<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Ari Volcoff</title>
    <description>The latest articles on DEV Community by Ari Volcoff (@avolcoff).</description>
    <link>https://dev.to/avolcoff</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3829311%2Fb732fb86-cfa7-46e4-8e91-aaa1b3e3ac40.jpg</url>
      <title>DEV Community: Ari Volcoff</title>
      <link>https://dev.to/avolcoff</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/avolcoff"/>
    <language>en</language>
    <item>
      <title>I just launched Complizo on Product Hunt — EU AI Act compliance for SMBs (free to try)</title>
      <dc:creator>Ari Volcoff</dc:creator>
      <pubDate>Tue, 17 Mar 2026 12:32:29 +0000</pubDate>
      <link>https://dev.to/avolcoff/i-just-launched-complizo-on-product-hunt-eu-ai-act-compliance-for-smbs-free-to-try-3o79</link>
      <guid>https://dev.to/avolcoff/i-just-launched-complizo-on-product-hunt-eu-ai-act-compliance-for-smbs-free-to-try-3o79</guid>
      <description>&lt;p&gt;I launched &lt;a href="https://complizo.com" rel="noopener noreferrer"&gt;Complizo&lt;/a&gt; on Product Hunt today and wanted to share what I built — and why — with this community.&lt;/p&gt;

&lt;h2&gt;
  
  
  The problem I kept running into
&lt;/h2&gt;

&lt;p&gt;Every EU AI Act compliance tool on the market is priced for enterprises with $50K+/year budgets and requires a consultant to implement. Meanwhile, SMBs are staring down an &lt;strong&gt;August 2, 2026 enforcement deadline&lt;/strong&gt; with fines up to €35M and trying to manage it with spreadsheets and PDFs.&lt;/p&gt;

&lt;p&gt;That's not sustainable.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Complizo does
&lt;/h2&gt;

&lt;p&gt;You add your AI systems, and Complizo:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Classifies them by risk level&lt;/strong&gt; using Annex III criteria (the 8 high-risk categories — employment, biometric, critical infrastructure, etc.)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Auto-generates the required documentation&lt;/strong&gt; — model cards, data governance records, human oversight protocols, FRIAs for high-risk systems — tailored to your specific system details, not a generic 40-page template&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Gives you a compliance score&lt;/strong&gt; so you know what's done and what isn't&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exports audit-ready PDFs&lt;/strong&gt; your legal team or regulator can actually use&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The AI doc generation is the core differentiator. It references actual EU AI Act article numbers and writes documentation specific to what you've described, not boilerplate.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I'm still figuring out
&lt;/h2&gt;

&lt;p&gt;A few open questions I'd genuinely love the dev community's input on:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;SMB self-serve vs. consultant-led&lt;/strong&gt;: Will SMBs actually navigate compliance on their own, or will they always want hand-holding? My bet is the August deadline creates enough urgency to force self-serve adoption.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;GPAI obligations&lt;/strong&gt;: General-purpose AI providers have their own obligations (Article 53+), distinct from Annex III. Still refining how Complizo handles these edge cases.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The Omnibus uncertainty&lt;/strong&gt;: The Digital Omnibus directive may delay high-risk obligations by 16 months. We built the risk classifier to be modular so your documentation doesn't start from scratch if the rules shift.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Free to try
&lt;/h2&gt;

&lt;p&gt;Free tier for up to 3 AI systems — no credit card needed.&lt;/p&gt;

&lt;p&gt;Would love feedback, especially from anyone who's actually tried to navigate the Act or is building AI-powered products for EU-market customers.&lt;/p&gt;

&lt;p&gt;👉 &lt;a href="https://complizo.com" rel="noopener noreferrer"&gt;complizo.com&lt;/a&gt; | &lt;a href="https://www.producthunt.com/products/complizo?tab=discussion&amp;amp;launch=complizo" rel="noopener noreferrer"&gt;Product Hunt launch&lt;/a&gt;&lt;/p&gt;

</description>
      <category>showdev</category>
    </item>
    <item>
      <title>The EU AI Act Kicks In August 2. Here's What Your AI Product Actually Needs to Do</title>
      <dc:creator>Ari Volcoff</dc:creator>
      <pubDate>Tue, 17 Mar 2026 11:30:36 +0000</pubDate>
      <link>https://dev.to/avolcoff/the-eu-ai-act-kicks-in-august-2-heres-what-your-ai-product-actually-needs-to-do-j6a</link>
      <guid>https://dev.to/avolcoff/the-eu-ai-act-kicks-in-august-2-heres-what-your-ai-product-actually-needs-to-do-j6a</guid>
      <description>&lt;p&gt;If you're building AI products that touch European users, August 2, 2026 is a date you need to have in your calendar. That's when the EU AI Act's high-risk AI obligations and GPAI (General Purpose AI) rules become enforceable — with fines up to €35M or 7% of global turnover for non-compliance.&lt;/p&gt;

