Progressio.ai

Fast, Automated EU AI Act Audits

Autonomously assesses High-Risk AI documentation requirement by requirement, showing what is evidenced, exposing gaps, and recommending the actions needed to remediate them.

eu-ai-act_audit-summary.pdf
Audit summary

Legislation: EU AI Act

AI system: Atria Cardiac Risk Stratifier

Articles
9
Coverage rate
72.4%
Gap rate
27.6%
Provisions
76
Evidenced
55
Evidence gap
21
Coverage overview
Coverage rate:72.4% evidenced·27.6% evidence gap
Strongest coverage
Art 9 · 8 of 8 provisions
Most gaps
Art 14 · 5 of 7 provisions
EU AI Act · Audit SummaryProgressio.ai

Founded by

Specialists in intellectual property and technology law, AI, and enterprise software.

Built for

C-suite, legal and compliance, and technology and data teams accountable for High-Risk AI.

The EU AI Act is already in force

Penalties of up to €35 million or 7% of global annual turnover, with enforcement powers live since August 2026. The Digital Omnibus moved the main High-Risk AI application dates to December 2027 and August 2028. The evidence runway is shorter than it looks.

  1. Feb 2025

    Prohibited AI practices ban in effect

  2. Aug 2025

    General-purpose AI (GPAI) obligations apply

  3. Aug 2026

    Transparency obligations and AI Office enforcement powers in force

  4. Dec 2027Upcoming

    High-Risk AI system requirements apply (Annex III)

  5. Aug 2028Upcoming

    High-Risk AI system requirements apply (Annex I)

Existing High-Risk AI systems may be subject to transitional provisions.

Timeline reflects Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (Digital Omnibus), in force since 27 July 2026. Last reviewed August 2026.

Evidence of intent is not evidence of execution

What was actually designed, implemented, tested, and operated must be evidenced against the requirements of the EU AI Act for High-Risk AI systems.

The challenge lies in connecting evidence to the requirements

01

Finding information

Multiple authors, organisational silos, and content spread across multiple systems.

02

Assessing the information

Completeness, consistency, ambiguity, and currency.

03

Mapping to the requirements

Connecting this vast body of information to the requirements of the EU AI Act for High-Risk AI systems.

04

Assessing the evidence

Assessing the strength of the evidence, identifying gaps, and determining remediation actions.

Search and retrieval tools can locate relevant material, but they cannot determine whether the available evidence sufficiently supports a specific requirement.

Consultants can provide guidance, but they cannot do the work for you.

See your High-Risk AI exposure clearly

One platform, one view, one source of truth about your evidence position against EU AI Act requirements for High-Risk AI systems, operable across the entire AI lifecycle at scale.

01

Maintain your High-Risk AI inventory

Maintain a searchable inventory of High-Risk AI systems with ownership, metadata, and provenance across the organisation.

02

Audit evidence requirement by requirement

Autonomously analyse documentation, identify relevant evidence, and assess suitability and completeness against each requirement.

03

Remediate and stay ready

Surface gaps, prioritise corrective action, and export evidence packs so readiness is continuous, not point-in-time.

Auditing at scale in minutes, not months

Compress months of evidence discovery for High-Risk AI systems into minutes.

Autonomous auditScanning
EU AI Act · Chapter III
  • Art. 9Risk management
  • Art. 10Data & data governance
  • Art. 11Technical documentation
  • Art. 12Record-keeping
  • Art. 13Transparency to users
  • Art. 14Human oversight
  • Art. 15Accuracy & robustness
  • Art. 17Quality management system
  • Art. 18Documentation retention
Coverage
0.0%evidenced
Evidence0
Gaps0
Provisions76
EU AI Act · Chapter IIIProgressio.ai

Each assessment delivers immediate value across the business

C-Suite

C-Suite

Strengthen executive oversight, secure a competitive advantage, and remove growth obstacles created by the EU AI Act.

Technology and Data

Technology and Data

Ship faster without the disruption of questionnaires and ad hoc evidence requests, through audits integrated into the AI lifecycle.

Legal and Compliance

Legal and Compliance

Collect and assess evidence against EU AI Act requirements faster, more consistently and at lower cost, identify gaps, track remediation and progress over time.

Built in the EU. Your data stays in the EU.

All customer data is processed and stored exclusively within the European Union. It never leaves EU jurisdiction and is never used to train our models.

Privacy by design

Built with privacy across every layer of the platform.

End-to-end encryption

AES-256 at rest and TLS 1.3 in transit.

Immutable audit trail

Every action logged with tamper-proof timestamps.

Recognised by

  • Governance Award
    OpenUK Awards 2025
  • UK AI100
    2025
  • Winner
    Women TechEU Deep-Tech

Frequently asked questions

No. Customer data is never used to train our models. It is used solely to run your assessment: identifying, mapping, and evaluating the evidence needed to prove conformance with the EU AI Act for your High-Risk AI systems.

The platform is built for High-Risk AI systems under the EU AI Act. It performs evidence-based, requirement by requirement conformity assessments against Articles 9, 10, 11, 12, 13, 14, 15, 17 and 18. Each requirement is evaluated on whether objective evidence sufficiently supports it, not on whether a policy or document merely exists.

Manual High-Risk conformity work often takes months. Progressio.ai compresses initial assessments to minutes or hours once relevant evidence is available. Final timing depends on scope, the number of systems, and how readily documentation and operational records can be accessed.

The platform maps your documentation to atomic EU AI Act requirements, assesses whether the evidence is sufficient and consistent, and returns a clear evidenced position for each requirement. Gaps and partial coverage are surfaced with remediation guidance so teams know what to fix next.

No. The platform is designed to find and assess evidence where it already lives. That removes the need for technical teams to fill out endless questionnaires, chase artifacts, or recreate documentation for every audit cycle.

Most approaches rely on questionnaires, consultant-led checklists, or general-purpose AI assistants that summarise documents. Progressio.ai uses specialised text models and a structured requirement graph so assessment is deterministic against atomic requirements. We prioritise Tier 1 errors: false confidence that a requirement is evidenced when the evidence is missing or insufficient.

No. Assessment is performed by specialised text models against a structured requirement graph. A general-purpose language model is used only in post-processing to articulate remediation guidance after the assessment is complete.

Legal and compliance teams use it to establish and defend an evidenced EU AI Act position for High-Risk systems. Technology and data teams use it to reduce audit burden. Executives use it to see where High-Risk AI creates exposure and where action is required.

Yes. Every result is requirement-linked and reviewable. Teams can inspect supporting evidence, see whether each requirement is Evidenced, Partial, or an Evidence Gap, and retain human ownership of the final conformance position.

Customer data is processed under strict access controls, encrypted in transit and at rest, and used only to perform your assessments. Data residency and handling controls are designed for regulated environments. Your data is not used to train our models.

Both. You can upload materials directly or connect enterprise systems that already hold technical, organisational, and operational evidence. The goal is to assess evidence in place, not force teams to recreate it for the audit.

See your evidence position at hyperspeed

Stop spending months buried in regulatory paperwork. Progressio.ai automates the heavy lifting so your teams can focus on what matters.