AI Act · NIS2 · DORA · GDPR — watched weekly at the source. Proposals are not law; no deadline moves on a press release.
Sovereign AI Readiness Platform

Regulated organisations that can prove their readiness win the contracts, the funding, and the regulator's trust. Most are still guessing.

One assessment, all four regimes. Every applicable obligation, every gap, a roadmap ordered by leverage — in days, cited to the law, yours to execute with anyone. Then we keep the proof current.

4
EU regimes under live watch
€35M
Maximum AI Act fine
24h
NIS2 incident early-warning duty
13
Controls, one evidence base
🇩🇪
Hetzner Germany
Infrastructure hosted on German-regulated servers. No US data routing.
🇫🇷
Mistral AI France
AI inference via European-native models. No dependence on US hyperscalers.
🇩🇰
Cordero Management Denmark
Operated from Copenhagen. EU jurisdiction. Legal and advisory accountability here.
🇪🇺
GDPR Native
Designed from the ground up under EU data protection law. No bolt-on compliance.
🤝
AI Pact applicant
Registered with the European AI Office AI Pact. Pillar I network member. Pillar II pledges submitted April 2026.
01

How it works

Step 01 · As-is

See where you actually stand

A guided assessment maps you against all four regimes — verified against EU and Danish law. Days, not consultant-months.

Step 02 · To-be

Get the roadmap — yours, unconditionally

Every gap prioritised by leverage, plus the architecture verdict — derived from your risk profile, not our sales targets. Sealed, cited, complete in itself.

Step 03 · Prove & progress

Prove it, continuously

Hash-verifiable attestations, board-visible progress, and a weekly watch on the law itself.

Live product preview
What your compliance dashboard looks like
Cordero Management
Dashboard AI Systems Tasks Reports Settings
Current stage
Unaware
Next: Inventoried — begin AI system intake
AI Act · 2 gaps open NIS2 · important entity DORA · not applicable GDPR · applies
AI Systems
0
identified
High-risk
classified
Tasks open
assigned
AI Act high-risk date
Dec 2, 2027 (Annex III)
System name Vendor Risk tier Stage Open tasks

Your full compliance picture — every system, every obligation, every open task — visible from day one.

02

One evidence base, four regulations

Four laws demand largely the same proof. Klarr keeps it as thirteen controls — fix one, close obligations in several laws at once. Every reference is to the operative article or Danish paragraph.

01 Regulatory classification Which laws apply to you, in what role — documented. + Which laws this serves
Risk tiers under the AI Act, entity class under NIS2, regime routing for finance, energy and telecom — each determination versioned, rationale cited to the paragraph.AI Act Art. 6NIS2 §§ 4–5DORA scoping
02 Incident detection & reporting One runbook. Three laws satisfied. + Which laws this serves
One incident-response capability, evidenced once, carries the AI Act’s serious-incident duty, NIS2’s 24h/72h/1-month chain, and DORA’s ICT-incident regime simultaneously.AI Act Art. 73NIS2 §§ 12–13DORA Art. 17–19
03 Technical documentation Design records, policies, and the technical file. + Which laws this serves
The AI Act’s Annex IV file and NIS2’s security policies draw on the same documentation discipline — maintained once, mapped to each law’s wording.AI Act Art. 11NIS2 § 6 nr. 1, 5
04 Human & management oversight Board approval, oversight roles, escalation paths. + Which laws this serves
The AI Act requires human oversight of high-risk systems; NIS2 makes the management body personally accountable for approving and supervising measures. Same governance spine.AI Act Art. 14, 26NIS2 § 7
05 Continuous monitoring Post-market surveillance and effectiveness assessment. + Which laws this serves
Monitoring systems in production and assessing whether your measures actually work — required, in different words, by three regimes.AI Act Art. 72NIS2 § 6 nr. 6DORA Art. 10
06 Regulatory registration The registers you must be in — and prove you are. + Which laws this serves
High-risk AI systems in the EU database; NIS2 entities with the competent authority within two weeks of coverage. Binary, checkable, and often overdue.AI Act Art. 49NIS2 § 10
07 Literacy & training Staff and management trained — with records to show. + Which laws this serves
AI literacy for everyone touching AI systems; cyber-risk training for the management body itself under NIS2. One training programme, two statutory duties.AI Act Art. 4NIS2 § 7 stk. 2, § 6 nr. 7
08 Transparency & disclosure Telling people what your systems are and do. + Which laws this serves
AI-interaction notices and synthetic-content labelling under the AI Act; information duties under the GDPR. Disclosure as a maintained control, not a footnote.AI Act Art. 50GDPR Art. 13–14
09 Continuity & disaster recovery Backups, recovery, crisis management — exercised. + Which laws this serves
NIS2 demands it as a named measure; DORA builds an entire resilience-testing regime on it. Evidence the capability once.NIS2 § 6 nr. 3DORA Art. 11–12
10 Supply-chain security Your vendors are your risk surface — and your sovereignty. + Which laws this serves
Vendor risk assessment under NIS2, the full ICT third-party regime under DORA — and the layer where EU-sovereignty of your stack becomes checkable fact.NIS2 § 6 nr. 4DORA Ch. V
11 Cryptography & encryption Policies for what gets encrypted, how, and by whom. + Which laws this serves
A named NIS2 measure and the canonical GDPR Art. 32 safeguard — one policy set, two regimes.NIS2 § 6 nr. 8GDPR Art. 32
12 Identity, access & assets Who can touch what — MFA, access control, asset inventory. + Which laws this serves
Personnel security, access policies and asset management under NIS2, ICT access rules under DORA. The control auditors check first.NIS2 § 6 nr. 9–10DORA Art. 9
13 Fundamental-rights impact Impact assessments where deployment demands them. + Which laws this serves
The AI Act’s FRIA for high-risk deployers and the GDPR’s DPIA are cousins — assessed with shared machinery, filed as separate artefacts.AI Act Art. 27GDPR Art. 35
03

