Entry level

UNAIT Risk Tool

Ideal for organisations that want a first overview and wish to record and document individual AI systems systematically.

Structured assessment of individual AI applications
Risk classification under the EU AI Act
Documentation support
Orientation for staff
A documented initial assessment
AI assistant in the assessment New
Structured recording of AI use cases

Planned or existing AI usage is captured consistently through a guided assessment.

An initial risk assessment under the EU AI Act

The tool supports the classification of the relevant roles (provider, deployer and so on), risk classes and legal obligations, based on structured decision logic.

Pointers on documentation requirements

Organisations see early on which information may matter for a later audit or internal discussion.

Orientation for staff and departments

The Risk Tool provides a clear starting point so that AI is not used informally or unchecked.

A documented initial assessment

The result is a traceable risk and role assessment of the specific AI case, as a basis for further decisions.

Ideal as an entry point into AI compliance: support for your AI officers before unclear usage turns into an organisational risk.
Try it free
Full compliance

UNAIT Compliance

Complete AI governance for your whole organisation. Everything in the Risk Tool, plus a central inventory, structured approval processes and audit-ready documentation for public authorities, companies and research institutions.

Around 90% less time spent by AI officers
All Risk Tool functions included
Central AI inventory
Review and approval processes
Audit-ready documentation
Governance Quick-Check
AI assistant in the assessment New
All functions of the UNAIT Risk Tool

AI use cases are recorded in a structured way, classified by risk and turned into a documented basis for further decisions.

Central AI inventory

Every reported and reviewed AI application is brought together in one place, with status, assessment, responsibilities and evidence.

Review and approval processes

AI cases are steered through clear roles, responsibilities and decision steps instead of email, spreadsheets and informal agreement.

Audit-ready documentation

Assessments, decisions and evidence are filed systematically and made available for data protection, internal audit, funding bodies or internal reviews.

Governance Quick Check

Organisations see not only the risks of individual AI cases but also the gaps in their overall AI governance.

Ideal for organisations with several AI applications, decentralised structures or an elevated audit and reputational risk.
Arrange a demo
Compliance documentation

41 document templates for every role and risk class

Depending on the role (provider, deployer, importer, distributor) and risk class of your AI application, UNAIT provides the matching templates from this library, for structured, audit-ready documentation under the EU AI Act.

Risk management and technical foundations 9
+
Risk management planArt. 9
Technical documentationArt. 11
Quality management systemArt. 17
Data governanceArt. 10
Logging and monitoringArt. 12
Human oversight planArt. 14
Transparency and markingArt. 50
Instructions for use for high-risk AIArt. 13
Review note: technical modification affecting riskArt. 25
Conformity, registration and market surveillance 7
+
EU declaration of conformityArt. 47
Registration in the EU databaseArt. 49
Sectoral conformity assessmentArt. 6 (1)
Post-market monitoring planArt. 72
Serious incident report to the market surveillance authorityArt. 73
Reporting processArt. 73
Extended logging obligation (high-risk biometric AI)Art. 12 (1)
Role-specific obligations 9
+
Review by legal / complianceArt. 5
Importer due diligence for high-risk AIArt. 23
Distributor due diligence for high-risk AIArt. 24
Training and competence records for deployersArt. 26 (2)
Retention of logs by deployersArt. 26 (6)
Prior information where AI use is mandatoryArt. 26 (7)
Role check: central provision, possible provider roleArt. 3 Nr. 3
Check of the EU scope of applicationArt. 2 (1)
AI literacy recordsArt. 4
General-purpose AI models (GPAI) 4
+
GPAI documentation packageArt. 53
GPAI open source, reduced obligationsArt. 53 (2)
GPAI with systemic risk, additional obligationsArt. 55
Open source release and governanceArt. 2 (12)
Special cases and exemptions 4
+
Documentation of a possible exemptionArt. 6 (3)
Documentation of the research exemptionArt. 2 (6)
Real-world testing plan and additional obligationsArt. 60
Check for prohibited AI practicesArt. 5
Data protection 8
+
Data protection impact assessment (DPIA)Article 35 GDPR
Protection concept for confidential organisational dataOrganisational
Sensitive data for bias detection and mitigationArt. 10 (5)
Legal basis for special categories of dataArticle 9 GDPR
Fundamental rights impact assessment (FRIA)Art. 27
Transfer of personal data to third countriesArticle 44 GDPR
Fully automated decisions and data subject rightsArticle 22 GDPR
Record of processing activitiesArticle 30 GDPR
Book a demo
ISO/IEC 42001

Prepared for certification

ISO/IEC 42001:2023 is the first international standard for handling artificial intelligence in organisations. A considerable part of the evidence it requires already accumulates in UNAIT as you work through the EU AI Act. Expand whichever point you want to know more about.

Why the certification body is not allowed to help you
+
Certification bodies may not advise the organisations they later audit, nor build their management system for them. This impartiality requirement is a condition of their accreditation, so the preparation stays with you. That is where UNAIT comes in: we do not audit and we do not issue certificates, we make sure you have something to present on the day of the audit.
What is ISO/IEC 42001, in short?
+
An international standard from 2023. It describes how an organisation governs its use of artificial intelligence: who is responsible, how risks are assessed, how that is documented and reviewed at regular intervals. Unlike the EU AI Act, the standard is voluntary.

