Skip to content

SOLUTIONS · AI COMPANIES

You build with AI. The regulation has arrived.

The European AI Regulation is in force and classifies systems by risk. If yours scores people, makes decisions about them or takes part in a regulated process, it is probably high risk.

Zerod covers the AI Act alongside the rest of your compliance, so you are not running two programmes in parallel.

An AI Act obligations register filtered by role: 25 of the 27 controls apply. Three rows with their article, subject and state.

Obligations that apply to you

25 of 27

ArticleStatus
  • Art. 9Risk managementImplemented
  • Art. 72Post-market monitoring planIn progress
  • Art. 14Human oversightIn progress

The AI regulatory landscape.

Building with AI adds obligations, it does not replace them:

Six frameworks piling up and overlapping: the EU AI Act, ISO 42001, GDPR and LOPDGDD, ISO 27001, ISO 27701 and SOC 2. Each carries its name and one line on what it requires of a company building with AI.
  1. EU AI Act

    Risk classification, technical documentation, risk management and post-deployment oversight

  2. ISO 42001

    A certifiable AI management system, the standard demanding buyers ask for

  3. GDPR + LOPDGDD

    Legal basis for training, automated decisions and data subject rights

  4. ISO 27001

    The entry requirement of any corporate customer

  5. ISO 27701

    Privacy maturity, once your product handles personal data at scale

  6. SOC 2

    Required by customers in the US

Your product does not have to be a model. It only has to decide something about a person.

What you will be asked.

Three cards, one per audience: corporate customers, investors, and regulators and auditors. Each carries what that audience asks for before moving forward.
  • Corporate customers

    • What data goes into your model
    • Who has seen it
    • Human review of decisions

    Before they sign they want to know what data goes into your model, who has seen it, and whether a human reviews the decisions. The question is no longer whether you use AI, it is how you govern it.

  • Investors

    • Risk classification
    • AI Act readiness
    • Documentation

    Technical due diligence now includes risk classification and AI Act readiness. A high-risk product with no documentation is a discount on the valuation.

  • Regulators and auditors

    • Technical documentation
    • Risk register
    • Post-deployment monitoring

    The AI Act requires technical documentation, a risk register and post-deployment monitoring. It is not a declaration: it is a file someone can ask you for.

How Zerod fits.

  • Obligations filtered by your role: You declare whether you are a provider or a deployer, and the register shows you only the controls that apply to you, not all 27.
  • Compliance that counts what applies: The percentage reflects what is yours, not the whole regulation, and it is the same figure on the dashboard, in reports and in your Trust Center.
  • Drafts of the documents Articles 9 and 72 require: An AI risk management policy and a post-market monitoring plan, generated as drafts and exportable.
  • ISO 42001, with guidance on all 38 controls: Annex A loaded with our own guidance, and an internal audit with a Statement of Applicability.

AI companies that trust Zerod.

Companies building AI products in regulated sectors use Zerod to cover the AI Act alongside the rest of their compliance.

The AI company that reaches the regulated market first is not the one with the best model. It is the one that can prove it.

Get compliant. Prove your security.

Compliance for AI companies · Zerod