01
Declare
A single structured declaration per AI system covering purpose, affected people, deployment context, and whether you are the provider, deployer, importer or distributor. That last field is not administrative. It decides which articles bind you, and getting it wrong is how a company ends up holding a document that overstates or understates its own obligations.
The gate: Nothing downstream runs on an incomplete declaration.
02
Classify
Every system is screened against the Article 5 prohibited-practice list and classified for risk tier. The screen produces a proposal, never a verdict: a named admin on your side confirms or overturns it, and the decision is recorded with who made it. A prohibited-practice finding is too consequential to be decided by software with no name attached.
The gate: A classification is a proposal until a named person on your team confirms it.
03
Obligations
The declaration plus the classification resolves to a concrete obligation plan: which articles bind you, in which jurisdiction, from which enforcement date, and what each one requires you to hold. The rule pack behind it is maintained and has a named expert reviewer, so the same declaration always yields the same result and you can see who stands behind it.
The gate: A jurisdiction only produces obligations once its rule pack has passed the live gate.
04
Generate
Technical documentation, risk registers, FRIAs, transparency cards, conformity packages, QMS material and UAE Charter assessments are drafted from your own facts, with the governing article supplied verbatim to the generator. The scope branches on your operator role, because the Article 9 duty of a provider is not the Article 26 duty of a deployer, and a document that gets that wrong overstates or understates what you actually owe.
The gate: Every generated document is watermarked DRAFT and carries no authority until signed.
05
Verify
Nothing goes to a reviewer on the strength of the system that wrote it. A separate, independent system re-derives the claims in the draft against your declared facts and the statutory text, and disagreement is surfaced to the reviewer rather than resolved silently. Where a draft has not been cross-checked it is labelled as such, never presented as verified. AI drafts and analyses here. It never rules.
The gate: A draft that fails the cross-check does not reach the signer as if it had passed.
06
Sign
Sign-off is enforced in the data layer rather than in the interface, so no client, script or integration can route around it. Only the named signer can sign. The signature binds to the exact content approved, a later edit cannot inherit it, and corrections are appended rather than overwritten.
The gate: Nothing ships unsigned, and no history is ever rewritten.
07
Monitor
Obligations become discrete controls that are re-tested on a cadence and against each article’s own enforcement date. Evidence is collected as controls pass, findings open when they fail and close on recovery, and a control that regresses from passing to failing raises an alert the same day. Compliance is a state that decays, so it is measured rather than remembered.
The gate: A posture reading older than our own monitoring cadence is labelled stale, not shown as current.
Evidence integrity
Records anyone can verify without asking us.
Auditors and regulators do not accept “the AI said so”. They accept records. Every determination AM8 makes is recorded tamper-evidently: the version of the law applied, the facts declared, the checks that ran, and who signed. A third party can reconstruct any determination from the records alone.
History that cannot be rewritten
Corrections supersede. Nothing is rewritten and nothing quietly changes, so the record of what you believed at the time survives learning that you were wrong.
Sign-off below the API
The signer gate is enforced in the data layer, so no client, script or integration can route around it, and a signature cannot be inherited by content edited after approval.
A dossier that checks out
An exported audit pack carries a cryptographic signature and states what that signature does and does not prove. Where signing is in force, the public key and an offline verifier are published with it, so a counterparty can check a pack we never see them open.
Where the guarantee is in force, the key, the algorithm and the verifier are printed in full on our Trust Center, and where it is not, that page says so instead. A guarantee that you can check something yourself, which then withholds what you need to check it, is not a guarantee. Packs exported before August 2026 carry a content hash and no signature, and we say so beside the guarantee rather than after you ask.
See the published key and verifierJurisdiction coverage
2 live. 7 in build. One bar for every flag.
A jurisdiction is LIVE only when the full compliance loop closes on its real rule pack in our gate test: classification, document generation, an independent cross-check by a second system, human sign-off, and a cryptographically signed, integrity-verified audit dossier. Earned, never declared.
| Jurisdiction | Regimes in the pack | Status |
|---|---|---|
| European Union | EU AI Act (post-Omnibus dates) · GDPR touchpoints | Live |
| United Arab Emirates | PDPL · DIFC Regulation 10 · UAE AI Charter | Live |
| United Kingdom | Pro-innovation framework · ICO guidance | In build |
| Saudi Arabia | SDAIA · Saudi PDPL | In build |
| Qatar | PDPPL (Law 13/2016) · QFC data protection · National AI Strategy | In build |
| Singapore | PDPC · IMDA model governance | In build |
| US states | Colorado-class state AI acts | In build |
| South Korea | AI Framework Act (Jan 2026) | In build |
| Japan | AI promotion regime · APPI | In build |
A jurisdiction in build is visible, never hidden. If your next market is on that list, tell us: customer commitment is what funds a pack and moves it up the queue, and a live jurisdiction is a maintained one, with a rule-pack update commitment and a named reviewer behind it.
Register interestWhere the claim stops
The four things we will not let you assume.
Every claim on this website traces to an artifact or a passing test, or it comes down the same day. That rule only means anything if the limits are on the page too.
We do not give legal advice
AM8 is a drafting and monitoring platform. Generated documents are watermarked DRAFT and carry no authority until a qualified human on your side reviews and signs them. Expert review hours buy you a named reviewer, not an opinion from us.
Discovery reaches what your identity provider sees
Connect Microsoft Entra, Google Workspace or Okta and AM8 surfaces the AI applications your people have been granted access through it, including ones IT never registered. Anything outside the identity provider is not visible to it, and we do not claim otherwise.
Article 50 scanning reports, it does not adjudicate
AM8 fetches your public AI surface and reports whether a disclosure is present and what it found. Whether the wording is prominent enough is a legal judgement, and it stays with a human.
We hold no third-party certifications
No SOC 2 report, no ISO certificate, no registry entry, and no badge on this site claiming one. What we publish instead is our own posture, measured by the engine we sell, and it goes to any counterparty who asks.
“Was the AI worth it?”
The question most companies currently cannot answer with evidence.
Governance intelligence
On the roadmapKnow what you run, what it costs, what it returns.
“Are we compliant?” was last year’s question. “What AI are we actually running, what does it cost, and what does it return?” is this year’s, and it comes from the CEO and the CFO rather than the risk function.
Shipping in v1.0, September 2026: a live inventory of the AI your company actually runs, what it costs, and what it returns. Compliance is the wedge. The AI portfolio evidence is what makes the platform indispensable, because the same declaration that drives compliance produces the answer, with no second data-gathering exercise.
None of it is available today, and this section will say so until it is. It ships when it passes its own gate, on the same rule as a jurisdiction: earned, never declared. If you want to see it before anyone else, a design partner shapes it.
A live AI inventory
Every AI system in use across the organisation, how it is classified and who approved it, drawn from your identity provider and from your own register.
Cost and usage, read from the provider
Spend and usage read from the AI providers themselves rather than retyped from an invoice, so the portfolio view starts from a measured number.
Measured never mixed with declared
Every figure will carry its basis on the figure: measured, declared or estimated. This is the property the gate tests, and it is the reason we are not showing you a euro number yet.
An approval chain that holds
Available now. Each system carries its determination, its documents, its reviewer and its signer, so when the board asks who authorised a model the answer is a record rather than a recollection.
See it run against your own systems.
A mapping call takes forty minutes and produces your obligation picture across every jurisdiction you operate in, whether or not you buy anything.