About Legalithm

We are building the compliance infrastructure for products entering Europe.

Legalithm connects regulation to the products companies actually build, so teams can understand what applies, implement what is required, prove it with evidence, and keep that record current as products and regulation change. Where we are today: Legalithm focuses on EU AI Act compliance, with further regulatory packs expanding incrementally as they are validated.

Where we are today

  • Started

    2026

    Legalithm is early and we are not going to dress that up. One founder, Pedram Madani. No support queue, so if something is wrong you are talking to the person who built it.

  • Access

    Free while we build

    Run the public assessment with no account required.

  • Early users

    Founding member access

    Early users shape what gets built next and keep their access terms as this grows.

Our mission

Make regulatory market access understandable and operational for every company building products for Europe.

Regulation increasingly shapes product architecture, engineering, security, accessibility and AI, not only legal teams. Yet compliance stays fragmented across law firms, spreadsheets, security tools and disconnected questionnaires, none of which know what the others concluded.

Legalithm exists to connect those pieces.

The problem

Compliance was designed around documents. Products change every day.

A modern product might depend on:

  • AI models
  • Cloud infrastructure
  • Software components
  • Third-party suppliers
  • Personal data
  • Customer-facing interfaces

And it may face, at the same time:

  • EU AI Act
  • Cyber Resilience Act
  • European Accessibility Act
  • GDPR
  • ISO standards
  • Customer assurance requirements

The problem is not simply: what does Article X say?

The harder question: what does it mean for this product, and can we prove we have done what is required?

Legalithm is being built around that question.

Available today

What can Legalithm do today?

Legalithm does EU AI Act compliance today. You describe an AI system and get a risk classification under Articles 5, 6 and 50, produced by a rule based engine rather than a model guessing at law, with the article, the effective date and the rules version attached to the answer. From that classification it maps which obligations bind you and in which role, drafts Annex IV technical documentation from your actual answers, and writes the result into a compliance record that is hash chained to the one before it, so any later edit is visible rather than erasable. You hold the signing key and we never see it. The same checks run from a command line tool, an MCP server or a GitHub Action, so compliance can run where the product is built. Everything here is free while we build.

  • AI Act risk classification

    Rule based and cited to source, with a versioned rules engine so past assessments can be checked against what the rules said at the time.

  • Obligation mapping

    Which articles bind you, in which role, from which date, with the legal basis attached to each one.

  • A compliance record you can verify

    Hash chained and tamper evident, with a customer held signing key. We never see your key.

  • Annex IV draft generation

    Structured technical documentation from your actual assessment answers, clearly flagged where a human still needs to finish it.

  • Developer tooling

    A command line tool, an MCP server and a GitHub Action, all public, so an AI Act check can run where the product is actually built rather than in a separate portal.

Vision

What we are building

One record engine across the regulations a product faces. Products and AI systems on one side, obligations and evidence on the other, and a dated, signed record connecting them that stays current as both change.

Three regulatory packs already share that engine: the EU AI Act, the European Accessibility Act, and the Cyber Resilience Act. This is the direction, not a description of what ships today.

Our approach

Six commitments that decide what we build and what we refuse to claim. Each one is checkable against the product rather than a statement of intent.

Regulation first

Every result traces back to the underlying regulatory requirement: the article, the effective date, and the version of the rules it was decided under. A conclusion you cannot follow back to a source is not a conclusion.

AI can assist compliance. It should not invent the law.

Applicability and obligation decisions run on deterministic rules and cited sources, not an opaque model. Where the law requires human judgment, the engine says so and defers rather than asserting.

Product, not paperwork

Compliance attaches to the product, its components, its controls and its evidence, instead of living as an isolated annual checklist that is true on the day it is signed and stale a week later.

Evidence over checkboxes

A tick in a box is not proof. Every classification is hash chained to the one before it, so edit history is visible rather than erasable, and you hold your own signing key.

Show what is live

Roadmap is never presented as shipped product. Where something is planned rather than built, the page says so in the same sentence.

Understanding your obligations should not require a sales call

The public assessment runs without an account, and the command line tool, MCP server and GitHub Action are public. Working out what applies to you is the part that should never be gated.

Find out what applies to your product.

Run the public AI Act assessment. No account required. Legalithm's outputs are operational guidance and do not constitute legal advice.