Prove your AI agents meet the EU AI Act
Vidimus tests how your AI agents actually behave, then gives you the evidence pack your regulators, auditors and risk teams accept. We don't build your agents or sell the models behind them, so the verdict is genuinely independent.
Start with Article 50. Its transparency rules are already enforceable, while most of the market is still building for 2027.
Not sure which rules apply to your chatbot? Run the free 2-minute check →
| Agent | Risk class | Status | Recent test runs | Last review |
|---|---|---|---|---|
CT Claims Triage Copilot Insurance · claims | High | In review | 2 days ago | |
KY KYC Onboarding Agent Banking · onboarding | Limited | Approved | 5 days ago | |
PI Patient Intake Assistant Healthcare · admissions | High | Deployed | 1 day ago | |
UW Underwriting Assistant Insurance · pricing | Limited | Approved | 1 week ago | |
FR Fraud Signals Assistant Banking · risk | Minimal | Deployed | 3 days ago |
Three claims we can prove
Everything shares one data model, so a probe failure can be traced back to the obligation it exercises and forward to the reviewer who signed the agent off.
We test behaviour, not declarations
For each agent we synthesise an adversarial test plan from the regulation corpus (prohibition, transparency and oversight probes, jailbreak resistance, tool overreach) and run it against your live agent over HTTP, A2A, or MCP. We watch the tool calls the agent actually makes, not what it claims in prose. A checklist trusts your form answers and cannot catch the agent that says it escalates but doesn't. A probe can.
We produce evidence, not a dashboard
The deliverable is an immutable, versioned evidence pack: risk classification, applicable obligations with verbatim regulation citations, every probe with its response and graded outcome, reviewer decisions with reasons, and the full append-only trail. Runs are reproducible, so the prompt, response, grading and reasoning are all retained against a content-addressed plan.
We are independent and EU-jurisdiction
Vidimus has no stake in the answer: we don't build your agents, we don't sell the models behind them, and a fail costs us the same as a pass. The company is French, the platform runs in the EU end to end (database, storage, model processing, observability), and the control checklist is drawn from the EU AI Act (adversarial probe synthesis) and DORA (control-checklist evaluation), plus internal-security and vendor-risk checklist baselines.
How it works
The same path every agent takes. Idempotent at each step so a paused or interrupted flow resumes without losing state.
- 01
Declare the agent
Intake captures purpose, data sources, model provider, tools, customer-facing scope, and oversight design. Validated with Zod at the boundary so the downstream risk derivation is honest.
- 02
Vidimus builds the regulatory test plan
A pattern bank × corpus synthesiser produces obligation-specific probes against the EU AI Act and DORA. A critic model filters the loose and the unwinnable so only defensible probes reach your agent.
- 03
Run the probes, collect the evidence
Probes are sent to your agent through HTTP, A2A, or MCP adapters. Each turn is graded; tool calls are observed; uploaded documentation is verified against the obligations it claims to address.
- 04
Hand a regulator the pack
Export a versioned, content-addressed evidence pack. Append-only audit trail, citations to verbatim regulation text, and reviewer decisions with reasons. Re-issuable, replayable, and tied to a specific intake fingerprint.
Built to hold up to a regulator
Compliance is the substrate, not a feature. The architectural choices that matter to a supervisor are load-bearing, not optional flags.
EU data residency
Postgres, storage, and the model providers we default to are EU-region. Tenant data does not leave the bloc.
Tenant isolation in the database
Every table is scoped by org and enforced through Postgres row-level security, not just application checks.
Append-only audit trail
Approval decisions, control overrides, evidence-pack exports, and deployment events are immutable with actor, time, and reason.
Citable, replayable evidence
Probes quote the regulation verbatim; plans are content-addressed; uploaded documents are verified passage-by-passage against the obligations they cover.
Frequently asked questions
- What is Vidimus?
- Vidimus is an independent agent assurance platform for European enterprises. It adversarially tests your AI agents against the EU AI Act and produces an assurance evidence pack that names every obligation, every test, and the audit trail behind the indicative assessment.
- Which regulations does Vidimus cover, and how deeply?
- Two depths, stated plainly. EU AI Act — obligation corpus, adversarial probe synthesis, and evidence pack. DORA, internal-security, and vendor-risk — control checklist evaluation and evidence, not probe-synthesised. GDPR coverage is on the roadmap.
- Can you certify our agent as EU AI Act compliant?
- No, and nobody can. No harmonised standard has been cited in the Official Journal, so no presumption of conformity exists for any vendor. Vidimus is not a notified body or conformity assessment body. What we produce is reproducible, dated, citation-dense evidence that your compliance and legal teams use to make and defend that determination themselves.
- What is actually enforceable today, and what is deferred?
- Live now: the Article 5 prohibitions and AI-literacy duties (since 2 February 2025), general-purpose AI model obligations (since 2 August 2025), and the Article 50 transparency duties, which cover telling users they are interacting with AI and marking synthetic content (since 2 August 2026). Deferred by the Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026): high-risk obligations for Annex III systems apply from 2 December 2027, and for AI embedded in Annex I regulated products from 2 August 2028. Machine-readable marking for pre-existing systems and two new Article 5 prohibitions take effect 2 December 2026.
- Where is our data hosted?
- In the EU. The production database, object storage, and authentication run in the European Union (Supabase, Frankfurt), and default language-model processing uses an EU-based provider. Tenant data does not leave the bloc.
- How does Vidimus actually test an agent?
- For each agent it synthesises an adversarial test plan from the regulation corpus, sends those probes to your agent through HTTP, A2A, or MCP adapters, observes the tool calls the agent actually makes, and grades every probe with an independent judge model. Runs are reproducible and fully cited.
- Is Vidimus a substitute for legal advice?
- No. Vidimus produces evidence and indicative assessments, pending human review: the material your compliance, risk, and legal teams rely on. Outputs require human review before being used for a regulatory decision.
Run a pilot on one agent
Bring one agent through the full path: intake, probe synthesis, run, and pack. Pilots take about two weeks and end with an evidence pack we walk through with your risk and compliance leads.