AI Compliance Vendors

Free tools

Free AI compliance tools (2026)

Thirteen browser-based tools that turn a blank page into a defensible AI compliance artefact in under an hour. Ten generators + three cost calculators. Nothing uploaded, no account, no email gate. EU AI Act, ISO/IEC 42001, SOC 2, Colorado SB 24-205, NYC LL-144, Texas TRAIGA, Illinois HB 3773, and California AB 2013 / SB 942 / SB 1001 covered.

Free tool

State-by-State AI Compliance Wizard

Cross-cites Colorado SB 24-205, NYC LL-144, Texas HB 149, Illinois HB 3773, and California AB 2013 / SB 942 / SB 1001 in one wizard.

  • Multi-state readiness in one place
  • Statute citations + penalty ranges
  • Prioritized action list for legal / GRC
  • Downloadable Markdown report
Open tool
Free tool

Article 73 Incident Report Builder

Draft EU AI Act Article 73 serious-incident notifications with auto-computed 2, 10, or 15-day reporting deadlines.

  • All 5 Article 3(49) incident classes
  • Auto-computes filing deadline
  • GDPR + GPSR overlap tracker
  • Markdown export for GRC
Open tool
Free tool

AI Transparency Notice Generator

Draft EU AI Act Article 50 transparency notices for chatbots, deepfakes, emotion recognition, and generative AI in English, Spanish, French, and German.

  • All four Article 50 scenarios
  • California SB 1001 / SB 942 overlays
  • Texas TRAIGA § 552.051 add-on
  • Markdown + HTML export
Open tool
Free tool

AI Model Card Generator

Generate a spec-compliant model card combining Mitchell et al. 2019, EU AI Act Annex IV, NIST AI RMF, and ISO/IEC 42001 documentation in one Markdown file.

  • Live preview + coverage score
  • Maps to EU AI Act Annex IV
  • Satisfies California AB 2013 training summary
  • Downloadable Markdown for GRC repo
Open tool
Free tool

NYC LL-144 Bias Audit Checker + Cost Estimator

Confirm AEDT compliance under NYC Admin Code §§ 20-870 to 20-874 and 6 RCNY § 5-300, and get a bias-audit cost estimate sized to your NYC candidate volume.

  • AEDT substantial-use test (6 RCNY § 5-300)
  • Annual bias audit + public posting (§ 5-301)
  • 10-business-day candidate notice (§ 5-303)
  • Independent-auditor cost estimate
Open tool
Free tool

Texas TRAIGA Compliance Checker

Screen your AI system against the Texas Responsible AI Governance Act (HB 149), codified at Tex. Bus. & Com. Code Chapter 552. Effective 1 January 2026.

  • Chapter 552 duties + § 552.052 prohibited-practice screen
  • NIST AI RMF affirmative defense (§ 552.202)
  • Curable vs. uncurable penalty exposure
  • Independent, statute-cited report
Open tool
Free tool

Colorado AI Act Compliance Checker

Classify high-risk AI under Colorado SB 24-205 (C.R.S. § 6-1-1701 et seq.). Get a gap report tied to every developer and deployer duty. Effective 1 February 2026.

  • High-risk classification (§ 6-1-1701(9))
  • Substantial-factor test (§ 6-1-1701(11))
  • Developer + deployer obligations (§§ 6-1-1702/1703)
  • Small-business § 6-1-1703(6) exemption logic
Open tool
Free tool

EU AI Act Risk Classifier

Answer 12 questions about your AI system. Get its tier under the EU AI Act — prohibited, high-risk, limited-risk, GPAI, or minimal — with the article and annex citations that put it there.

  • Article 5 prohibitions
  • Annex III high-risk + Article 6(3) derogation
  • Article 50 transparency
  • GPAI + systemic-risk thresholds
Open tool
Free tool

FRIA Generator

Build a Fundamental Rights Impact Assessment that follows Article 27(1)(a)–(f) line by line. Live markdown preview, downloadable .md, print-to-PDF.

  • All six mandatory FRIA sections
  • Risk catalogue with likelihood × severity
  • Article 27(3) AI Office notification reminder
  • Article 27(4) GDPR DPIA complementarity note
Open tool
Free tool

AI Risk Register

Editable risk table mapped to NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, and EU AI Act Article 9. Loads with 14 pre-filled risks. Exports to .xlsx, .csv, and markdown.

  • 10 risk categories pre-populated
  • 5×5 likelihood × severity heatmap
  • XLSX export with summary sheet
  • No login, no email, no server storage
Open tool
Free tool

ISO/IEC 42001 Certification Cost Calculator

Stage 1 + Stage 2 audit fees, implementation consulting, internal labor, and surveillance audits. Ranges cite IAF MD 5:2019 tables and public CB rate cards.

  • Audit-day estimates by size + scope
  • Accredited vs. direct path comparison
  • Maturity discount (ISO 27001, NIST RMF)
  • Year 1 + ongoing annual breakdown
Open tool
Free tool

SOC 2 Audit Cost Calculator (AI companies)

Type 1 vs. Type 2 fees, Trust Services Criteria adders, and AI-workload multipliers for LLM users, hosted inference, and model-training workloads.

  • AI-specific control multipliers
  • GRC platform + gap-assessment pricing
  • Readiness consulting toggle
  • Year 1 + ongoing annual breakdown
Open tool
Free tool

EU AI Act Article 43 Conformity Assessment Cost

Auto-detects the Annex VI (internal-controls) vs. Annex VII (notified-body) route. Prices Annex IV documentation, Article 72 post-market monitoring, and Article 71 registration.

  • Route auto-detection by system class
  • ISO 42001 harmonized-standard discount
  • Notified-body fee triangulation
  • GPAI + systemic-risk coverage
Open tool

How to use this toolkit

The 2026 AI compliance stack has three tiers: (1) a classification of where a system falls under the applicable framework, (2) the required assessments and disclosures for that classification, and (3) a living operational artefact — usually a risk register — that connects controls to owners and review cadences. This toolkit produces drafts for each tier.

Start with classification. Use the EU AI Act risk classifier for anything EU-facing, the state-by-state wizard for U.S. deployments, and the jurisdiction-specific checkers for Colorado, NYC LL-144, and Texas TRAIGA when you already know the state matters.

Then produce required documentation. FRIA for public-sector and financial deployers, the model card for anything EU high-risk, an Article 50 transparency notice for anything user-facing, and an Article 73 incident report when something goes wrong.

Finally, operationalise. Everything above rolls into the AI risk register — the audit-defensible artefact that Article 9 of the EU AI Act, ISO/IEC 42001, and NIST AI RMF all assume you have. Estimate what the whole program will cost with the AI compliance cost calculator.

These tools produce drafts. They will not file your AI Office notification under Article 27(3), they will not do your bias audit, and they will not replace counsel. What they will do is get you from a blank page to a defensible document in about an hour, in a format your legal, security, and product teams can argue with.

Need a vendor next?

Once you have a classification and a draft register, the AI Compliance Vendors matchmaker will rank vendors against the frameworks and capabilities you actually need — no email gate, no booking required.