Readiness stages

Stage 01UnawareNo inventory. No classification. Exposure unknown and unmanaged.
Stage 02InventoriedAI systems identified and documented. Risk tiers not yet assigned.
Stage 03AssessedRisk classification complete. Obligations identified per system.
Stage 04ControlledDocumentation, oversight, and monitoring mechanisms in place.
Stage 05CompliantAll obligations met. Audit-ready. Board-reportable. Deadline secure.
Proof, not promises

Watched at the source.
Proven by hash.

Every Monday, Klarr sweeps EUR-Lex and retsinformation.dk at the primary-source level. When the law moves, you know — and when it doesn’t, no one moves your deadlines on a press release.

4 regimes · 5 watched sources · EUR-Lex SPARQL + national document hashes · weekly

Klarr readiness seal - live from production

This is not a mock-up — it is our own seal, rendered live from production. Score, stage, and validity, resolved by SHA-256 hash. Green is earned, never decorative. Verify it →

04

Engagement & pricing

What you are replacing

Finding out where you stand across GDPR, NIS2, DORA and the AI Act is normally a consulting engagement per regulation: interviews across the organisation, weeks of analysis, a report that starts decaying the day it lands — then the same again next year, and again for the next law.

Klarr runs the as-is assessment across all four regimes at once, in days. The roadmap is yours to execute with anyone — your own team, your existing advisors, or us. The assessment is complete in itself; the platform is there when you want the posture maintained and provable continuously.

The comparison is not with other software. It is with the alternative.

Cost of the alternative
Consultant as-is assessment — per regulation1–3 weeks at €1,500–2,500/day, per regime. Four regimes: do the maths.
€10,000–40,000+
Legal review — per system, per cycleRepeated for every high-risk system, every annual update.
€3,000–6,000
Internal coordination overheadInventory, evidence-chasing, board prep — across four regimes now.
€1,200–2,400/mo
Klarr Readiness AssessmentAll four regimes, sealed report, prioritised roadmap, architecture verdict. Fixed fee, scoped to your estate.
fixed fee

Based on EU market consulting day rates. Your costs will vary. The direction will not.

Platform
from €149
per month · scales with your estate

The posture, maintained: evidence, watch, attestations that stay current.

  • Continuous readiness across all four regimes
  • Thirteen-control evidence base
  • Live watch: EUR-Lex + Danish law, weekly
  • Verifiable attestations (the Klarr Seal)
  • Snapshot-over-snapshot progress for the board
  • Regulatory alerts when the law moves
Design Partnership
Custom
bespoke engagement

Government and regulated finance: tailored scope, executive workshops, a direct line.

  • Tailored regime scope and depth
  • On-site assessment and executive briefings
  • Legal review integration
  • Sector add-ons (clinical, financial, HR AI)
  • SLA-backed advisory
  • Early access to new regime modules

Turn European regulation from a liability into a competitive advantage.

Know where you stand before your board, your investors, or a regulator asks. Request access — or reach us directly.

Klarr is a compliance intelligence platform, not a law firm. Nothing on this platform constitutes legal advice. Output from Klarr should be reviewed with qualified legal counsel before reliance in regulatory, contractual, or enforcement contexts. Cordero Management ApS accepts no liability for decisions made based solely on platform output.