# Maditon > Maditon is an EU compliance assistant for European startups and SMEs. It takes the volume work of compliance — reading the documents, mapping the obligations, keeping track — and leaves the judgement to a named human. It inventories AI systems, classifies their risk under Regulation (EU) 2024/1689 with citations that quote the passage the classification rests on word for word rather than only naming the article, verifies each conclusion back against the retrieved legal text and reports any claim it could not support alongside a confidence score, produces the complete obligation checklist for that classification, links evidence to each obligation, builds audit-ready compliance dossiers as PDF, tracks EU database registration under Article 49, and applies SME reliefs where they are available. Every AI-generated risk classification or compliance determination is a draft until a named human accepts it with a timestamp — no AI output reaches a "compliant" or "cleared" state autonomously, which is what makes the output defensible to a regulator. A free plan runs a real classification with no card. Maditon works across the regulatory stack rather than being a single-regulation tool: the EU AI Act module is live today and GDPR, NIS2 and more follow on the same foundation — see https://maditon.com/modules. Built by Abiton Ventures AB (Sweden) and hosted entirely in the EU. B2B only. ## Guides — EU AI Act - [AI literacy under Article 4 — what's required](https://maditon.com/guides/ai-literacy-article-4-requirements/): Article 4 of the EU AI Act requires staff AI literacy from every provider and deployer. What it means in practice, and how to document a programme regulators accept. - [Annex III high-risk categories explained](https://maditon.com/guides/annex-iii-high-risk-categories-explained/): The eight Annex III categories of high-risk AI under the EU AI Act, with worked examples in biometrics, employment, credit, education, and infrastructure. - [Article 14 human oversight — how to design it](https://maditon.com/guides/article-14-human-oversight-design/): Article 14 requires human oversight built into every high-risk AI system. What 'meaningful review' actually means in product design, and patterns that satisfy regulators. - [Article 5 prohibited AI practices — ten banned outright](https://maditon.com/guides/article-5-prohibited-ai-practices/): Article 5 of the EU AI Act bans ten AI practices outright. Eight enforceable since February 2025, two more from December 2026. What's banned and the narrow exceptions. - [Article 6(3)(d) explained: the preparatory-task carve-out](https://maditon.com/guides/article-6-3-d-preparatory-task-explained/): The EU AI Act's Article 6(3)(d) carve-out lets some AI systems escape high-risk classification by performing a preparatory task. Here's exactly when it applies. - [Audit-ready compliance dossier template for the EU AI Act](https://maditon.com/guides/audit-ready-compliance-dossier-template/): What a regulator-ready EU AI Act compliance dossier actually contains — section by section, with the Annex IV mapping for high-risk providers. - [Conformity assessment for high-risk AI systems](https://maditon.com/guides/conformity-assessment-high-risk-ai/): Article 43 conformity assessment: internal control vs notified body, what gets assessed, and the practical timeline before a high-risk system goes to market. - [EU AI Act compliance checklist for SMEs](https://maditon.com/guides/eu-ai-act-compliance-checklist-for-smes/): A practical, source-referenced compliance checklist for European startups and SMEs that use or build AI systems. Written for product and operations teams, not lawyers. - [EU AI Act deadlines 2026 — what applies when](https://maditon.com/guides/eu-ai-act-deadlines-2026/): The EU AI Act timeline after the Digital Omnibus delay: prohibited practices (Feb 2025), GPAI (Aug 2025), high-risk (Dec 2027), regulated products (Aug 2028). - [EU AI Act deployer obligations — Article 26 explained](https://maditon.com/guides/eu-ai-act-deployer-obligations-article-26/): Most European companies are deployers, not providers, under the EU AI Act. Article 26 is the practical obligation set: human oversight, logging, transparency. - [EU AI Act fines and penalties — what's at stake](https://maditon.com/guides/eu-ai-act-fines-and-penalties/): The EU AI Act's three-tier fine structure: €35M / 7% for prohibited practices, €15M / 3% for high-risk breaches, €7.5M / 1% for misinformation. SME perspective. - [EU AI Act for fintech and credit-scoring AI](https://maditon.com/guides/eu-ai-act-for-fintech-credit-scoring/): Credit-decisioning, insurance-pricing, and