For public bodies and universities the regulation usually comes first. The standard is not mandatory there, but it helps to meet those obligations in an orderly and audit-ready way.
For companies it is often the practical lever: customers, partners and tenders ask for evidence, and a certificate is evidence you can show.

What the standard requires, and what UNAIT produces

An overview of which AI is in use
+
In UNAIT: a central AI inventory with role and risk class for each system.
On your side: the completeness of that record and the decision what belongs in scope.
Named responsibilities and documented approvals
+
In UNAIT: an approval path from draft through submission to approval, with roles for AI officers, administrators and staff, and a named team per case. Who gains or loses a responsibility, and who approves, is recorded with person and date.
On your side: a policy and your management’s commitment to it.
Assessed risks and a decision on which are acceptable
+
In UNAIT: a guided risk assessment per system with a traceable classification.
On your side: deciding which risks you are prepared to accept.
Defined responsibilities and trained staff
+
In UNAIT: versioned compliance documents and templates, plus training on AI literacy under Art. 4 EU AI Act.
On your side: responsibilities, resources and the training records.
Traceable decisions in day-to-day operation
+
In UNAIT: creation, submission, approval, status changes, changes to the risk class, changes to entries, report exports and the arrival and departure of team members are all logged with person and date. A case with a logged history is not removed when deleted, only marked as deleted; the history remains.
On your side: embedding it into your own processes.
Regular review through internal audits
+
In UNAIT: an audit log and a full audit report as a PDF at the touch of a button.
On your side: audit planning and the internal auditors.
Demonstrable improvement over time
+
In UNAIT: the gapless history as a basis for corrective action.
On your side: the management review and the measures derived from it.

The Governance Quick-Check shows you where your organisation stands today, in about 15 minutes. Free of charge and without registration.

Start the Quick-Check

UNAIT is not a certification body. Certification against ISO/IEC 42001 is carried out by an accredited body; UNAIT supports you with preparation and documentation.

New in 2026

AI assistant in the assessment

The built-in AI assistant supports users directly as they complete the assessment. It explains questions in plain language, offers orientation on classification and gives targeted pointers. It does not constitute legal advice. Responses are generated by GWDG AI models running on servers in Germany. Nothing you enter is stored permanently; details from your case are only transmitted if you explicitly enable that in the assistant.

Processed in Germany
No user tracking, no permanent storage. The assistant works within the current conversation on servers in Germany.
Guidance on the EU AI Act
The assistant explains questions in the context of the EU AI Act, in plain language rather than legalese. It is not legal advice.
A faster result
Uncertainties are resolved on the spot, so the assessment can be completed quickly and in full even without prior knowledge.
See the feature in the demo
AI
AI assistant
Assessment guidance · step 2 of 6
GDPR-compliant
Current question: 2.3: Primary intended purpose
Let me help with question 2.3. „Automated decision-making“ means the system decides without human review. Does that apply to your system?
No, a manager always reviews the result.
Thank you. Human oversight is a key criterion of the EU AI Act. I have noted this for the assessment. ✓
What you gain

UNAIT brings clarity to how you handle AI applications.

The EU AI Act is already in force, and its obligations take effect in stages. Extensive documentation obligations are coming for high-risk applications; the exact deadlines are currently being adjusted in the Digital Omnibus process (more on this in our blog post). UNAIT structures your AI inventory, assigns risk classes and helps you build the documentation you need.

90% Less time than doing it manually

You get a reliable basis for classifying risks, recognising obligations and making well-founded decisions, without adding complexity.

Clear classification of AI risks in minutes
A reliable basis for decisions and approvals
Orientation for staff when using AI tools
Traceable documentation without extra effort

The highest standard of data protection

Data security comes first at UNAIT. The software runs exclusively in a data centre in Germany. UNAIT documents every AI case with its role assessment, risk classification and decision history: structured, traceable and available at any time. No installation effort, no IT dependency.

Data centre in Germany with TÜV certification to DIN ISO 27001
No transfer to third countries
A separate, protected area for each organisation
Clear access control and separation of data

Certification to DIN ISO 27001 applies to the operator of the data centre in which UNAIT runs. It should not be confused with ISO/IEC 42001, which UNAIT helps you prepare for.

Why UNAIT

Governance without a major project

What UNAIT does differently from traditional enterprise GRC platforms. Expand whichever point you want to know more about.

1. Usable from day one

No IT project, no integration
+
UNAIT is entirely web-based. There is no roll-out project, no connection to your IT systems and no configuration workshops. We set up your organisation and you start the same day. Traditional GRC platforms, by contrast, rely on implementation phases with integration partners.
Usable without prior IT or AI knowledge
+
Built for AI officers in public administration, universities and mid-sized companies. You need neither a compliance department nor special software skills: the guided process explains every step and technical terms are explained in context.

