11 June 2026 · Regula maintainers

Static Analysis for AI Compliance: Why Code Scanning Complements Questionnaires

Code scanning and compliance questionnaires cover different parts of the EU AI Act. Neither alone is sufficient. Most teams need both — and understanding the gap each leaves is the first step to closing it.

What code scanning finds that questionnaires miss

Code scanners detect concrete, verifiable signals that questionnaire respondents may not know about or may describe inaccurately: Article 5 prohibited-practice indicators, AI framework imports that suggest risk tier, credential exposure and unsafe deserialisation affecting Article 15 cybersecurity, and agent autonomy patterns without human oversight gates relevant to Article 14.

Code scanners analyse source code directly. The findings exist in the repository regardless of how anyone answers a questionnaire.

These are facts about the codebase. A questionnaire respondent may not know about them, may understate them, or may describe them inaccurately. Code scanning provides an independent check.

What questionnaires cover that code scanning cannot

Questionnaires capture the obligations that have no source-code footprint: risk management systems (Article 9), deployment context that determines risk tier, fundamental rights impact assessments (Article 27), post-market monitoring plans (Article 72), and data governance policies (Article 10). These are organisational obligations that no scanner can verify.

Questionnaires capture organisational and contextual information that does not exist in source code.

Honest comparison: tools in this space

Examples include Regula (423 tiered risk regexes, 8 detected source languages, offline), AIR Blackbox (whose repository describes 51 checks and a local Python scanner), and Systima Comply (whose repository describes AST-assisted analysis for TypeScript/JavaScript and Python projects). Questionnaire-based approaches include the European Commission's ALTAI. These are maintainers' published descriptions, not independently validated performance comparisons.

Tool Approach Strengths Limitations
Regula Code scan (regex) 423 tiered risk regexes and 8 detected source languages; zero runtime dependencies in the core; offline Regex-based — no semantic understanding. Deep coverage for Python; shallower for other languages. Cannot assess organisational compliance.
AIR Blackbox Code scan (Python) Its repository describes 51 checks, an Apache 2.0 licence, and framework trust layers Its public scanner is described for Python projects. This comparison has not independently validated its checks.
Systima Comply Code scan (AST) Its repository describes AST-assisted call-chain analysis and framework detection for TypeScript/JavaScript and Python projects Its published scope is narrower by language than Regula's. This comparison has not independently validated its analysis.
EU Commission ALTAI checker Questionnaire Free, official, covers organisational and ethical dimensions Self-assessment only. No code verification. Pre-dates the final AI Act text.
EuroComply Questionnaire Guided workflow for EU AI Act obligations, document generation No code analysis. Relies entirely on the accuracy of respondent answers.
Credo AI, Holistic AI Platform (both) Combine code-level analysis with governance workflows, policy management, and questionnaires Enterprise pricing. Heavier integration requirements. Not open source.

When you need both

Most teams building AI systems that may fall under the EU AI Act need code scanning in CI and a questionnaire or governance platform for organisational obligations. The combination looks like this:

Regulation (EU) 2026/1744 is in force and sets 2 December 2027 for Annex III high-risk provisions. The original Article 5 prohibitions have applied since 2 February 2025, while the amendment's new Article 5 points apply from 2 December 2026. Scope and classification still require contextual review.


Last reviewed: 14 August 2026 · Author: Regula maintainers · Not legal advice. Regula is a code scanning tool that identifies risk indicators for developer review. It does not determine your system’s risk classification or replace professional legal counsel.

Related reading