AI Compliance Vendors

19 New AI Compliance Vendors Added to Our Directory in September 2026

A source-cited roundup of the 19 AI governance, compliance, security, and audit vendors we added on September 21, 2026, plus the 15 submissions that did not clear our sourcing bar and why.

By AI Compliance Vendors Editorial · September 21, 2026 · 6 min read · Last reviewed September 21, 2026

On September 21, 2026, we published 19 new vendor profiles to the directory, bringing the active vendor count to 64. This roundup names all 19, links to their new profiles, and explains the 15 submissions that did not make it through.

Every profile is a free Listed entry per our methodology — no vendor paid to be included. Each profile currently cites the vendor’s own homepage as its single source; deeper source coverage (funding, certifications, named customers, third-party reviews) will be added on the normal editorial cadence.

Batch stats

  • Unique companies that submitted through our form in the last four months: 39
  • Approved in this batch: 19
  • Rejected: 15 (breakdown below)
  • Active vendors in the directory after this batch: 64

The 19 new vendors, grouped by category

Governance platform (6)

  • [AI Sigil](/vendors/ai-sigil) — Centralised AI compliance platform for inventory, assessment, documentation, monitoring, audit, and risk management. _(HQ: United States; source: https://aisigil.com/)_
  • [Adeptiv AI](/vendors/adeptiv-ai) — Enterprise AI governance from inventory and risk assessment through real-time observability and regulatory compliance. _(HQ: India; source: https://adeptiv.ai/)_
  • [Attevera](/vendors/attevera) — Living operating record for the EU AI Act — inventory, article-level obligation mapping, control ownership, and audit-ready evidence. _(HQ: European Union; source: https://www.attevera.com/)_
  • [Crelis](/vendors/crelis) — Routes uncertain, sensitive, or high-risk agent tasks to verified human experts with approval flows and audit trails. _(HQ: United States; source: https://crelis.ai/)_
  • [Meilynx](/vendors/meilynx) — Enforces AI policy inline across models, agents, and tools; records every decision in a tamper-evident audit chain. _(HQ: United States; source: https://www.meilynx.com)_
  • [Regulayer](/vendors/regulayer) — Checks human authority before consequential AI acts, enforces human decisions, and creates independently verifiable evidence. _(HQ: United States; source: https://regulayer.com)_

Compliance automation (10)

  • [AIMS by Workflo](/vendors/aims-by-workflo) — Maps company AI usage, classifies risk, and guides organisations through EU AI Act compliance. _(HQ: Hungary; source: https://aims.workflo.hu)_
  • [Complipath](/vendors/complipath) — Register, classify, and document AI systems under the EU AI Act. _(HQ: Sweden; source: https://www.complipath.io)_
  • [ComplyAgent](/vendors/complyagent) — Inventories and classifies AI systems, then maps them to EU AI Act, NIST AI RMF, and ISO 42001 for documentation and audit packs. _(HQ: European Union; source: https://www.complyagent.eu)_
  • [DisclosureProof](/vendors/disclosureproof) — Scans live websites for EU AI Act Article 50 disclosure gaps and produces timestamped, hashed, signed evidence with scheduled re-scans. _(HQ: European Union; source: https://disclosureproof.com)_
  • [Embed AI](/vendors/embed-ai) — Freelance AI and privacy consultancy for organisations — advice and delivery for GDPR, DPIAs, contracts, and AI governance. _(HQ: Netherlands; source: https://embedai.nl)_
  • [LandingRed](/vendors/landingred) — EU AI Act compliance for European SMEs — classification, technical documentation, quality/conformity, cross-regulation tracking. _(HQ: Italy; source: https://landingred.com)_
  • [LearnWize](/vendors/learnwize) — Role-based AI literacy and privacy-aware AI training with assessments, certificates, and evidence dossiers. _(HQ: Netherlands; source: https://learnwize.ai)_
  • [QL Security](/vendors/ql-security) — AI security, governance, compliance, assurance, and ISO 42001 implementation services. _(HQ: United Kingdom; source: https://qlsecurity.co.uk)_
  • [SetAIComply](/vendors/setaicomply) — EU AI Act classification, documentation, and compliance management aimed at European SMEs. _(HQ: European Union; source: https://www.setaicomply.com)_
  • [TRUSS Compass](/vendors/truss-compass) — Continuously monitors AI systems against applicable regulations and frameworks, turning obligations into live checks and tracked fixes. _(HQ: Argentina; source: https://truss-compass.arionkoder.com/)_

LLM / agent observability (1)

  • [Traccia](/vendors/traccia) — AI agent control plane for observing, evaluating, governing, auditing, and enforcing policies across AI agents. _(HQ: United States; source: https://traccia.ai)_

Data governance (1)

  • [PrivacyScrubber](/vendors/privacyscrubber) — Local PII detection, tokenization, and reversible redaction for AI prompts, documents, files, and developer workflows before they hit LLMs. _(HQ: United States; source: https://privacyscrubber.com)_

Model governance / MLOps (1)

  • [DeepKeep](/vendors/deepkeep) — End-to-end AI security platform for GenAI applications, agents, and models across the AI lifecycle. _(HQ: Israel; source: https://www.deepkeep.ai)_

Why 15 submissions did not make it in

Our inclusion criteria require a real operating company, a productized offering primarily aimed at AI governance / risk / compliance / audit / security, a public website with verifiable contact information, and at least one named customer or documented deployment. Submissions that fell short in this batch:

  • LexFlag — adjacent scope (screening tool, not AI governance).
  • The AI Plumber — Substack blog, not a product.
  • Try AI Compliance — site failed to load during review.
  • EuroAIGuard Conseil — consultancy, no productized offering visible.
  • EU AI Act Article 4 Command Center — Notion template, not a company.
  • JudgeAI — adjacent scope (autonomous decision research project).
  • Regula (regula-ai) — single-person open-source scanner, no operating company.
  • Intellectyx AI — adjacent scope (financial transaction monitoring, not AI governance).
  • AQE — unclear operating status.
  • CLEARANCE — robots.txt blocked; could not verify content.
  • Formalize — general GRC platform, not AI-specific.
  • Deepwire Advisory — consultancy, no productized offering visible.
  • Star — global technology consultancy, not an AI-governance product.
  • OutTheBox.ai — unclear operating status.
  • SecureTraces — adjacent scope (AI-first cybersecurity, not AI governance).

If any of the above was rejected in error, reply to the acknowledgment email you received with a public source that clears the criteria and we will re-review within two business days.

What comes next

We just generated 38 new head-to-head comparison pages pairing each of the 19 new vendors against two established peers in the same category. Browse them via /compare or from each new vendor’s profile page.

Vendors who want to correct anything on their new profile should reply directly with the correction plus a public source. Every material fact on this site is source-cited and updated within two business days on request.


_This roundup is a factual accounting of a directory update. It contains no rankings, no editorial best-of calls, and no paid placement. Rankings live on the best-of pages; paid placement rules live in our methodology._

Keep reading

Related