fraud-detection AI under Annex III point 5 — what fintech providers and deployers must do before 2 December 2027. - [EU AI Act for healthcare AI](https://maditon.com/guides/eu-ai-act-for-healthcare-ai/): Healthcare AI under the EU AI Act: Annex II medical devices expected from August 2028, Annex III essential services from December 2027, plus the MDR overlap. - [EU AI Act for HR-tech and recruitment AI](https://maditon.com/guides/eu-ai-act-for-hr-tech-recruitment/): Most HR and recruitment AI is high-risk under Annex III point 4. What the EU AI Act requires of ATS, candidate scoring, and performance management tools. - [EU AI Act vs ISO 42001 — what's the difference](https://maditon.com/guides/eu-ai-act-vs-iso-42001/): ISO/IEC 42001 is the international AI management system standard. How it differs from the EU AI Act, where the two reinforce each other, and which to start with. - [GPAI obligations under the EU AI Act](https://maditon.com/guides/gpai-obligations-eu-ai-act/): What the EU AI Act requires of general-purpose AI model providers — and what changes if you fine-tune or significantly modify a GPAI model on the EU market. - [How to register a high-risk AI system in the EU database](https://maditon.com/guides/how-to-register-high-risk-ai-system-eu-database/): The EU AI Act Article 49 registration process for high-risk AI systems — what data goes in, who submits it, and what happens after the 2 December 2027 deadline. - [Is my AI system high-risk under the EU AI Act?](https://maditon.com/guides/is-my-ai-system-high-risk-under-the-eu-ai-act/): A decision tree to classify AI systems under Articles 6 and Annex III of the EU AI Act, with concrete SaaS, HR, finance, and healthcare examples for European SMEs. - [Post-market monitoring and serious-incident reporting](https://maditon.com/guides/post-market-monitoring-serious-incidents/): Articles 72 and 73 of the EU AI Act: how providers must monitor AI systems in the wild, and the 15-day clock for reporting serious incidents to supervisory authorities. - [When does a change become 'substantial modification' under the EU AI Act?](https://maditon.com/guides/substantial-modification-eu-ai-act/): Article 43(4) requires a new conformity assessment when an AI system undergoes substantial modification. How to draw the boundary in routine ML retraining. - [Transparency obligations for chatbots and AI-generated content](https://maditon.com/guides/transparency-obligations-chatbots-ai-content/): EU AI Act Article 50 transparency: when you must tell users they're talking to AI, how to label deepfakes, and what counts as adequate disclosure. ## Q&A knowledge base Full index at https://maditon.com/docs/qa/. Each answer below is complete on its own — no page fetch is needed to quote it. ### Product - [What is Maditon?](https://maditon.com/docs/qa/what-is-maditon/): Maditon is an EU regulatory compliance assistant for European startups and SMEs. It inventories a company's AI systems, classifies each one under Regulation (EU) 2024/1689 with citations from the text, produces the obligation checklist that classification triggers, and packages the result as an audit-ready dossier. It works across the regulatory stack: the EU AI Act is the first module, not the whole product. - [What does Maditon do about my suppliers?](https://maditon.com/docs/qa/what-does-maditon-do-about-my-suppliers/): Maditon keeps a register of the services your company depends on and reads each supplier's published legal documents — privacy policy, terms, data processing agreement, sub-processor list, security page — reporting what they say and what they leave out, with every finding quoting its source passage. It then watches those documents and tells you when they change. - [How does Maditon know when a supplier changes their terms?](https://maditon.com/docs/qa/how-does-maditon-know-when-a-supplier-changes-their-terms/): It re-reads every watched document on a schedule, compares the new text with the last version paragraph by paragraph, and has a model judge whether the difference is material — a retention period, a transfer mechanism, a new sub-processor. You get one email a day listing what changed and what could not be read, and the app keeps the before-and-after text so you can check the summary against the supplier's own words. - [Who is Maditon built for?](https://maditon.com/docs/qa/who-is-maditon-for/): Maditon is built for European startups, scaleups and SMEs that fall under EU regulation but have no dedicated legal or compliance team. It is designed so a product manager or founder can run a