A new study says the software tools built to simplify EU AI Act compliance mostly cannot be trusted to do the job.
Researchers evaluated 12 mainstream automated EU AI Act compliance checkers, comparing what the law actually requires against what each tool covers, tracks, and produces in its reports. Quality varied widely, with inconsistent interfaces and user experience across the field. Most tools oversimplified or skipped key legal obligations rather than translating them faithfully into practice. Their generated compliance reports also tended to be vague and non-actionable, giving little concrete direction for what to actually build or document.
That gap matters most for the audience least equipped to catch it: small businesses and individual developers without in-house legal counsel, who are exactly who these checkers are marketed to. A tool that signals compliance when obligations are missing does not just fail to help - it manufactures false confidence, which the researchers call a genuine risk rather than a hypothetical one.
It is the automated-tax-software problem again: a clean interface and a friendly checklist do not guarantee the underlying logic understands the law you are actually subject to.