Catalogue of Tools & Metrics for Trustworthy AI

These tools and metrics are designed to help AI actors develop and use trustworthy AI systems and applications that respect human rights and are fair, transparent, explainable, robust, secure and safe.

Legalithm



Background. Most teams shipping AI features in the EU find out about their AI Act obligations late, from a lawyer or a procurement questionnaire, long after the design decisions that determine the risk tier were made. The Regulation is long, its dates have moved (the Digital Omnibus, Regulation (EU) 2026/1744, deferred the high-risk obligations to 2 December 2027 and 2 August 2028 while Article 50 transparency applied from 2 August 2026), and most guidance online is either a restatement of the text or a sales page. Legalithm was built by a founder who needed the answer inside the development loop, with the legal basis attached, and could not find it.

Objectives. Put the compliance check where the AI feature is built, and make every answer checkable. Legalithm takes a description of the system, the provider or deployer role and the use context, and returns: the risk tier; the obligations that apply, each with its Article number; the Article 50 disclosure text where transparency duties apply; and a dated record. Every output cites the Regulation and carries an asOf date tied to a versioned rule corpus, so a reader can see what the answer was based on and when. Low-confidence results are flagged for human review rather than resolved silently.

How it runs. Three surfaces share one rule set: a command-line tool, a Model Context Protocol server that works inside AI-assisted editors, and a GitHub Action for the build pipeline. The rule corpus ships with the tool, so classification and disclosure generation run fully offline, with no API key and with no source code, prompt or result leaving the machine. The public website adds a free risk assessment, an applicability checker, a penalty calculator, an Annex IV technical-documentation generator, a fundamental rights impact assessment generator, and an obligations map that publishes one page per obligation with its EUR-Lex source. The same corpus also covers the Cyber Resilience Act and the European Accessibility Act.

Records. A completed determination can be recorded and signed by the organisation with its own key, and verified offline by anyone with the tool. Legalithm holds no key and cannot alter a signed record.

Limits. This is a self-assessment aid for the statutory self-assessment routes. It is not a conformity assessment by a notified body and it is not legal advice. Coverage is limited to the obligations encoded in the corpus, which is versioned and published with a changelog. The tool is MIT-licensed and free to use; the source is public on GitHub.

About the tool




Impacted stakeholders:



Target sector(s):


Country/Territory of origin:



Type of approach:




Target groups:



Stakeholder group:




Geographical scope:


Technology platforms:


Tags:

  • eu ai act
  • regulatory compliance
  • ai act article 50

Modify this tool

Use Cases

There is no use cases for this tool yet.

Would you like to submit a use case for this tool?

If you have used this tool, we would love to know more about your experience.

Add use case
Partnership on AI

Disclaimer: The tools and metrics featured herein are solely those of the originating authors and are not vetted or endorsed by the OECD or its member countries. The Organisation cannot be held responsible for possible issues resulting from the posting of links to third parties' tools and metrics on this catalogue. More on the methodology can be found at https://oecd.ai/catalogue/faq.