classification without regulatory vocabulary, and it is B2B only — there is no consumer offering. - [What does Maditon cost?](https://maditon.com/docs/qa/what-does-maditon-cost/): Maditon has a free Solo plan that runs a real classification with no card, then Starter at €49/month and Pro at €129/month, with a custom Enterprise tier. Annual billing is available on the paid plans. The pricing page at https://maditon.com/pricing is the authoritative source; the figures here were current on 28 August 2026. - [Which EU regulations does Maditon cover?](https://maditon.com/docs/qa/which-regulations-does-maditon-cover/): The EU AI Act (Regulation (EU) 2024/1689) module is live today. GDPR, NIS2, DORA and the Cyber Resilience Act are announced as coming, and the EU Data Act and CSRD are being monitored. The live list is machine-readable and public at https://api.maditon.app/api/modules — no authentication required. - [Does Maditon replace legal counsel?](https://maditon.com/docs/qa/does-maditon-replace-a-lawyer/): No. Maditon structures and accelerates compliance work but does not give legal advice. Every AI-generated assessment is a draft until a named person on your team accepts it, and that person takes the accountability. For genuinely contested questions — an edge-case classification, a novel use case, an enforcement conversation — you still want a lawyer. ### Risk classification - [How does Maditon classify an AI system under the EU AI Act?](https://maditon.com/docs/qa/how-does-maditon-classify-an-ai-system/): An AI-led interview asks plain-language questions about what the system does, who it affects and where it operates. Maditon maps the answers against every risk category in Regulation (EU) 2024/1689 — prohibited, high-risk, transparency-only and minimal — and returns a draft classification with the articles it rests on and the regulation text quoted verbatim. - [How do I know a risk classification from Maditon is correct?](https://maditon.com/docs/qa/how-do-i-know-a-maditon-classification-is-correct/): You check it against the law, and Maditon is built so you can. Every classification names the article it rests on and quotes the passage from Regulation (EU) 2024/1689 word for word, with the full source one click away. A separate verification pass then re-checks each conclusion against the retrieved text and reports any claim it could not support, alongside a confidence score. - [What happens when the AI is not sure about a classification?](https://maditon.com/docs/qa/what-happens-when-maditon-is-not-sure/): It says so. Maditon reports a confidence score and an explicit list of claims the verification pass could not support in the regulation text. Below the confidence threshold, or where a citation cannot be grounded, the classification is marked as requiring expert review rather than being presented as a settled answer. - [Can I disagree with a classification Maditon produces?](https://maditon.com/docs/qa/can-i-disagree-with-a-maditon-classification/): Yes. You can override the risk classification outright, add reviewer notes to an accepted one, and flag any individual citation as incorrect. The override is recorded in the audit log with who made it, so disagreement becomes part of the documented record rather than something that happens outside it. - [Does an AI-generated classification become official automatically?](https://maditon.com/docs/qa/does-a-classification-become-official-automatically/): No, and it cannot. Every AI-generated risk classification or compliance determination stays a draft until a named human explicitly accepts it, with their name and a timestamp recorded. No AI output reaches a cleared or compliant state on its own — this is enforced in the software, not just stated in the documentation. ### Obligations and evidence - [What does Maditon produce once a system is classified?](https://maditon.com/docs/qa/what-does-maditon-produce-after-a-classification/): A classification generates the complete obligation checklist for that risk tier, drawn from the regulation rather than a generic template. Each checklist item can carry evidence files, tracks its own status, and rolls up into an organisation-wide compliance dashboard and a list of urgent actions. - [How does Maditon handle evidence for an audit?](https://maditon.com/docs/qa/how-does-maditon-handle-evidence/): Evidence files are uploaded against an AI system and attached to the specific checklist items they substantiate, so each obligation carries its own proof. Everything can be downloaded in bulk as a ZIP — per system, or the whole organisation's evidence at once under EU