Every regulation your digital product triggers, in one place.
Grecta covers 20+ European and international frameworks — and determines which ones apply to your specific AI system from a plain-language description. You do not pick from a list. The engine does. Review the complete compliance frameworks list - on average, 3 to 8 of them apply to your product.
The frameworks we govern
Every framework below is mapped at obligation level — specific articles, specific evidence requirements, specific cross-framework overlaps. Not checklists. The actual law, translated into what your AI system owes.
EU AI Act
The world's first binding AI regulation. Grecta maps every EU AI Act obligation your system carries — from risk management under Article 9 to transparency under Article 50 — at article level, not control level.
GDPR
The baseline for any AI system processing personal data in Europe. Grecta identifies whether your system triggers a mandatory DPIA, automated decision-making obligations, or special category data requirements.
Cyber Resilience Act
Applies to any AI product with digital elements placed on the EU market. Grecta determines whether your product falls under default, Important Class I, or Critical Class II requirements.
DORA
Digital operational resilience for financial entities and the ICT providers that serve them. Grecta flags whether your AI system triggers DORA directly or through your customer base.
NIS2
Network and information security obligations for essential and important sector entities. Grecta evaluates your organisation's sector and size to determine whether NIS2 applies and at which tier.
Medical Device Regulation
AI software intended to support clinical decisions is a medical device under EU law. Grecta identifies MDR scope and maps the technical documentation overlap with the EU AI Act.
IVDR
In-vitro diagnostic regulation for AI used in specimen analysis and diagnostic processes. Grecta determines IVDR scope and risk classification from your system's intended purpose.
EU Data Act
Applies to connected products and related services generating usage data. Grecta identifies whether your AI system triggers data access and portability obligations under the Data Act.
ISO 42001
The international standard for AI management systems — voluntary but increasingly required by enterprise procurement. Grecta maps ISO 42001 clauses against your EU AI Act obligations to close both with the same documentation.
NIST AI RMF
The US voluntary framework for AI risk management. Grecta shows where your EU AI Act compliance work already satisfies NIST functions — useful for US market access and procurement requirements.
Digital Services Act
Applies to intermediary services, platforms, and search engines with EU users. Grecta determines whether your AI system triggers DSA transparency and recommender system obligations.
Data Governance Act
Applies to data intermediaries and data altruism organisations. Grecta identifies whether your AI system's data-sharing role triggers DGA obligations alongside GDPR.
EU AI Liability Directive
Applies in civil liability proceedings involving high-risk AI systems. Grecta shows how your EU AI Act compliance documentation functions as your primary liability defence.
GPAI Code of Practice
The EU AI Act's implementing instrument for general-purpose AI model providers. Grecta distinguishes between providers of GPAI models and deployers who use them — obligations differ fundamentally.
Revised Product Liability Directive
Software is now a product under EU law. Grecta maps the evidence overlap between PLD disclosure obligations and your EU AI Act technical documentation.
ePrivacy Directive
Applies where your AI system uses cookies, tracking technologies, or provides electronic communications services. Grecta identifies ePrivacy obligations alongside GDPR for the same system.
Colorado AMDTA
US state-level AI regulation for high-risk systems serving Colorado consumers. Grecta evaluates US AI applicability for European companies with US market exposure.
HEAT Framework (Cambridge AI Lab)
The Human, Ethical, Accountable and Transparent AI framework developed by the University of Cambridge AI Lab. Grecta maps HEAT principles against your EU AI Act obligations — particularly risk management, human oversight, and transparency — closing both with the same evidence set.
General Product Safety Regulation
Applies to any product placed on the EU market that consumers can use, including AI-enabled hardware and consumer-facing software. Grecta identifies GPSR scope and maps its safety obligations against MDR, CRA, and the EU AI Act where they apply to the same product.
Radio Equipment Directive
Applies to any hardware product that emits or receives radio waves — including AI-enabled IoT devices, wearables, and connected hardware with WiFi or Bluetooth. Grecta identifies RED scope and the cybersecurity requirements that apply to internet-connected radio equipment from August 2025.
MiFID II
Applies where your AI system provides investment advice, portfolio management, or automated trading functionality. Grecta identifies MiFID II obligations for fintech AI alongside DORA and the EU AI Act.
PSD3
Payment services regulation for AI systems in the payments and open banking space. Grecta maps PSD3 applicability for payment AI alongside DORA and GDPR.
AMLD6 / AML Regulation
Anti-money laundering obligations for AI systems supporting KYC, transaction monitoring, or suspicious activity reporting at obliged entities. Grecta identifies AML scope from your system's function and customer base.
Solvency II
Applies to insurance and reinsurance undertakings using AI in underwriting, pricing, claims assessment, or solvency calculations. Grecta identifies Solvency II obligations alongside DORA and the EU AI Act for insurance AI systems.
How Grecta determines which frameworks apply You describe your AI system in plain English. The engine extracts what matters — sector, geography, your role, whether personal data is involved, how autonomous the system is — and evaluates your description against every framework in the library. You see only the frameworks that apply to your specific system, with a plain-English explanation of why each one applies. No menu to navigate. No frameworks to pick. The engine does the work.
Start with the EU AI Act, free.
Bring your first AI system under governance against the EU AI Act at no cost — no card, no time limit. Add further frameworks as your systems enter their scope. Existing evidence carries forward automatically.
Join the waitlist!Work email required. Accounts activate within 24 hours.
Compliance Frameworks FAQ
Grecta maps obligations at article level — Article 9(1) through 9(9) are separate obligations with separate evidence requirements, not a single "risk management" control. Every obligation carries its determinacy classification, temporal type, and the specific evidence that closes it.
That is the common case, not the exception. Grecta shows where one piece of evidence satisfies obligations across multiple frameworks at once. For example, your GDPR DPIA covers most of your EU AI Act Article 9 requirement, your MDR technical file satisfies EU AI Act Article 11. You build the control once and it counts everywhere it applies.
Yes. When a new framework is added to the library, it is evaluated against your existing AI systems automatically. Obligations that fire are surfaced in your review queue. Your existing evidence carries forward and is mapped against the new obligations where coverage applies.