Can your organization currently produce a complete, audit-ready record showing every AI system in use is mapped against EU AI Act requirements? In my research, most cannot and under NIS2 and the AI Act, that gap now carries personal liability implications for named executives, not just the organization.
I'm developing Compliant to address this: a structured inventory of AI systems and vendors, a clear view of what documentation is missing, and an audit trail to support compliance efforts.
Ran the numbers on SaaS spend at a few companies out of curiosity and honestly wasn't ready for it. Seats paid for months after nobody logged in, three tools doing basically the same job across different teams, subscriptions nobody remembered signing up for!!
Has anyone else actually audited this at their own company?
Ran the numbers on vendor/software spend at a few companies out of curiosity and honestly wasn't ready for it. Duplicate tools solving the same problem, licenses paid for months after nobody was using them, contracts that quietly auto-renewed because no one was watching!!. Has anyone else actually audited this at their own company? Curious if what I'm seeing is normal or if we just got unusually messy.