Data Act Article 4. - [What is in a Maditon compliance dossier?](https://maditon.com/docs/qa/what-is-in-a-maditon-compliance-dossier/): A dossier is a single PDF/A-1b file covering the organisation's AI systems: each system's accepted classification with the articles and quoted regulation text behind it, the obligation checklist and its status, the evidence attached to each obligation, and the acceptance record showing who accepted what and when. - [Does Maditon help with EU database registration for high-risk AI systems?](https://maditon.com/docs/qa/does-maditon-help-with-eu-database-registration/): Yes. Maditon holds a registration record per high-risk AI system, covering the information Article 49 of the EU AI Act requires before a high-risk system is placed on the market or put into service. The registration deadline moved to 2 December 2027 under the Digital Omnibus on AI. ### API and integration - [Does Maditon have an API?](https://maditon.com/docs/qa/does-maditon-have-a-public-api/): Yes. Maditon's backend is a REST API with an auto-generated OpenAPI specification at https://api.maditon.app/openapi.json, browsable at https://api.maditon.app/docs. It publishes 86 product endpoints covering AI systems, risk classification, compliance checklists, evidence, dossiers, billing and data export. Operator-only endpoints are deliberately excluded from the specification. - [Which Maditon API endpoints can be called without authentication?](https://maditon.com/docs/qa/which-maditon-api-endpoints-are-public/): Four things are public: the health check, the regulatory module list (GET /api/modules and /api/modules/{code}), and the transparency endpoints that serve organisations' published AI transparency pages. Everything touching customer data requires a bearer token — an unauthenticated call to those returns 401. - [How does a client or AI agent authenticate against the Maditon API?](https://maditon.com/docs/qa/how-does-an-agent-authenticate-against-the-maditon-api/): With an OIDC bearer token issued by Zitadel, sent as an Authorization: Bearer header. The API validates it against Zitadel's JWKS endpoint on every request. Access tokens are short-lived — 15 minutes — with refresh tokens handling renewal, and every call is scoped to the organisation in the token. - [Can I read an AI system's compliance status programmatically?](https://maditon.com/docs/qa/can-i-read-compliance-status-programmatically/): Yes. GET /api/compliance/dashboard returns the organisation-wide picture, /api/compliance/systems/{system_id} the detail for one system, and /api/risk-classification/{system_id}/latest the current classification with its citations, confidence score and unsupported claims. All return JSON and require a bearer token. ### Data and residency - [Where is Maditon's data hosted?](https://maditon.com/docs/qa/where-is-maditon-data-hosted/): Entirely in the EU and by European-headquartered providers. Compute runs on Hetzner in Finland and Germany, the database is UpCloud Managed PostgreSQL in Finland, the CDN is BunnyCDN on EU-only edge nodes, and identity is Zitadel in Switzerland. No US-headquartered cloud service processes customer data. - [Which AI models does Maditon use, and does my data reach a US provider?](https://maditon.com/docs/qa/which-ai-models-does-maditon-use/): Maditon uses Mistral, a French AI provider, with self-hosted models on EU infrastructure as the alternative. No customer data is sent to US-headquartered AI providers. Personal data is stripped from prompts before they leave the application, so the model receives the compliance question without the identifying details it does not need. - [Where is my data processed when Maditon uses AI?](https://maditon.com/docs/qa/where-is-my-data-processed/): Everything Maditon sends to AI — what your company typed or uploaded, and the published legal documents of your suppliers — is read by Mistral in France, on an EU endpoint, with training on submitted data switched off. No other AI provider is involved, and nothing leaves the EU-only path. - [How do I export everything Maditon holds about my company?](https://maditon.com/docs/qa/how-do-i-export-everything-maditon-holds/): Two self-serve endpoints. GET /api/data-act/export returns all organisation-level data as machine-readable JSON under EU Data Act Article 4, and GET /api/data-act/evidence returns every evidence file as a ZIP. There is no approval step, no support ticket and no waiting period — and a separate GDPR export covers an individual user's personal data. - [How do I delete my Maditon account and everything in