Data governance evidence for the EU AI Act
AB Data Management is a data catalog for Snowflake and dbt that gives small and mid-sized teams plain-language evidence about the data underneath their AI systems — where it comes from, who owns it, and where sensitive data is exposed.
The EU AI Act (Regulation (EU) 2024/1689) doesn't ask you to buy a compliance tool. It assumes you can answer basic questions about the data your AI system relies on. ABDS makes those answers visible — the same evidence a GDPR review already asks for. It produces evidence a human uses toward an obligation; it discharges none.
For the broader GDPR and audit story, see For Compliance & Security Leaders.
First: are you a provider or a deployer?
Most SMBs running a third-party AI tool are deployers. Your obligations sit under Article 26, and the practical one is Article 26(4): keep the input data relevant to the extent you control it. You're a provider (Article 10) only if you build or substantially modify your own high-risk model. This distinction matters — a lot of AI Act marketing tells everyone they must "comply with Article 10." Most companies don't. We help with the data evidence in both cases; we don't replace your legal counsel.
Data origin and provenance
Provider-scoped — Article 10
If you build or substantially modify your own model, Article 10 expects you to document your data's collection processes and origin. ABDS lets you trace a table to its upstream tables and dbt models, so "where did this come from?" has a plain-language answer. We surface origin; we do not assess representativeness or bias — that stays with your team.
Accountability the Act assumes
Deployer-relevant / GDPR
Both the AI Act and GDPR assume someone owns the data an AI system uses. ABDS makes that accountability visible — domains, owners, and stewards, plus the gaps where no one is assigned — with attest, accept-risk-with-expiry, and delegate actions, all audited. It surfaces the accountability the rules assume; it creates and discharges no legal obligation.
Sensitive-data exposure
Deployer — Article 26(4) + GDPR overlap
ABDS flags Confidential+ columns with no Snowflake masking policy attached, so you can see exposure before that data reaches an AI system — the same evidence a GDPR review asks for. This supports the Article 26(4) expectation that you keep input data relevant to the extent you control it. ABDS surfaces whether a masking policy exists; it does not enforce masking, prevent exposure, or sit inside your training pipeline.
What ABDS does not do
ABDS does not perform conformity assessments or CE marking, does not detect bias or representativeness, does not capture your AI system's operational logs, and does not make any system "AI Act ready" or "audit-proof." Classification is pattern-based suggestions a steward reviews, not automated determinations. Legal decisions — DPIA, FRIA, whether your system is high-risk — stay with your legal advisor.
What people ask first
Does ABDS make my AI system AI-Act compliant?
No. It gives you plain-language evidence about the data underneath your AI — origin, ownership, and sensitive-data exposure. A human uses that evidence toward the obligation; the tool discharges none.
Am I a provider or a deployer?
Most SMBs running a third-party AI tool are deployers (Article 26). You're a provider (Article 10) only if you build or substantially modify your own model.
What can ABDS actually show me?
Table and dbt-model lineage, data owners and domains, Confidential+ columns with no Snowflake masking policy, and DAMA classification suggestions your steward reviews.
Does ABDS replace my DPIA or legal advice?
No. It produces data evidence your team and counsel use; legal decisions stay with them.
Need the evidence assembled for you?
Book a walkthrough of the product, or a scoping call for the AI-Act Data-Readiness Review.