EU AI Act compliance for SMEs

Do you actually know what AI tools your team is running right now?

Most teams are using AI tools nobody officially approved — some handling sensitive client data. Disclose maps your full AI stack, classifies each tool under the EU AI Act, and gives you a trust artifact you can hand to any customer asking how you govern it.

📋
Vendor Security Questionnaire
From: Enterprise Procurement  ·  Received today
4 / 4 answered
Q1
Which AI tools do you use on our data, and how do you govern them?
✓ 4 tools documented, roles classified
Q2
Is our data used to train the AI tools in your service?
✓ Data use documented per vendor
Q3
Where is our data processed and stored?
✓ Processing locations on record
Q4
Are you notified when those vendors change their terms — and can you show evidence?
✓ Active vendor monitoring enabled
The problem

The problem starts before the questionnaire

Most teams are running more AI than anyone officially approved. Some of it is handling sensitive data nobody sanctioned. And most SMEs only find out what they're running when someone asks — by which point finding out isn't enough.

01
What AI tools is your team actually using — including the ones nobody officially approved?
02
What data is going into those tools — client data, personal data, commercially sensitive information?
03
Which of those tools creates legal obligations under the EU AI Act — and what exactly are they?
04
When a customer asks how you govern your AI, what evidence can you actually show them?
Most SMEs can't answer any of these today. The fourth question is the one that stalls deals — but you can't answer it without having answered the first three.
How it works

From questionnaire to answer, in minutes

Disclose does the heavy lifting. You get a clear overview of every AI tool, its risk tier, role and your obligations under the EU AI Act — ready to share or bring to an advisor.

1
Complete your Use Case Card
Fill in a Use Case Card for each AI tool in your stack — covering what it does, who uses it, and what data goes in.
2
Know your risk and role
Disclose classifies each tool against EU AI Act risk tiers and translates your obligations into plain language. Not legalese.
3
Share your trust artifact
Get a clean, shareable document that maps your AI governance to EU AI Act articles. Hand it to the customer asking the question.
4
Always on
We keep watching
When a vendor changes their terms or privacy policy, we tell you what changed, whether it matters for your specific use case, which tools are affected, and what to do next.
A peek inside your dashboard

Every AI tool, classified by EU AI Act risk tier and kept under continuous vendor monitoring — all in a single, shareable view.

Book a demo →
The Disclose dashboard showing an AI inventory with two high-risk tools, two limited-risk tools and four vendors actively monitored.
Who it's for

For the team responsible for what AI does in practice

🏢
Consultancies & professional services
You use AI on client data — for research, analysis, delivery. Enterprise clients are asking how you govern it. Disclose gives you the structured answer, fast.
⚙️
Agencies & BPOs
You run client operations with AI-assisted workflows. Your tools, your responsibility. Disclose tracks what you're running and keeps the record current.
📊
SMEs using AI in HR, finance, or ops
A CV screening tool or credit-risk model may be high-risk under the EU AI Act. Disclose tells you which ones, and what you need to do before your next audit.
Book a demo →

Other reasons teams come to Disclose:

Cyber-insurance renewal asking about AI use
DPO or GDPR review flagged AI tools
Staff pasting client data into AI tools
Leadership asking "what AI are we even running?"
New enterprise contract requiring AI governance proof

The next vendor questionnaire shouldn't catch you off guard.

Log your first AI tool now. You'll have your trust artifact before the end of the day.