
EU AI Act Compliance Tool - Risk classification and bias testing
🇪🇺 Open-Source Evidence Toolkit For AI Compliance
Open evidence format • Local bias evaluation • Schema validation • CycloneDX interoperability
Offline-first • Privacy-preserving • Reusable artifacts • WCAG 2.2 AA accessible
EuConform defines an open evidence format for AI compliance and provides the tools to produce, validate, and empirically evaluate it — offline and vendor-independent.
[!IMPORTANT] Legal Disclaimer: This tool provides technical guidance only. It does not constitute legal advice and does not replace legally binding conformity assessments by notified bodies or professional legal consultation. Always consult qualified legal professionals for compliance decisions.
🚀 Quick Start · 📖 Docs · 🌐 Deploy · 🐛 Report Bug
| Feature | Description |
|---|---|
| 🧾 Open Evidence Format | Produce portable report, aibom, ci, and bundle artifacts as inspectable JSON documents |
| 🧪 Local Bias Evaluation | CrowS-Pairs-based model evaluation with log-probability and latency fallback — reproducible, offline, no vendor dependency |
| ✅ Schema Validation | Validate EuConform JSON documents against the published schemas with euconform validate |
| 📦 Bundle Verification | Verify manifest, directory, or ZIP bundle integrity before handing artifacts to CI, reviewers, or auditors |
| 🚦 Compliance CI Gate | Turn euconform scan into GitHub-native annotations, CI summaries, and machine-readable artifacts |
| 🎯 Risk Classification | Interactive quiz implementing EU AI Act Article 5 (prohibited), Article 6 + Annex III (high-risk) |
| 🔄 CycloneDX Interoperability | Import external CycloneDX SBOMs into the EuConform AI BOM layer as an interoperability bridge |
| 🌐 Offline-First | Core evidence workflows stay local and inspectable instead of depending on vendor dashboards |
| 🔒 Privacy-Preserving | Zero tracking, no cookies, no external fonts – your data stays under your control |
| 🌙 Dark Mode | Beautiful glassmorphism design with full dark mode support |
| ♿ Accessible | WCAG 2.2 AA compliant with full keyboard navigation |
| 🌍 Multilingual | English and German interface |
| Command | Primary output | Use case |
|---|---|---|
scan | Native EuConform artifacts | Generate structured evidence from a real repository |
bias | Bias report JSON and/or Markdown | Run reproducible local model evaluation with Ollama — EuConform's distinctive empirical layer |
validate | Valid/invalid status per JSON file | Check EuConform JSON files against published schemas |
verify | Bundle integrity status | Check a manifest, extracted bundle, or ZIP archive |
import | euconform.aibom.json | Map an external CycloneDX SBOM into the EuConform AI BOM layer |
Want to try it without installation? Click the 🌐 Deploy link above to start your own instance on Vercel.
# Clone the repository
git clone https://github.com/Hiepler/EuConform.git
cd EuConform
# Install dependencies
pnpm install
# Start development server
pnpm dev
# Open http://localhost:3001
The repo-local examples below use the built CLI directly:
# Build the CLI
pnpm --filter @euconform/cli build
Generate native EuConform artifacts from a real codebase:
node packages/cli/dist/index.js scan . --scope production
This writes:
.euconform/euconform.report.json.euconform/euconform.aibom.json.euconform/euconform.summary.md.euconform/euconform.bundle.jsonTypical use:
For CI usage, add GitHub-native annotations and fail thresholds:
node packages/cli/dist/index.js scan . --scope production --ci github --fail-on high
For portable artifact exchange, create a bundle archive:
node packages/cli/dist/index.js scan . --scope production --zip true
Validate individual EuConform JSON documents against the published schemas:
node packages/cli/dist/index.js validate .euconform
Typical output:
euconform.aibom.json — valid (euconform.aibom.v1)0 for fully valid input, 1 for schema errors, 2 when no EuConform JSON files are foundVerify a bundle manifest, extracted bundle directory, or ZIP archive:
node packages/cli/dist/index.js verify .euconform/euconform.bundle.json
Typical use:
Run a reproducible CrowS-Pairs bias evaluation against a local Ollama model:
node packages/cli/dist/index.js bias llama3.2 --lang de --output all
This is EuConform's distinctive empirical evidence layer. It produces model-behavior data that no other open-source compliance tool currently offers — completely offline, reproducible, and independent of any vendor API.
Typical use:
scanMap an external CycloneDX JSON file into the EuConform AI BOM layer:
node packages/cli/dist/index.js import ./third-party.cdx.json \
--scope production \
--output /tmp/euconform-import
node packages/cli/dist/index.js validate /tmp/euconform-import/euconform.aibom.json