AI Sigil is an AI governance platform that maps AI systems to regulatory obligations, tracks controls, and collects the evidence that proves compliance — with every control quoting the source law verbatim.
What is AI Sigil?
AI Sigil is an AI governance platform for compliance, legal, and AI development teams. It takes an inventory of an organization's AI systems — models, datasets, actions, interfaces, and use cases — and outputs a mapped control set, completed assessments, and an audit pack. It runs as a hosted web app at app.aisigil.com, is EU-hosted and GDPR-compliant, and is offered with a free 14-day trial.
Key Features
- AI system registry — Register AI systems, classify them by risk tier, and map their components: models, datasets, actions, interfaces, and use cases.
- Framework activation — Turn on a framework and its controls and obligations populate automatically, scoped to each system's risk level and the organization's provider or deployer role.
- Control assessment workflow — Work through each control by answering pre-built evaluations, attaching evidence, and tracking completion while the audit trail builds itself.
- EU AI Act coverage — 113 articles mapped and 62 controls derived directly from the text, with provider and deployer roles distinguished and content adapting to minimal, limited, high-risk, GPAI, and systemic GPAI classifications.
- ISO 42001 coverage — 10 clauses plus 38 Annex A controls mapped from the standard text, with AI lifecycle roles (provider, developer, user, customer) distinguished and alignment to the EU AI Act control library.
- NIST AI RMF (coming soon) — Govern, Map, Measure, and Manage functions and subcategories mapped from NIST AI 100-1, cross-mapped to the EU AI Act and ISO 42001 libraries.
- Verbatim legal citations — Every control quotes the legal basis or standard text, and every piece of evidence is one click from the regulation that demands it.
- Regulation tracking — Controls, evidence requirements, and evaluation forms are kept current when delegated acts, standard revisions, or new guidelines land.
Who is it for?
- Compliance teams — Maintain a single AI inventory and prove control completion with an audit trail tied to specific articles.
- Legal teams — Read the source text behind each control in two clicks and hold auditor conversations grounded in the regulation itself.
- AI development teams — Register and classify systems as they ship, so governance work produces the audit pack as a by-product.
Use cases
- EU AI Act readiness: Register each AI system, set its risk classification and provider/deployer role, and receive the obligations that bind it.
- ISO 42001 management system: Activate the standard's clauses and Annex A controls, answer the shipped evaluation forms, and file evidence against each control.
- Audit preparation: Produce an audit pack from the same workflow used to govern AI, rather than assembling documentation at the end.
How does AI Sigil work?
- Register AI systems and classify them, mapping models, datasets, actions, interfaces, and use cases.
- Activate the frameworks that apply; controls and obligations populate scoped to each system's risk level and role.
- Assess each control by answering evaluations and attaching evidence while the audit trail builds automatically.