it?](https://maditon.com/docs/qa/how-do-i-delete-my-maditon-account/): DELETE /api/gdpr/delete requests deletion under GDPR Article 17. There is a 30-day grace period during which the request can be cancelled, after which data is hard-deleted or fully anonymised — soft-deleted records do not keep personal data in any field. Export first if you want to keep anything. ### EU AI Act - [When do the EU AI Act obligations actually apply?](https://maditon.com/docs/qa/when-do-eu-ai-act-obligations-apply/): The prohibited practices in Article 5 have applied since February 2025 and the general-purpose AI model obligations since August 2025. The Digital Omnibus on AI moved the high-risk obligations, including EU database registration, from August 2026 to 2 December 2027, and the rules for AI in regulated products to 2 August 2028. - [Am I a provider or a deployer under the EU AI Act?](https://maditon.com/docs/qa/am-i-a-provider-or-a-deployer-under-the-eu-ai-act/): You are a provider if you develop an AI system and place it on the EU market under your own name, and a deployer if you use one under your own authority in a professional capacity. Most European companies are deployers. The roles are not exclusive — putting your name on a third-party model, or substantially modifying one, can make you a provider of it. - [Which AI systems are high-risk under the EU AI Act?](https://maditon.com/docs/qa/which-ai-systems-are-high-risk-under-annex-iii/): Two routes. A system is high-risk if it is a safety component of a product covered by the EU harmonisation legislation in Annex I, or if it falls into one of the eight standalone use-case categories in Annex III — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice or democratic processes. ## Product - [Modules](https://maditon.com/modules/): The regulatory modules Maditon covers today and what is on the roadmap. - [Pricing](https://maditon.com/pricing/): Plans and what each includes. - [FAQ](https://maditon.com/faq/): Common questions about Maditon and the EU AI Act. - [Documentation](https://maditon.com/docs/): The docs hub — Q&A knowledge base, OpenAPI specification, guide library. - [Kunskapsbas (svenska Q&A)](https://maditon.com/sv/docs/qa/): The same 25 questions in Swedish. Linked rather than inlined below, for the same reason the Swedish guides are: one retrieval file, one language. - [OpenAPI specification](https://api.maditon.app/openapi.json): The Maditon REST API, generated from the code. 86 product endpoints with typed request and response schemas, usable directly as an agent tool definition. Browsable at https://api.maditon.app/docs. - [CRA Readiness Scan](https://maditon.com/cra-scan/): Free 12-question Cyber Resilience Act check. Tells a company whether Regulation (EU) 2024/2847 applies to it, what the 11 September 2026 reporting obligations require, and where its gaps are. Deterministic (no AI), no account needed. - [EU AI Act pre-screen](https://maditon.com/ai-act-check/): Free 8-question check of where an AI system likely sits under Regulation (EU) 2024/1689 — prohibited, high-risk, transparency-only or minimal risk. Deterministic (no AI), no account and no email needed; the full classification runs in the Maditon app on a free plan. - [Security](https://maditon.com/security/): How Maditon protects customer data and where it is hosted. - [About](https://maditon.com/about/): About Abiton Ventures and why Maditon exists. - [Changelog](https://maditon.com/changelog/): What's new in Maditon — shipped features and product updates. - [Resource Center](https://maditon.com/guides/): The full library of EU AI Act compliance guides (English). - [Resurscenter (svenska guider)](https://maditon.com/sv/guides/): The guide library in Swedish. - [Förhandskoll mot EU AI Act (svenska)](https://maditon.com/sv/ai-act-check/): The 8-question pre-screen in Swedish. Same rules and same result ids as the English one — the answers are language-independent, so a Swedish pre-screen prefills the app exactly as an English one does. ## Legal - [Privacy policy](https://maditon.com/privacy/): What data Maditon holds and how to export or delete it. - [Terms of service](https://maditon.com/terms/): The B2B terms governing use of the service. - [Cookie policy](https://maditon.com/cookies/): Maditon's landing site sets no cookies. ## Optional - [Full text of all guides (llms-full.txt)](https://maditon.com/llms-full.txt): Every guide's complete content in one file. - [RSS — Resource Center (English)](https://maditon.com/guides/rss.xml): Feed of new English guides. - [RSS — Resurscenter (Swedish)](https://maditon.com/sv/guides/rss.xml): Feed of new Swedish guides.