2 Aug 2026 — still the binding AI Act date (23 days) · the Omnibus would move it, but proposals are not law · watched weekly at the source
Sovereign AI Readiness Platform

Regulated organisations that can prove their readiness win the contracts, the funding, and the regulator's trust. Most are still guessing.

Klarr shows exactly where your organisation stands across the EU AI Act, NIS2, DORA and GDPR: which obligations apply, what evidence is missing, and what to fix first. Verified against EU and Danish law at the primary-source level.

4
EU regimes under live watch
€35M
Maximum AI Act fine
24h
NIS2 incident early-warning duty
13
Controls, one evidence base
🇩🇪
Hetzner Germany
Infrastructure hosted on German-regulated servers. No US data routing.
🇫🇷
Mistral AI France
AI inference via European-native models. No dependence on US hyperscalers.
🇩🇰
Cordero Management Denmark
Operated from Copenhagen. EU jurisdiction. Legal and advisory accountability here.
🇪🇺
GDPR Native
Designed from the ground up under EU data protection law. No bolt-on compliance.
🤝
AI Pact applicant
Registered with the European AI Office AI Pact. Pillar I network member. Pillar II pledges submitted April 2026.
01

How it works

Step 01 · As-is

See where you actually stand

A guided assessment maps your organisation and its systems against the AI Act, NIS2, DORA and GDPR — which regimes apply, in what role, and which obligations follow. Verified against EU and Danish law at the primary-source level. Days, not consultant-months.

Step 02 · To-be

Get the roadmap — yours, unconditionally

Every gap, prioritised by leverage: one fix often closes obligations in several regulations at once. You get a sealed report, a prioritised roadmap, and an architecture verdict — reference architecture, sovereign runtime, or air-gapped — derived from your risk profile, not our sales targets. Execute it with anyone. The assessment is complete in itself.

Step 03 · Prove & progress

Prove it, continuously

Hash-verifiable attestations you can hand to a regulator, an investor, or procurement. Snapshot-over-snapshot progress your board can see. And a live watch on EUR-Lex and Danish law — when the rules move, you know Monday morning.

Live product preview
What your compliance dashboard looks like
Cordero Management
Dashboard AI Systems Tasks Reports Settings
Current stage
Unaware
Next: Inventoried — begin AI system intake
AI Act · 2 gaps open NIS2 · important entity DORA · not applicable GDPR · applies
AI Systems
0
identified
High-risk
classified
Tasks open
assigned
AI Act high-risk date
Aug 2, 2026
System name Vendor Risk tier Stage Open tasks

Your full compliance picture — every system, every obligation, every open task — visible from day one.

02

One evidence base, four regulations

GDPR, NIS2, DORA and the AI Act demand largely the same proof in four different vocabularies. Klarr maintains thirteen controls — fix one, and obligations close in several laws at the same time. Every reference below is to the operative article or Danish paragraph.

01 Regulatory classification Which laws apply to you, in what role — documented. + Which laws this serves
Risk tiers under the AI Act, entity class under NIS2, regime routing for finance, energy and telecom — each determination versioned, rationale cited to the paragraph.AI Act Art. 6NIS2 §§ 4–5DORA scoping
02 Incident detection & reporting One runbook. Three laws satisfied. + Which laws this serves
One incident-response capability, evidenced once, carries the AI Act’s serious-incident duty, NIS2’s 24h/72h/1-month chain, and DORA’s ICT-incident regime simultaneously.AI Act Art. 73NIS2 §§ 12–13DORA Art. 17–19
03 Technical documentation Design records, policies, and the technical file. + Which laws this serves
The AI Act’s Annex IV file and NIS2’s security policies draw on the same documentation discipline — maintained once, mapped to each law’s wording.AI Act Art. 11NIS2 § 6 nr. 1, 5
04 Human & management oversight Board approval, oversight roles, escalation paths. + Which laws this serves
The AI Act requires human oversight of high-risk systems; NIS2 makes the management body personally accountable for approving and supervising measures. Same governance spine.AI Act Art. 14, 26NIS2 § 7
05 Continuous monitoring Post-market surveillance and effectiveness assessment. + Which laws this serves
Monitoring systems in production and assessing whether your measures actually work — required, in different words, by three regimes.AI Act Art. 72NIS2 § 6 nr. 6DORA Art. 10
06 Regulatory registration The registers you must be in — and prove you are. + Which laws this serves
High-risk AI systems in the EU database; NIS2 entities with the competent authority within two weeks of coverage. Binary, checkable, and often overdue.AI Act Art. 49NIS2 § 10
07 Literacy & training Staff and management trained — with records to show. + Which laws this serves
AI literacy for everyone touching AI systems; cyber-risk training for the management body itself under NIS2. One training programme, two statutory duties.AI Act Art. 4NIS2 § 7 stk. 2, § 6 nr. 7
08 Transparency & disclosure Telling people what your systems are and do. + Which laws this serves
AI-interaction notices and synthetic-content labelling under the AI Act; information duties under the GDPR. Disclosure as a maintained control, not a footnote.AI Act Art. 50GDPR Art. 13–14
09 Continuity & disaster recovery Backups, recovery, crisis management — exercised. + Which laws this serves
NIS2 demands it as a named measure; DORA builds an entire resilience-testing regime on it. Evidence the capability once.NIS2 § 6 nr. 3DORA Art. 11–12
10 Supply-chain security Your vendors are your risk surface — and your sovereignty. + Which laws this serves
Vendor risk assessment under NIS2, the full ICT third-party regime under DORA — and the layer where EU-sovereignty of your stack becomes checkable fact.NIS2 § 6 nr. 4DORA Ch. V
11 Cryptography & encryption Policies for what gets encrypted, how, and by whom. + Which laws this serves
A named NIS2 measure and the canonical GDPR Art. 32 safeguard — one policy set, two regimes.NIS2 § 6 nr. 8GDPR Art. 32
12 Identity, access & assets Who can touch what — MFA, access control, asset inventory. + Which laws this serves
Personnel security, access policies and asset management under NIS2, ICT access rules under DORA. The control auditors check first.NIS2 § 6 nr. 9–10DORA Art. 9
13 Fundamental-rights impact Impact assessments where deployment demands them. + Which laws this serves
The AI Act’s FRIA for high-risk deployers and the GDPR’s DPIA are cousins — assessed with shared machinery, filed as separate artefacts.AI Act Art. 27GDPR Art. 35
03

