit
The EU AI Act's main obligations have applied since August 2, 2026. Scan your AI systems now to find PII exposure risks. Free, no account required.
Start Free Scan