Start with Maditon

Maditon EU AI Act risk assessment

Risk classification, assessment & dossier export

Classify AI systems under the EU AI Act, run source-referenced risk assessments, and produce audit-ready documentation. Built for startups, small companies, and SMEs without a legal or compliance team.

113
EU AI Act articles covered
48h
To your first risk report
100%
Hosted in Europe

Maditon is an EU AI Act risk assessment and classification platform for startups, small companies, and SMEs. It helps teams inventory AI systems, classify risk, map obligations, and produce source-referenced compliance documentation in hours instead of months. Built by Abiton Ventures AB in Sweden, Maditon is hosted entirely in Europe with no data leaving European borders.

/ For startups & SMEs

Built for AI risk assessment, classification, and compliance

AI risk assessment & classification

Classify each AI system under the EU AI Act as prohibited, high-risk, limited-risk or minimal-risk. Get plain-language obligations for every result.

Prohibited
High Risk
Limited
Minimal

Audit-Ready Documentation

Turn every risk assessment into regulation-compliant documentation. Every conclusion traces back to specific EU AI Act clauses.

Obligation Mapping

Map provider and deployer duties to each AI system, then translate dense regulatory text into actionable controls for your team.

GDPR, NIS2 & CRA — Coming Soon

A unified view across the full European regulatory stack is on our roadmap. GDPR, NIS2 and the Cyber Resilience Act follow the same source-referenced, audit-ready methodology.

GDPR
2018
NIS2
2024
EU AI Act
2025
CRA
2026
EU AI Act
Article 17(1)
“Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation. The quality management system shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions.”

Dense regulatory text like this is exactly what Maditon translates into clear, actionable steps — with a reference to the exact clause that requires each control.

/ How EU AI Act risk assessment works

Every AI system you use assessed, classified, and audit-ready

  1. AI-Led Interview

    Plain-language questions. No regulatory vocabulary required. Your product manager can run this — reserve your lawyer for the cases that need one.

  2. Risk Classification with Honest Gaps

    When the AI isn’t sure, it says so. That’s what auditors trust, and what most AI tools quietly hide.

  3. Human-Accepted Determinations

    Every AI suggestion becomes a draft. A human on your team accepts it, with their name and timestamp. Accountability stays where the law says it must — with you. Maditon cuts the work down to hours.

  4. PDF/A-1b Audit Dossier

    One click. Archival-quality. Ready for a regulator.

  5. Evidence Vault

    Stop hunting through Notion, Drive and Slack the day before the audit. Everything in one place.

  6. AI Literacy Training

    Article 4 says your staff must have AI literacy. Most teams don’t know this exists. Maditon includes the training.

EU AI Act
Risk Classification

A chatbot here. An AI screening tool there. Now someone asks: “Is any of this high-risk under the AI Act?” Maditon answers that — for every system, with reasoning, in minutes.

Describe your AI system in plain language. Maditon maps it against every risk category in the regulation, flags what applies, and tells you exactly why — citing the specific articles behind each determination. No guesswork, no billable hours, no waiting for a consultant to get back to you.

/ EU data residency

European data sovereignty your data stays in Europe, always

Hosted Entirely in Europe

Data sovereignty guaranteed. All processing stays within European borders, always.

GDPR-Native Architecture

Built from the ground up for data minimisation, purpose limitation and data subject rights.

No Vendor Lock-In

Export your entire documentation bank in audit-ready formats at any time.

Multilingual Platform

Available in English and Swedish today. German, French, Spanish and Italian coming soon.

/ Common questions

Answers for startups, scaleups, and SMEs

How do I classify an AI system under the EU AI Act?

Start with the system’s purpose, users, data, sector, and effect on people. Maditon turns that into a structured EU AI Act risk assessment, checks the prohibited, high-risk, limited-risk and minimal-risk categories, and explains the classification with article references. The result is a documented classification your team can review and sign off.

Does the EU AI Act apply to startups and SMEs?

Yes. The EU AI Act applies by your role (provider or deployer) and your system’s risk tier — not by company size. A ten-person startup deploying a high-risk AI system carries the same core obligations as a large enterprise. There is no blanket SME exemption, though some duties are lighter and fines are capped for smaller companies. Maditon helps you find out exactly which tier each of your systems falls into.

Do I need a legal team to comply with the EU AI Act?

No. Maditon is built for startups, scaleups, and SMEs that don’t have a dedicated legal or compliance team. It runs a plain-language interview, drafts a risk classification with specific article references, and generates audit-ready documentation. A named person on your team accepts each determination — accountability stays with you, but the heavy lifting does not.

When are the EU AI Act deadlines?

Prohibited practices have applied since February 2025 and general-purpose AI model obligations since August 2025. In May 2026 the EU agreed — through the Digital Omnibus — to postpone the high-risk obligations (Annex III, including EU database registration) from August 2026 to 2 December 2027, and the rules for AI in regulated products to 2 August 2028. That delay is politically agreed but still pending formal adoption, so classify your systems now to know which obligations will apply to you.

Is my company data kept in the EU?

Yes. Maditon is hosted entirely in Europe. All processing, storage, and delivery stays within European borders, and we use European-headquartered service providers only — no US-headquartered cloud services touch your data. This is a core architectural decision, not a configuration option.

Auditors don’t want claims. They want evidence.

Documents, timestamps, and a human signature. That’s what Maditon produces. Go from AI risk assessment to a complete audit package in hours, not months.

Hosted in Europe  ·  GDPR-compliant