The European AI Regulation is in force and classifies systems by risk. If yours scores people, makes decisions about them or takes part in a regulated process, it is probably high risk.
Zerod covers the AI Act alongside the rest of your compliance, so you are not running two programmes in parallel.
Building with AI adds obligations, it does not replace them:
Six frameworks piling up and overlapping: the EU AI Act, ISO 42001, GDPR and LOPDGDD, ISO 27001, ISO 27701 and SOC 2. Each carries its name and one line on what it requires of a company building with AI.
EU AI Act
Risk classification, technical documentation, risk management and post-deployment oversight
ISO 42001
A certifiable AI management system, the standard demanding buyers ask for
GDPR + LOPDGDD
Legal basis for training, automated decisions and data subject rights
ISO 27001
The entry requirement of any corporate customer
ISO 27701
Privacy maturity, once your product handles personal data at scale
SOC 2
Required by customers in the US
Your product does not have to be a model. It only has to decide something about a person.
What you will be asked.
Three cards, one per audience: corporate customers, investors, and regulators and auditors. Each carries what that audience asks for before moving forward.
Corporate customers
What data goes into your model
Who has seen it
Human review of decisions
Before they sign they want to know what data goes into your model, who has seen it, and whether a human reviews the decisions. The question is no longer whether you use AI, it is how you govern it.
Investors
Risk classification
AI Act readiness
Documentation
Technical due diligence now includes risk classification and AI Act readiness. A high-risk product with no documentation is a discount on the valuation.
Regulators and auditors
Technical documentation
Risk register
Post-deployment monitoring
The AI Act requires technical documentation, a risk register and post-deployment monitoring. It is not a declaration: it is a file someone can ask you for.
How Zerod fits.
Obligations filtered by your role: You declare whether you are a provider or a deployer, and the register shows you only the controls that apply to you, not all 27.
Compliance that counts what applies: The percentage reflects what is yours, not the whole regulation, and it is the same figure on the dashboard, in reports and in your Trust Center.
Drafts of the documents Articles 9 and 72 require: An AI risk management policy and a post-market monitoring plan, generated as drafts and exportable.
ISO 42001, with guidance on all 38 controls: Annex A loaded with our own guidance, and an internal audit with a Statement of Applicability.
AI companies that trust Zerod.
Companies building AI products in regulated sectors use Zerod to cover the AI Act alongside the rest of their compliance.
The AI company that reaches the regulated market first is not the one with the best model. It is the one that can prove it.