&lt;p&gt;I built &lt;a href="https://complizo.com" rel="noopener noreferrer"&gt;Complizo&lt;/a&gt; to solve this for SMBs, and in the process learned a lot about what compliance actually requires at a technical level. Here's the practical breakdown.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the EU AI Act actually requires
&lt;/h2&gt;

&lt;p&gt;The Act introduces a risk-based framework. Most AI systems fall into one of four tiers:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Unacceptable risk&lt;/strong&gt; — banned outright (e.g. social scoring, real-time biometric surveillance in public spaces)&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;High risk&lt;/strong&gt; — the hard one. Defined in Annex III, this covers 8 categories including:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Biometric identification and categorisation&lt;/li&gt;
&lt;li&gt;Critical infrastructure management&lt;/li&gt;
&lt;li&gt;Education and vocational training&lt;/li&gt;
&lt;li&gt;Employment and worker management&lt;/li&gt;
&lt;li&gt;Access to essential services (credit scoring, insurance)&lt;/li&gt;
&lt;li&gt;Law enforcement&lt;/li&gt;
&lt;li&gt;Migration and asylum management&lt;/li&gt;
&lt;li&gt;Administration of justice&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If your system falls here, you need: a conformity assessment, a risk management system, data governance documentation, technical documentation, human oversight mechanisms, and registration in the EU database.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Limited risk&lt;/strong&gt; — transparency obligations only. Chatbots must disclose they're AI. Deepfakes must be labelled.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Minimal risk&lt;/strong&gt; — no obligations. Spam filters, AI in video games, etc.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Annex III trap most developers fall into
&lt;/h2&gt;

&lt;p&gt;The trickiest part isn't the clear cases — it's the edge ones. A recruitment screening tool that ranks CVs? Likely high-risk (Article 6, employment category). An AI credit scoring component embedded in a larger fintech app? High-risk. A sentiment analysis tool used in hiring decisions? Probably high-risk too.&lt;/p&gt;

&lt;p&gt;The language in the Act is intentionally broad, which means you need to actually reason through your system's purpose, deployment context, and whether a human is "meaningfully" in the loop — not just technically present.&lt;/p&gt;

&lt;h2&gt;
  
  
  What documentation you actually need to produce
&lt;/h2&gt;

&lt;p&gt;For high-risk systems, the minimum viable compliance package looks like this:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;AI system inventory&lt;/strong&gt; — register every AI system you deploy, with purpose, input/output data types, intended users&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Risk classification decision&lt;/strong&gt; — documented reasoning for why you landed at your classification (or why you're &lt;em&gt;not&lt;/em&gt; high-risk)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Technical documentation&lt;/strong&gt; — architecture, training data description, performance metrics, known limitations&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Data governance policy&lt;/strong&gt; — how training and input data is sourced, validated, and monitored for bias&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Human oversight protocol&lt;/strong&gt; — how a human can intervene, override, or stop the system&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Conformity assessment&lt;/strong&gt; — either self-assessed (for most) or third-party (for certain biometric/law enforcement use cases)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Audit-ready export&lt;/strong&gt; — all of the above in a format you can hand to a regulator&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  The GPAI rules (relevant if you're building on top of foundation models)
&lt;/h2&gt;

&lt;p&gt;If you're deploying a general-purpose AI model (think: your own fine-tuned LLM or a wrapper around GPT/Claude/Gemini), you have additional obligations:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Publish a technical summary of training data&lt;/li&gt;
&lt;li&gt;Implement a copyright compliance policy&lt;/li&gt;
&lt;li&gt;Maintain model documentation and make it available to downstream deployers&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For GPAI models with "systemic risk" (above a compute threshold — currently 10^25 FLOPs), there are even stricter requirements including adversarial testing and incident reporting.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Digital Omnibus delay — and why it doesn't mean you can relax
&lt;/h2&gt;

&lt;p&gt;There's been a lot of noise about the Digital Omnibus potentially delaying high-risk obligations by 16 months. Even if that passes, the GPAI rules and general obligations (transparency, prohibited practices) still kick in August 2. And building your compliance foundation now means you're not scrambling in 2027.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I built
&lt;/h2&gt;

&lt;p&gt;After going through this process for my own AI products, I built &lt;a href="https://complizo.com" rel="noopener noreferrer"&gt;Complizo&lt;/a&gt; — it walks you through each step with guided forms, auto-generates the documentation you need, scores your compliance readiness, and exports audit-ready PDFs. Free for up to 3 AI systems.&lt;/p&gt;

&lt;p&gt;It's not a legal service — it's the engineering scaffolding that gets your docs in shape before you talk to a lawyer (and makes that conversation a lot cheaper).&lt;/p&gt;

&lt;p&gt;Happy to answer questions about the Act in the comments — this stuff is genuinely confusing and the official guidance is not developer-friendly.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>machinelearning</category>
      <category>news</category>
      <category>privacy</category>
    </item>
  </channel>
</rss>
