AimRank Labs compliance case studies
We audit our own AI systems with iCOMPLY and publish the results, including the gaps. These are real findings from real codebases.
Why we publish these
The EU AI Act expects providers to demonstrate compliance, not just claim it (Article 43). The strongest credibility signal we can offer is auditing our own products first and publishing the unedited findings. If iCOMPLY cannot find real issues in a real system built by the same team, it has no business reviewing yours. These case studies are the evidence that it can.
Composite pipeline of 7 foundation models (Claude, Fish Audio S2, Whisper v3, AWS Rekognition, LatentSync, Demucs, GFPGAN) deployed on AWS Lambda. 4 transparency gaps found. 5 open classification questions pending AIGP review.
Key findings
- 1.No machine-readable synthetic-content marking (Art. 50(2))
- 2.No voice-cloning consent gate
- 3.No data subject delete API (GDPR Art. 17)
- 4.No end-audience deep-fake disclosure tooling (Art. 50(4))
RAG-powered conversational AI with 4 agent types (sales, support, informational, community). 4 compliance findings: one MET control, two Article 50 gaps, one GDPR gap. 5 open classification questions pending AIGP review.
Key findings
- 1.Art. 50(1) disclosure: MET (injection-resistant, default-on)
- 2.Art. 50(3) emotion-inference disclosure: GAP (trigger contested)
- 3.Art. 50(2) machine-readable marking: GAP
- 4.GDPR Art. 6 lawful basis + DPIA: GAP
Ready to audit your own system?
Start with the free tier -- classify your AI system and get a preliminary risk tier and applicable articles list in minutes.