Prove EU AI Act compliance without sharing originals.
Complying with the EU AI Act means proving operational accountability for a "high-risk AI system." Lemma lets you prove compliance with each provision — risk assessment performed, human oversight, transparency disclosure — as attributes, so you can demonstrate it without disclosing the original data.
Three voices from the front line.
- Legal / compliance
“We want to run AI that falls in the EU AI Act's high-risk class in a compliance-verifiable form”
- AI governance
“We want to continuously prove our AI's compliance to regulators and third-party auditors”
- Executives
“We want to minimize regulatory-breach risk technically”
Hand over the source, or just the facts?
Nothing changes on the floor. Everything changes for the receiver.
① Your team just saves, as always.
- The usual step
- Fill in the record and save
- On save
- A proof is attached (API, behind the scenes)
- The document itself
- never sent
② They just open a link.
- Proven fact
- compliance with each AI Act provision
- the AI system internals, training data and model details
- not shown
- Login / keys
- not needed
- The document stays private — the record itself is never sent or disclosed.
- Independent verification — the receiver just opens a link. No account, no keys.
- Edits are detected — even a one-character edit fails verification.
Each AI Act provision is implemented as a policyHash, and every AI decision issues a satisfiesPolicy proof. What is disclosed is only attributes such as "risk assessment done," "human oversight" and "transparency" — while training data, model internals and customer data stay hidden and protected. Compliance can be presented to regulators and third-party auditors continuously, without surfacing the originals.
See the technical details ↗Why the usual methods fall short.
Only work that needs all three at once — pass without exposing, independent verification, tamper-evidence — is Lemma's domain.
| Method | Pass without exposing | Independent verification | Tamper-evident | What happens |
|---|---|---|---|---|
| Access control / permissions | △ | ✗ | ✗ | “Someone inside could have edited it” remains possible |
| Masking / redacted copies | △ | ✗ | ✗ | Redaction work grows; the original is still unproven |
| Encrypt and store / send | ✓ | ✗ | ✗ | To verify, the receiver needs it disclosed after all |
| Lemma (ZK proof)the only one with all 3 | ✓ | ✓ | ✓ | The receiver just opens a link |
How it works — and how to start.
We help design disclosure scope and retention, run the PoC, and support production.
Start with a 30-minute call.
Tell us one AI system worried about the AI Act's high-risk class, in the first 30 minutes. No disclosure of training data or model details required.
Find the case that matches your industry and problem
Browse all 36 use cases →TRY LEMMA
Run it yourself.
No sales call needed — start hands-on with Lemma's products.