2. Traceable rather than a black box

An assessment reviewed by lawyers
+
The risk analysis is based on a structured assessment developed directly from the text of the EU AI Act and reviewed by lawyers. Written by people, checked by legal professionals.
Deterministic and audit-ready
+
The same answers always produce the same classification. No AI decides your compliance; every result can be traced question by question and evidenced to auditors.

3. From the public sector, for the public sector

Hosting in Germany
+
All data is stored and processed exclusively in Germany, in a data centre with TÜV certification to DIN ISO 27001. No transfer to third countries.
A Leibniz spin-off with hands-on knowledge
+
UNAIT grew out of ZALF, a Leibniz institute. We know the processes, committees and audit requirements of public institutions from our own experience, and we offer AI literacy training under Article 4.
Getting started

We support you through the roll-out

UNAIT needs no complex IT installation. You start with a demo, try it free for 30 days and are then guided through onboarding by our team.

Demo & Online-Meeting
A 30-minute online meeting in which we show you UNAIT and discuss what you specifically need.
Try it free for 30 days
No risk, no credit card. Try UNAIT in your own environment.
Personal onboarding
We accompany the roll-out in your organisation, with no complex IT installation.

Frequently asked questions

When can I start?
+
You can start within a few days, after a short demo conversation and the setup of your account.
Is setup complicated?
+
No. UNAIT is web-based and requires no technical integration. We set up your organisation, create user accounts and define roles together with you.
Are IT resources needed?
+
No. UNAIT is entirely web-based. All you need is a modern browser: no installation, no IT infrastructure, no servers of your own.
Which organisations is UNAIT suitable for?
+
UNAIT suits public institutions and companies, authorities and organisations that want to use AI in a structured and secure way, regardless of size or sector.
What is the difference between the Risk Tool and Compliance?
+
The Risk Tool allows a structured assessment of individual AI applications. UNAIT Compliance adds a central AI inventory, review and approval processes and complete audit documentation for external reviews and evidence.
Can several members of staff work at the same time?
+
Yes. You can create any number of users and assign them clearly defined roles, which suits teams and distributed organisations.
Where is the data stored?
+
All data is stored and processed exclusively in Germany, in a data centre with TÜV certification to DIN ISO 27001. No transfer to third countries.
Is UNAIT GDPR-compliant?
+
Yes. UNAIT runs the software on servers in Germany and follows the requirements of the GDPR. Data processing agreements are available on request.
Why is a spreadsheet not enough?
+
Because auditors work with samples and ask about the history. A spreadsheet shows today’s state. It does not show who changed a classification three months ago, on what basis, or who approved it. In UNAIT every case is documented with its full decision history: person, date, basis and outcome.
Does UNAIT help with ISO/IEC 42001?
+
Yes, with the preparation. The free Governance Quick-Check shows you across seven areas where your organisation stands today, and the documentation produced in UNAIT covers a considerable part of the required evidence. Certification itself is carried out by an accredited body. See Prepared for certification for details.
Can I try UNAIT first?
+
Yes. After a demo appointment you receive free trial access for 30 days, with no credit card and no obligation.
Our solution

For everyone using AI responsibly

UNAIT supports three groups at once, each with a different focus on the same platform.

Confidence when using AI

Many staff would happily use AI tools but do not know which data they may enter, when use becomes critical or which rules apply. UNAIT guides them through a structured set of questions and shows which risks and obligations the specific use case may involve.

The efficiency potential of AI is considerable, particularly in knowledge and administrative work. McKinsey estimates that generative AI could raise annual productivity growth by 0.1 to 0.6 percentage points.

Describe and review specific AI usage
Understand risks and obligations better
Reduce uncertainty about using AI
Awareness of data, purpose and responsibility
Enable safe AI use rather than prevent it

A solid basis for decisions

AI officers have to judge which AI applications are emerging in the organisation, which risks exist and which obligations may follow. UNAIT creates a consistent basis for that: use cases are captured in a structured way, classified by risk and linked to the relevant obligations.

Consistent review instead of case-by-case chaos
Risk-based classification of AI applications
A better basis for internal decisions
Pointers to the relevant obligations and next steps
Relief from recurring questions from departments

Audit confidence for the organisation

Without structure, AI either stays uncontrolled in a grey area or goes unused out of uncertainty. UNAIT helps resolve that tension: AI applications can be reviewed, risks made visible and use enabled more responsibly.

BCG puts the global productivity potential of generative AI in the public sector at around 1.75 trillion US dollars a year.

Spot legal and reputational risks earlier
Enable AI use safely rather than blocking it
A shared basis for departments, IT, data protection and management
Preparation for governance, inventory and audit processes
Better use of efficiency potential through clear orientation

Get started today

Demo, Try it free for 30 days, dann Onboarding – ohne komplexe Installation.

Live-Demo

See UNAIT in action

Click your way through the platform interactively, no appointment needed.

🔊 Sound recommended · The voice-over in this demo was generated with artificial intelligence.
▶
Load the interactive demo

Loading establishes a connection to servers operated by our demo provider Guideflow. The privacy information on the product demo applies.