Solution

Be audit-ready before the request lands.

Grasp keeps a live, classified inventory of every AI tool and turns it into signed, timestamped evidence - so EU AI Act, ISO 42001, NIS2 and SOC 2 audits become a review, not a scramble.

Part of the Act is already law. You can't see if you're breaking it.

Prohibited AI practices have been enforceable since February 2025. The high-risk obligations follow in December 2027. Both assume something most companies do not have: a complete, classified inventory of every AI system in use. You cannot classify what you have not found - and an employee can adopt a tool that crosses the line in an afternoon.

The hard part is not reading the Act. It is keeping a classified inventory current while teams adopt tools faster than you can assess them.

Where the EU AI Act stands

The Act is already partially in force. Prohibited practices have been enforceable since February 2025. The general application date of 2 August 2026 stands, bringing the governance and penalties framework with it. Under the Digital Omnibus agreement of May 2026, high-risk obligations for standalone systems shift to 2 December 2027, with product-embedded systems following on 2 August 2028, and transparency obligations landing 2 December 2026. The delay exists because technical standards were not ready. It was granted with the explicit expectation that implementation is already underway. The deadline moved. The homework did not.

How Grasp helps

Every AI tool, classified against the Act's four risk tiers.

Grasp discovers every AI system in use, then classifies each one as Prohibited, High, Limited, or Minimal. Anything in the Prohibited tier is flagged and blocked the moment it appears. Everything else is assessed, documented, and evidenced, so when the high-risk obligations land, your inventory is already built and your sign-offs are already signed.

Controls

What EU AI Act Compliance looks like in Grasp

A cleaner operating rhythm: find the signal, attach the context, route the decision, and keep the evidence.

01 / 06

Risk tier classification

Every detected tool is mapped to Prohibited, High, Limited, or Minimal risk as it enters the inventory.

Framework fit

How it connects to the work you already do

Grasp is designed to reuse the same inventory, risk, vendor, and evidence data across the frameworks your team already reports against.

GDPR

The Act runs alongside GDPR. Any tool processing personal data still needs lawful basis and a DPA.

ISO 42001

ISO 42001 and the EU AI Act ask for the same foundations: inventory, risk assessment, and documented governance.

ISO 27001

Your ISO 27001 system already covers inventory and supplier risk. Grasp bridges those controls to AI.

SOC 2

Vendor and risk-management criteria overlap with the Act's documentation duties. The same evidence supports both.

See where you stand against the EU AI Act.

Book a demo. We will show you every AI system in use and the risk tier of each one.