Readiness stages

Stage 01UnawareNo inventory. No classification. Exposure unknown and unmanaged.
Stage 02InventoriedAI systems identified and documented. Risk tiers not yet assigned.
Stage 03AssessedRisk classification complete. Obligations identified per system.
Stage 04ControlledDocumentation, oversight, and monitoring mechanisms in place.
Stage 05CompliantAll obligations met. Audit-ready. Board-reportable. Deadline secure.
Proof, not promises

Watched at the source.
Proven by hash.

Every Monday at 06:00, Klarr sweeps EUR-Lex and retsinformation.dk at the primary-source level — amending acts, legislative proposals, corrigenda, and the Danish transposition texts themselves. When the law moves, you know. When it doesn’t, you know that too — and no deadline moves on a press release, because proposals are not law.

4 regimes · 5 watched sources · EUR-Lex SPARQL + national document hashes · weekly

Klarr readiness seal - live from production

This is not a mock-up — it is our own seal, rendered live from production. Score, stage, and validity, resolved by SHA-256 hash. Green is earned, never decorative. Verify it →

04

Engagement & pricing

What you are replacing

Finding out where you stand across GDPR, NIS2, DORA and the AI Act is normally a consulting engagement per regulation: interviews across the organisation, weeks of analysis, a report that starts decaying the day it lands — then the same again next year, and again for the next law.

Klarr runs the as-is assessment across all four regimes at once, in days. The roadmap is yours to execute with anyone — your own team, your existing advisors, or us. The assessment is complete in itself; the platform is there when you want the posture maintained and provable continuously.

The comparison is not with other software. It is with the alternative.

Cost of the alternative
Consultant as-is assessment — per regulation1–3 weeks at €1,500–2,500/day, per regime. Four regimes: do the maths.
€10,000–40,000+
Legal review — per system, per cycleRepeated for every high-risk system, every annual update.
€3,000–6,000
Internal coordination overheadInventory, evidence-chasing, board prep — across four regimes now.
€1,200–2,400/mo
Klarr Readiness AssessmentAll four regimes, sealed report, prioritised roadmap, architecture verdict. Fixed fee, scoped to your estate.
fixed fee

Based on EU market consulting day rates. Your costs will vary. The direction will not.

Platform
from €149
per month · scales with your estate

The posture, maintained: continuous evidence, live regulatory watch, and attestations that stay current instead of decaying.

  • Continuous readiness across all four regimes
  • Thirteen-control evidence base
  • Live watch: EUR-Lex + Danish law, weekly
  • Verifiable attestations (the Klarr Seal)
  • Snapshot-over-snapshot progress for the board
  • Regulatory alerts when the law moves
Design Partnership
Custom
bespoke engagement

For government and regulated finance: tailored assessment scope, executive workshops, and a direct line into the roadmap.

  • Tailored regime scope and depth
  • On-site assessment and executive briefings
  • Legal review integration
  • Sector add-ons (clinical, financial, HR AI)
  • SLA-backed advisory
  • Early access to new regime modules

Turn European regulation from a liability into a competitive advantage.

Know where you stand before your board, your investors, or a regulator asks. Request access — or reach us directly.

Klarr is a compliance intelligence platform, not a law firm. Nothing on this platform constitutes legal advice. Output from Klarr should be reviewed with qualified legal counsel before reliance in regulatory, contractual, or enforcement contexts. Cordero Management ApS accepts no liability for decisions made based solely on platform output.