FAQ

FREQUENTLY
ASKED.

Everything you need to know about the EU AI Act and how euactguard works.

THE LAW

The EU AI Act is the world's first comprehensive legal framework for artificial intelligence, adopted in 2024. It classifies AI systems by risk level and imposes obligations on providers and deployers of AI systems operating in or affecting the EU market.

Key deadlines: prohibited AI practices banned from February 2025; general-purpose AI model obligations from August 2025; high-risk AI system obligations from August 2, 2026. Most engineering teams need to be compliant by August 2026.

It applies to providers (those who develop and place AI systems on the market) and deployers (those who use AI systems in a professional context) whose systems affect people in the EU — regardless of where the company is headquartered.

High-risk AI systems are defined in Article 6 and Annex III. They include AI used in critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice. If your AI system makes or influences decisions in these areas, it is likely high-risk.

THE PRODUCT

We connect to your GitHub repository via OAuth and analyze your source code. We map functions, model calls, data pipelines, and API endpoints to specific EU AI Act articles, identify violations, classify your system's risk tier, and generate remediations.

Python, JavaScript, TypeScript, Java, Go, and Rust. We can analyze any public or private GitHub repository regardless of framework.

Most repositories complete in 2–5 minutes. Large monorepos (1000+ files) may take up to 10 minutes. You receive a notification when your report is ready.

Yes. GitHub OAuth grants us read access to private repositories you select. We never request more than the minimum scopes needed and your token expires after 1 hour.

Articles 6, 9, 10, 11, 12, 13, 14, 17, 26, and 50 — covering risk classification, data governance, transparency, human oversight, record-keeping, documentation, and AI disclosure requirements.

DATA & PRIVACY

No. Source files are fetched from GitHub, analyzed in memory, and immediately discarded. We store only the compliance findings: article scores, violation summaries, file paths, and remediations.

Compliance findings are stored in a Postgres database hosted on infrastructure that maintains SOC 2 Type II compliance. All data is encrypted at rest and in transit.

Yes. You can delete your account and all associated scan data at any time from your Settings page. Deletion is permanent and immediate.

Your GitHub OAuth token is stored only in a short-lived, httpOnly session cookie. It is never written to our database. It expires after 1 hour and can be revoked instantly from GitHub settings.

RESULTS

Our analysis uses structured AI reasoning grounded in the actual text of the EU AI Act. We are precise about what the law requires and transparent about edge cases where human legal review is recommended.

We flag borderline cases explicitly. The report will indicate when a finding requires human legal or compliance review rather than claiming certainty where the law is ambiguous.

Yes. Every scan can be exported as PDF (formatted for regulators and legal teams) or JSON (formatted for engineering tooling). Both formats are available from the scan detail page.

A high compliance score means your codebase aligns well with the EU AI Act's technical requirements. It is not a legal certification. For formal compliance, you will also need organizational measures and potentially legal advice for your specific context.

STILL HAVE
QUESTIONS?

Start a free scan — the report will answer most of them for your specific codebase.

Start Free →