Norma is API-first compliance infrastructure for SMEs and engineering teams: mark generative media, keep Annex IV files alive, prove agent logs, and catch Article 25 provider traps before procurement does.
The compliance vacuum for agile teams is widest exactly when enforcement starts.
Machine-readable marking of AI content is enforceable EU-wide.
Protected channels force verifiable controls over paper policies.
Up to 7% global turnover — existential for most SMEs on middle-tier failures.
Annex III still needs multi-year documentation discipline, starting today.
Product suite
Enterprise GRC platforms own policy packs. Norma owns the acute technical bottlenecks — signing an asset, regenerating a living technical file, proving a log, or killing a silent provider reclassification.
C2PA-style manifests, EU deployer labels, and steganographic watermark flags so generative outputs stay machine-readable after social re-encoding.
Turn high-risk technical files into a continuously updated evidence pack mapped to Annex IV clauses — export ready for 15-day authority requests.
Tamper-evident agent traces with Merkle-style chaining that preserve auditability after GDPR erasure via PII hash separation.
Procurement workflow that detects white-label, fine-tune, and purpose-shift triggers that reclassify deployers as providers.
Regulatory timeline
Feb 2025
Unacceptable-risk practices banned; AI literacy duties begin.
Aug 2025
AI Office operational; Member State competent authorities designated.
Aug 2026
Article 50 marking; broad enforcement & whistleblower coverage.
2027–28
Annex III / Annex I embedded systems deadlines — long runway required.
Article 99
Middle-tier failures — missing documentation, weak oversight, transparency gaps — carry up to €15M or 3% of worldwide turnover.
€35M or 7%
€15M or 3%
€7.5M or 1%